Knowing Which Agent Acted Is Not Knowing Who Decided

Agent platforms are closing the technical control gap. The institutional one stays open — and that open question is what my research is about.

Share

Every serious agent platform is converging on the same three things: an identity for the agent, an authorisation layer that decides which tool it may call, and a record of what it did. This is real progress, and it is the right progress. A year ago the honest answer to “which system made this change?” was often a shrug. It is becoming a query.

But look at what that query returns. An agent identifier, a tool call, a policy decision, a timestamp. It tells you that agent svc-47 invoked transfer_funds and that the call satisfied policy fin-003. It does not tell you which organisational capability was being exercised, who granted the authority to exercise it, or who inside the institution is accountable when it turns out to have been the wrong thing to do.

That is not a logging problem. The information was never represented anywhere in machine-readable form, so no amount of instrumentation will surface it. Call it the institutional semantics gap: the missing connection between the technical authority to execute and the institutional authority to decide. Closing the technical gap is what made this one visible.

The question has changed shape

Governance becomes necessary where agency, interdependence and uncertainty meet. Agentic systems change the first term — agency is now delegated to software that plans and acts through tools — and that changes the governance question itself.

It is no longer whether a system works. It is conditional: under which conditions may which agency be exercised, and how do we know that those conditions actually hold?

Most current work stops before the second half of that sentence. Frameworks tell you what should be in place. Maturity models tell you how thoroughly you have documented it. Neither tells you whether what you documented is true of the system that is running this morning. What an organisation says it permits lives in policies and models; what its systems actually did lives in runtime traces. The two are kept in different worlds, and almost never meet on the same object — this capability, this mandate, this action.

Represent first, govern second

The claim I am working on is that governance effectiveness has an upper bound, and that the bound is not set by the governance function at all. It is set by the system being governed — by how far the exercise of an organisational capability can be observed, attributed and constrained in the first place.

A mature governance function operating on a system it cannot see into produces documents, not control. The same function operating on a well-represented one produces enforcement. The capability is identical; what it can achieve is not.

An organisation cannot govern what it cannot represent.

Knowledge infrastructure, on this reading, is not an enabler of governance. It is a precondition. And the representation that matters is not the technical one — the service map, the data catalogue — but the institutional one: what the organisation does, what it is permitted to do, and on whose decision.

Being in control is not the same as being entitled

There is a second question underneath the first, and it took me a while to separate it properly.

An architecture can be fully observable, fully constrainable, and still be steered by a body that was never authorised to steer it. Effectiveness and legitimacy are different properties, and a governance arrangement can have one without the other. In practice, most governance disputes I have watched were not about whether a decision worked. They were about whether it was that body’s decision to make.

So the second half of the subject is authority itself: where a mandate comes from, what it covers, where it stops, and how far the question “by what right?” can be traced from an action back to its source.

Why research organisations

Every framework needs a case where it can actually fail. Research organisations are the most demanding one I know for this particular question.

They run two authority systems at once. Bureaucratic authority flows down from the institution: budget, compliance, employment, liability. Professional authority flows from disciplinary standing and answers to a community outside the organisation entirely. Both are legitimate. Neither overrides the other by decree. The interesting failures happen at the seam — research integrity, research security, dual-use assessment, data access — where a decision is formally correct in one system and illegitimate in the other.

A model of decision rights that survives that case has been tested against something. One that only works where a clean org chart exists has not.

What the claim is not

The claim is not that governance can be automated. Judgement, contestation and the weighing of incommensurable goods will not be delegated to a constraint solver, and should not be. It is narrower, and I think more defensible: that the formal part of governance — who may decide what, on what basis, with which evidence — can be made explicit, queryable and testable, and that leaving it implicit is a choice, with consequences we are now in a position to observe.

That is the subject. I will post here as the work develops, and the paper when it is done.