Opinion · Governance

Your agents are staff. Where's their handbook?

Microsoft's 2025 Work Trend Index gave the next few years of work a vocabulary. It describes the rise of the agent boss, "someone who builds, delegates to, and manages agents to amplify their impact." It says organizations need a new metric, the human-agent ratio. And it predicts Intelligence Resources departments, a blend of HR and IT, to manage the two together (source). Take that frame seriously for a minute. If agents are staff, ask what staff get on their first day.

Day one, for a person

A new hire gets five things, usually before lunch:

what a new hire getswhat it is forwho is building it for agents
a badgeProof of who they are, and the doors it opens.Identity vendors: agent identities, short-lived credentials, tokens that say whose behalf.
a desk and a jobTools, tasks, someone to hand them work.Agent platforms: builders, orchestrators, systems of record.
a handbookWhat you may not do here, even with the doors your badge opens.Mostly nobody.
a managerSomeone to ask when the handbook says "it depends."Mostly nobody.
a personnel fileA record, so there is a way to know later what happened.A log that says "the connector was called."

An agent gets a badge and a desk and is sent to work in HR, finance and the customer database with no code of conduct, nobody to ask, and no real file. We would never onboard a person that way.

Why the handbook does not transfer by itself

For people, the handbook barely needs enforcing. A person who could assemble a list of colleagues about to be laid off, by asking four innocent questions of four systems, mostly does not. It would take an afternoon, and they would feel terrible.

An agent does it in eleven seconds while trying to be helpful. It has the badge. It does not have the conscience, the tiredness, or the fear of being found out that made the handbook work. So a handbook for agents cannot be a document someone reads. It has to be the thing standing between the agent and the systems, applying the rule every time, before anything is fetched.

Three places the staff analogy breaks, and what they tell you

An agent is not the one responsible. When Maya's planning agent pulls the budget and her reporting agent pulls the rota, neither agent "knows too much." Maya does. What matters is what the person ends up holding, whichever agent fetched it. So the memory of who has seen what has to follow the person, across all of their agents. Track it per agent and the most obvious workaround is to use two agents.

An agent cannot be talked to, but it can be talked into things. Text it reads can carry instructions from a stranger. A person shrugs those off. An agent may not. The rule that works is not "spot the trick." It is "after reading something from outside, nothing leaves until this task is over."

An agent does not wait well. A person who hits a locked door goes and finds the manager. An agent is mid-request with a timeout running. So "ask your manager" has to be built in: the request is held, the owner of the rule is asked, and a yes lasts a few hours with their name on it.

What Intelligence Resources will actually need

If that department is coming, this is its first-week shopping list:

  • A roster. Which agents work here, and for whom. You cannot compute a human-agent ratio for agents you cannot list.
  • A code of conduct that is enforced, not read. Written by the people who own the rules, applied before the act.
  • Memory per person, not per agent. Because responsibility does not move when the work does.
  • A manager's sign-off. A third answer between yes and no.
  • A personnel file for every decision, naming both the agent that acted and the person it acted for, in a form nobody can quietly edit.

Notice what is not on the list: performance reviews for agents, productivity dashboards, headcount planning. Those belong to the platforms that give agents their desks. Conduct is a different job from management, for agents as much as for people, and it is the one nobody is staffing yet.

One caution about the metaphor

"Agents as staff" is useful because it makes the missing pieces obvious. It turns harmful the moment it makes anyone think the agent is accountable. It is not. Every one of these controls exists so that a named person stays answerable for what was done in their name. The handbook is for the agent. The responsibility never leaves the human.

This is the layer Aggrete builds: an open-source policy proxy that enforces your code of conduct across every assistant and agent, remembers per person, can hold a request for the rule's owner, and writes a tamper-evident record naming both the agent and the person. The console now shows the roster: each agent, who it acts for, what it was allowed, refused and held, and the agents-per-person ratio. See it on sample data at console.aggrete.com, or try the proxy at try.aggrete.com.
Open source

Deterministic policy for what AI can reach and do.

Aggrete is Apache-2.0. No model in the decision path.

Star on GitHub How it works