Skip to content

An Agent Is Authority You Delegate to a Model

Until someone decides what an agent may do without asking a human, you have a fast assistant. How to write the first authority boundary in an afternoon.

An agent is authority you delegate to a model. Until somebody decides what it’s allowed to do without asking a human, you don’t have an agent. You have a fast assistant.

Somebody on your team wants to build an agent that follows up with every high-intent account. Reasonable ask. The moment they try, it hits a pile of questions nobody has answered. What counts as high intent. Which intent source wins when two of them disagree. Who owns an account with five contacts on it. What we’re even going for, a reply, a meeting, a renewal, a new membership.

Over the past three months I’ve had more than ten conversations with association leaders, mostly member services and BD. The people doing that work navigate it through memory, relationships, hallway conversations and unofficial workarounds. Almost none of it is written down, and an agent can’t recover that operating model from a CRM field and a prompt.

The constraint is organizational legibility, and that changes what you should be buying.

What you actually bought

AI lowered the cost of starting work. It hasn’t lowered the cost of coordinating, validating and finishing it.

The error underneath that is people bought a reasoning capability and expected an operating model. An agent is a reasoning model operating inside a business process. The model brings language, judgment and adaptability. The business brings the outcome it wants, the information worth trusting, the tools and permissions, the definition of done, and the signal that separates success from failure.

Without those, autonomy is improvising. AI doesn’t automate ambiguity. It scales it.

The part of this that really is temporary

Look, a good chunk of this is a 2026 problem, and I’ll concede more of it than you’d expect.

If process means an SOP telling the agent every step to take, that requirement is going away. Better models, bigger context windows, persistent memory and access to organizational traces will let agents reconstruct most of a workflow without anyone documenting it first. I’d abandon the claim that a business has to write down every task before it can use agents. That’s brittle and already dating badly.

OpenAI’s in-house data agent is the proof against my own position. It learns from schema metadata, historical query patterns, pipeline source code, and institutional knowledge in Slack, Google Docs and Notion, and queries the warehouse directly when its context goes stale. Nobody prescribes the analytical steps. OpenAI reported that highly prescriptive prompting actually degraded its results, and that higher-level guidance produced a better agent.

The thing is, look at what sits in that system alongside the inference. One of its context layers is human-curated: descriptions written by domain experts, capturing intent, business meaning and known caveats. They’re in there because they can’t be derived from schemas or query history. The company with the strongest possible incentive to make inference do all the work still pays people to write down what the business means.

Context can tell an agent what your organization has done. It can’t tell it what your organization decided it should do.

Some ambiguity isn’t missing context at all. Sales wants pipeline, finance wants margin, legal wants less exposure, customer success wants fewer disruptions. Feed a model infinite context about those preferences and there’s still no inferable answer to the tradeoff. It can name the conflict and recommend a resolution. It can’t decide whose objective wins unless somebody delegated it that authority.

Permission isn’t information either. An agent can correctly infer that issuing the refund is the normal next step and still have no business issuing it.

Where most companies actually are

There’s a ladder. Assist, where the AI drafts and a human owns execution. Recommend, where it proposes and a human decides. Execute, where it performs routine actions inside defined permissions. Own, where it runs bounded workflows against measurable outcomes.

What we keep seeing at Dual Logic is companies jumping straight from the first rung to the last. That’s our read from the field rather than a survey finding, but the published numbers agree. Deloitte’s State of AI in the Enterprise surveyed 3,235 leaders across 24 countries: close to three quarters plan to deploy agentic AI within two years, and only 21% report a mature governance model. What most are missing is which decisions an agent can make on its own and which need human approval.

The first decision, and it’s about an afternoon of work

Say it’s a sales agent. It may send approved outreach to 25 qualified, opted-in leads a day. No pricing discussion, no contacting existing opportunities, no contractual claims. It stops automatically if complaints or unsubscribes cross the threshold sales ops already uses. Sales operations owns the rollout. After a couple hundred successful actions you raise the limit or add a segment.

That’s rung three. Execute, inside defined permissions, with the exceptions still going to a person. Nobody skipped to Own, and nobody had to.

The whole exercise could take the workflow owner thirty minutes. Sort every action the agent could perform into three buckets. Act autonomously. Act only with approval. Never act. Then add a quantitative limit on its blast radius, the conditions that force escalation, and one named business owner accountable for the outcome.

If leadership can’t approve that statement, the system isn’t ready to be an agent. It can still research, draft, summarize and recommend. That’s an assistant.

I know how that reads: add a control board, then call the slowdown a strategy. Fair. So the narrower version is that before an agent takes consequential external actions, the person who already owns that workflow defines its authority boundary. No new committee. Prototypes, research agents and draft generation all just start. Honestly, the fastest organizations already work this way, with a permitted operating space set up ahead of time. That’s what lets them move. The envelope behaves like a feature flag or a credit limit, not a policy review board.

Process and governance maturity get conflated constantly, and they’re different constraints. Process determines whether an agent can perform reliably and economically. Governance determines how much autonomy you’ll authorize. A beautifully documented process can still support zero autonomy, because the consequences are too severe. Your real autonomy is the lowest of three limits: what the model can do, what your operating environment lets it verify, and what your organization authorizes it to do.

The boring work is the strategy

The companies that win here are the ones that made their work legible: clear outcomes, trusted context, defined authority, observable execution, measurable completion.

The boring work of understanding how your business actually runs is the AI strategy, not the preparation for it.

So pick one workflow this quarter and write its authority boundary. Three buckets, a blast radius, escalation conditions, one named owner. If nobody will sign that, you don’t have an agent problem. You have a decision nobody has made.

Keep reading

Get new posts in The 5th Wave

Case studies, frameworks and industry updates for mid-market leaders. Unsubscribe in one click.

By signing up you agree to the terms and the privacy policy.

A single figure standing at a horizon where a warm field of light meets a cool one.

Start with a conversation.

Thirty minutes with a partner to talk through your priorities and a sensible first step.