The Evidence Map for Employee-Built Agent Sprawl
The action layer behind the core verdict: how to discover, promote, and retire employee-built agents without overstating what the growth telemetry, the control planes, or the governance analogies actually support.
Use this when employees are packaging assistants and agents faster than anyone can review them. The failure point is not creation; it is the moment a useful personal tool acquires shared users, sensitive data, write authority, or business reliance without a named owner and runtime evidence. The goal is not to stop the building. It is to make the visible path faster, safer, and more reusable than the invisible one.
The findings at full depth
Risk-management frameworks call for risk-proportionate inventory, accountable roles, testing, monitoring, incident response, and decommissioning across the lifecycle, and binding regulation adds oversight and log-retention duties for covered high-risk deployers. Inventory and basic guardrails start before production; stronger controls attach as data sensitivity, audience, tools, permissions, autonomy, reversibility, and reliance rise.
One platform reports 15x year-over-year growth in active agents; another reports roughly 19x growth in weekly users of reusable AI configurations and one bank running more than 4,000 of them. All are vendor telemetry without absolute counts or definitions. A 360-leader survey found broad agent activity but no more than 15% even considering fully autonomous agents. Creation, active use, system connection, write authority, and autonomy are separate adoption stages; report the ladder, not one number.
Government RPA and citizen-developer programs, and the older end-user-computing control record, support broad low-risk creation with stronger gates for AI-driven automation, mission-critical use, and advanced connectors. No reviewed source compares this design's outcomes with blanket prohibition or universal central approval, so treat it as a design hypothesis to pilot and measure.
Registry, agent identity, policy gateway, observability, evaluation, and lifecycle controls now exist across multiple major platforms, several of them cross-platform. Every reviewed surface depends on supported connectors or scanners, credentials, registration, instrumentation, gateway routing, managed status, source-platform APIs, or preview features. Some inline safety layers inspect the first prompt and final response but not intermediate agent steps.
Current lifecycle documentation separates the accountable owner from independent risk review, supporting a three-way split: platform team on shared infrastructure and evidence, risk and compliance on policy and block authority, and a business or product owner on purpose, output acceptance, value, and retirement. This is a supported operating-model inference, not a proven universal standard.
First moves before hiring anyone
Require agent ID, creator, accountable owner, purpose, users, environment, data sources, tools, runtime identity, permissions, model and version, cost center, risk tier, last activity, last review, incident contact, and retirement state. Reconcile vendor registries with identity, gateway, endpoint, API, expense, and owner-attestation data.
Personal sandbox with low-risk data and no production actions; internal read and draft with automated controls and a named owner; write or action with human approval, integration tests, rollback, and security review; narrow autonomous or high-impact use with formal risk review, independent evaluation, a kill path, an incident plan, and periodic recertification.
Never ask makers to type metadata the platform can infer. Give low-risk reviews a short service target, publish approved connectors and templates, and let teams search for reusable agents before building another one. Track approval lead time and workaround rate as governance-product metrics.
The platform team owns the paved road, identity, shared controls, telemetry, evidence collection, and technical support. Risk and compliance own classification, policy, exceptions, independent validation, and block authority. The business or product owner owns the use case, output acceptance, value, user readiness, and retirement authorization.
For agents with action authority, capture who delegated what, which identity acted, data and tools touched, policy checks, approvals, outputs, side effects, cost, exceptions, and recovery. Prompt screening alone is not a substitute for authorization and intermediate-step visibility.
Review agents when the owner leaves, usage is absent for 90 days, the value threshold is missed, a duplicate exists, a connector or model changes materially, permissions expand, or an incident occurs. Revoke credentials, preserve required records, transfer dependencies, and close the inventory record.
Owner, briefing, proof
Owner
One accountable operational owner per promoted agent, plus independent block authority that sits outside the owning team. Orphaned agents with live permissions are the signature failure.
Briefing
The six-stage fleet count: created, active, shared, system-connected, write-capable, autonomous. Plus each agent's tier, what it cannot do, and which move needs a new approval.
Proof
Run evidence for action-capable agents: delegation, acting identity, tools, policy checks, approvals, side effects, cost, and recovery. Plus retirement records with the same rigor as launches.
Start by asking for the fleet count in six stages: created, active, shared, system-connected, write-capable, and autonomous. Not being able to answer is the first finding, not an embarrassment. If the gap is material, widen to a discovery reconciliation and a 90-day promotion pilot on one platform, measured on review time, workaround rate, and complete run evidence. Build the full operating machinery only when the sponsor wants it run.
Claim ledger
The verified base establishes that agent-like use is growing inside major ecosystems, that lifecycle controls exist, and precisely where each control plane's coverage depends on integration. It does not establish how many employee-built agents hold production authority, because vendor telemetry lacks neutral denominators and workforce surveys measure general AI use. It does not quantify losses from duplicated agents, orphaned production agents, or agent-specific compliance failures; those stay risk scenarios and control objectives, not measured incident rates. And no comparative study yet shows that tiered promotion beats prohibition or universal central approval on incidents, speed, or value.
- A neutral cross-enterprise census reports absolute counts for created, active, shared, system-connected, write-capable, and autonomous employee-built agents.
- A regulator, insurer, auditor, or peer-reviewed study publishes agent-specific incident rates, control effectiveness, or a required run-evidence checklist.
- A named preview control, such as cross-platform registry sync or an agent gateway, reaches general availability with materially broader automatic discovery or enforcement.
- A vendor documents zero-configuration cross-platform discovery with independently tested coverage, or a public incident disproves an every-agent control claim.
- A comparative enterprise study measures tiered promotion against blanket prohibition or universal central approval on incident rate, review time, adoption, and realized value.
- EU AI Act amendments, implementing rules, or enforcement materially change high-risk deployer, logging, monitoring, or human-oversight obligations.
- A primary-source dataset quantifies orphaned-agent exposure, duplicate-agent waste, or the cost of dormant identities and permissions.