Company operating policy rebuilt for agents (L6)
Policy stops treating AI as a tool question and starts treating agents as actors. Access, approval, retention, and accountability rules are rewritten so an agent taking an action has a named human accountable for it.
The steps
- 01
Give agents identities
Tool: Manual
Every agent gets a service identity, an owner, a scope, and a review date, exactly like an employee account. Shared human credentials for agents are a hard stop. Owner: security. DoD: no agent runs on a personal credential.
- 02
Define accountability, not just approval
Tool: Manual
For each agent, name the human who answers for its actions. Approval workflows without a named accountable person diffuse responsibility to nobody. Pitfall: a committee as the accountable party. DoD: accountable person listed per agent in the registry.
- 03
Set retention and disclosure rules
Tool: Manual
Decide what agent transcripts and outputs are retained, for how long, and what must be disclosed to customers. Write it before a customer asks in a security review. Owner: legal plus security. DoD: retention and disclosure text approved and published.
- 04
Review the registry quarterly
Tool: Manual
Quarterly review of every agent identity, scope, and owner, with automatic deactivation for anything unreviewed. Owner: security. DoD: deactivation runs automatically after the review window.
Tools in this playbook
- Manual
Next playbooks
Unfamiliar terms are defined in the AI and Revenue Dictionary. Related frameworks live in the framework library.
