← Back to Insights
Advisory Brief · Employee-Built Agents

Govern the Agent's Authority, Not Its Author

A verified read on the employee-built agent wave: what the growth evidence actually supports, where today's control planes stop, and how a risk-tiered promotion path keeps the makers while containing the risk.

Date  Jul 2026 Prepared as  Outcome brief ✓ Verified  29 citations checked
Conditional sign-off verdict

It is safe to let employees keep building agents only if the sponsor can show the machinery around them: discovery that reconciles platform registries with identity, gateway, and expense data; a named accountable owner for anything promoted past a personal sandbox; controls that tighten as data sensitivity, write authority, autonomy, and business reliance rise; and a retirement path with the same visibility as adoption. The evidence supports risk-tiered promotion as a credible design, not a proven winner, and no reviewed control plane discovers every agent on its own.

The promotion path

Sandbox

Personal experimentation with approved low-risk data and no production actions. Keep this tier cheap; it is where the value gets discovered.

Read and draft

Internal read and draft use with automated controls and a named owner. Registration is automatic, not a form the maker fills in.

Act with approval

Write or action authority with human approval, integration tests, rollback, and security review before each expansion of reach.

Narrow autonomy

High-impact or autonomous use with formal risk review, independent evaluation, a tested kill path, an incident plan, and periodic recertification.

The sign-off test

Owner

Who owns each promoted agent's purpose, outputs, value, and retirement, and who holds independent authority to block or suspend it?

Briefing

Can leadership state the count at six stages: created, active, shared, system-connected, write-capable, and autonomous? Not knowing is the first finding.

Proof

For agents with action authority, can the team produce run evidence: who delegated, which identity acted, tools touched, approvals, side effects, and cost?

What leaders should take from it

1
Governance follows what the agent can do, not who built it.

Current frameworks and binding regulation converge on risk-proportionate controls: inventory and basic guardrails begin before production, and stronger duties attach as data sensitivity, write authority, autonomy, and business reliance rise. A centrally built tool can be dangerous and an employee-built agent can be low risk; the authority is what matters.

2
The growth is real; the count is not.

Major platforms report rapid multiples in active agents and reusable AI configurations, and one large customer reports more than 169 employee-built agents. These are vendor claims without absolute counts or a neutral market denominator. Report adoption as a ladder, created through autonomous, rather than one agent number.

3
The sandbox-to-production path is credible, not proven superior.

Prior RPA, low-code, and end-user-computing practice supports cheap local experimentation with promotion gates that strengthen as dependency grows. No comparative study yet shows this design beats blanket prohibition or universal central approval, so run it as a measured pilot with published service levels.

4
Control planes are real products now; automatic completeness is not.

Multiple major vendors ship registries, agent identity, policy gateways, observability, and lifecycle controls, several of them cross-platform. Every reviewed control surface still depends on supported connectors, registration, credentials, instrumentation, gateway routing, or source-platform APIs. Reconcile what existing systems already see before buying another dashboard.

5
Split enablement, challenge, and accountability three ways.

The platform team runs the paved road, shared controls, and evidence collection. Risk and compliance own policy, classification, exceptions, and block authority. The business or product owner accepts outputs, owns value and functional support, and authorizes retirement. This split is a supported operating-model inference, not a universal standard, so test it on decision latency and retirement discipline.

Where the evidence stops

Three kinds of claims run ahead of the evidence here: prevalence, harm, and design superiority. The growth multiples come from vendor telemetry without absolute counts, and the workforce surveys that document risky AI behavior measure general AI use, not employee-built agents. No study yet compares risk-tiered promotion with prohibition or universal central approval on incidents and time-to-value, and duplicated-agent waste and orphaned production agents remain risk scenarios, not measured loss rates. The control boundaries above are verified; the sprawl's true size and cost stay open.

The Deep Dive holds the action map: the inventory object, the four-tier promotion path, service-level registration, the three-owner split, run-level evidence, retirement triggers, the full claim ledger, and refresh triggers.

Open the Deep Dive
Outcome brief staged from verified Storm Research v2 · 29 citations checked · 0 fabricated · 10 corrected · 7 demoted