Microsoft's 2025 Work Trend Index gave the next few years of work a vocabulary. It describes the rise of the agent boss, "someone who builds, delegates to, and manages agents to amplify their impact." It says organizations need a new metric, the human-agent ratio. And it predicts Intelligence Resources departments, a blend of HR and IT, to manage the two together (source). Take that frame seriously for a minute. If agents are staff, ask what staff get on their first day.
A new hire gets five things, usually before lunch:
| what a new hire gets | what it is for | who is building it for agents |
|---|---|---|
| a badge | Proof of who they are, and the doors it opens. | Identity vendors: agent identities, short-lived credentials, tokens that say whose behalf. |
| a desk and a job | Tools, tasks, someone to hand them work. | Agent platforms: builders, orchestrators, systems of record. |
| a handbook | What you may not do here, even with the doors your badge opens. | Mostly nobody. |
| a manager | Someone to ask when the handbook says "it depends." | Mostly nobody. |
| a personnel file | A record, so there is a way to know later what happened. | A log that says "the connector was called." |
An agent gets a badge and a desk and is sent to work in HR, finance and the customer database with no code of conduct, nobody to ask, and no real file. We would never onboard a person that way.
For people, the handbook barely needs enforcing. A person who could assemble a list of colleagues about to be laid off, by asking four innocent questions of four systems, mostly does not. It would take an afternoon, and they would feel terrible.
An agent does it in eleven seconds while trying to be helpful. It has the badge. It does not have the conscience, the tiredness, or the fear of being found out that made the handbook work. So a handbook for agents cannot be a document someone reads. It has to be the thing standing between the agent and the systems, applying the rule every time, before anything is fetched.
An agent is not the one responsible. When Maya's planning agent pulls the budget and her reporting agent pulls the rota, neither agent "knows too much." Maya does. What matters is what the person ends up holding, whichever agent fetched it. So the memory of who has seen what has to follow the person, across all of their agents. Track it per agent and the most obvious workaround is to use two agents.
An agent cannot be talked to, but it can be talked into things. Text it reads can carry instructions from a stranger. A person shrugs those off. An agent may not. The rule that works is not "spot the trick." It is "after reading something from outside, nothing leaves until this task is over."
An agent does not wait well. A person who hits a locked door goes and finds the manager. An agent is mid-request with a timeout running. So "ask your manager" has to be built in: the request is held, the owner of the rule is asked, and a yes lasts a few hours with their name on it.
If that department is coming, this is its first-week shopping list:
Notice what is not on the list: performance reviews for agents, productivity dashboards, headcount planning. Those belong to the platforms that give agents their desks. Conduct is a different job from management, for agents as much as for people, and it is the one nobody is staffing yet.
"Agents as staff" is useful because it makes the missing pieces obvious. It turns harmful the moment it makes anyone think the agent is accountable. It is not. Every one of these controls exists so that a named person stays answerable for what was done in their name. The handbook is for the agent. The responsibility never leaves the human.
Aggrete is Apache-2.0. No model in the decision path.