The short version
So far the evidence shows where agent rules are edited, points to who runs agents, and gives an early sign of who owns their rules
Public sources show that products put agent rule edits in admin settings. They point to existing staff, mostly technical, running agents. On who owns an agent’s rules the evidence is still thin: an early sign is that firms own them as standards set up front, not as approvals of each change.
By an agent’s rules we mean its instructions, tools and limits: what it may do, spend or say, and when it must hand over to a person. One vocabulary marks how sure we are: High, the evidence shows; Medium, it points to; Low, an early sign.
The evidence points to existing staff, not new hires, running most agents
In job ads that means technical staff more than business teams: 86 ordinary ads list agent work for every 100 AI-titled ones (range 63–115), and about half of those are technical jobs. In speech, 20 of 30 practitioners describe running agents, and 6 of 10 who discuss staffing gave the work to existing staff.
Products show agent rule edits happen in admin settings
In Claude, ChatGPT, Codex, Copilot, Agentforce and most others, an admin edits an agent’s limits in the product, under central policy. This is what products allow, not what firms do.
An early sign: agent controls are being owned as standards, not as change approvals
About a quarter of agent rule duties in job ads carry decision rights, more than credit, pricing or IT change. All nine set standards and frameworks up front; none approves individual changes, which is common in IT change and pricing (11 of 26 decision duties elsewhere). This may partly reflect that agent work sits with architects.
Sources118,526 job postings from 218 employers1,167 company filings771 statements from 30 practitioners111 provisions in 19 laws and policies31 agent products and protocolsHow we know
Chapter 1 · The work
High that finding unwritten rules and deciding changes are nearly absent from public sources: when we planted examples, the coders found nearly all of them. How much people talk about running agents is less certain: speech extraction catches about half of what is said.Public sources show finding unwritten rules and deciding rule changes barely appear; running agents is what people talk about
771 statements · 30 practitioners
771 things people said about working with agents
We transcribed recorded talks and podcasts by 30 practitioners who run functions with AI agentsWe collected 38 recordings. 30 have timestamps, so every statement can be checked against the audio. All counts here use those 30 practitioners. and split them into single statements about their work.
Most of it is about something else
Two AI models from different vendors sorted each statement independentlyEach model coded every statement on its own. A third pass settled disagreements. Before coding, both had to find planted test examples. Prompts and codes are on GitHub.. 600 describe other work: strategy, adoption, results.
149 describe running agents
Supervising, tuning and training agents is the work people talk about. Counted by speaker, 20 of the 30 practitioners describe itA few speakers talk at length: three sales managers account for 89 of these statements. So we compare speakers, not statement counts..
she spends 20% of her time managing the agents, orchestrating the agents.Sales leader, podcast, 2026
21 describe setting what agents may do
Limits, guardrails and hand-off rules. In job postings, setting limits is about a quarter of agent-related duties.
One describes finding an unwritten rule. None describes deciding a change across functions
It is not a blind spot in our method: when we planted examples, the coders found nearly all of themThe coders caught 94–100% of hidden test examples of this work.. The work is simply absent from the public record. The clearest paid example is one engineering duty at Amgen.
Map rules, exceptions, data dependencies and human decision points before selecting deterministic automation, classical ML, deep learning, GenAI, RAG, agents or a manual approach.Amgen · Sr Machine Learning Engineer posting · 2026
Chapter 2 · The tools
High on what the documentation says. It shows what products allow, not what firms do. Four products’ documentation could not be retrieved.Product documentation shows agent rules are edited in admin settings; it shows what products allow, not how firms approve a change
We read 31 products’ documentation to see where rule changes happen
We read the public documentation of 31 agent products, governance platforms and protocols, as published on 10 October 2026, and coded where an agent’s limits live and who may change them.
Coding assistants put it plainly: an admin edits what the agent may do
Seven of eight assistants and coding agents document an owner or admin role that sets agent limits. Organisation settings override the user, and most keep an audit log.
Business agent platforms mostly do the same
Seven of twelve document a named permission. Some vendors pair the editor with a decider.
These guardrails are controlled by your admin and typically signed off by your internal leadership or key decision-makers.Salesforce Agentforce documentation
Governance platforms record approvals but rarely say who edits
Inventories, approval workflows and audit trails, but only one of six names the role that changes a limit.
Protocols leave it to the implementer or the user
MCP and A2AMCP (Model Context Protocol) connects an agent to tools and data. A2A (Agent2Agent) lets agents call each other. AP2 (Agent Payments Protocol) and ACP (Agentic Commerce Protocol) let agents pay on a user’s behalf. leave authorisation to whoever builds on them. Payment protocols put the limit in a mandate the user signs.
15 of 26 products name an editor: a majority, short of the two-thirds we set in advanceBefore reading any documentation we set a test: at least two-thirds of products would have to name an editor. 15 of 26 do, so the evidence is mixed rather than conclusive..
Every platform shows an agent is a lasting design plus short-lived runs
A design (instructions, tools and limits) persists; runs created from it last minutes or hours, often many at once. So the design can be owned, and each run can only be traced back to it. No law registers agents.
Explore · Who holds what
Five roles are taking shape around agents. Who sets their standard is an early sign; who approves each change is still open
Select a role to see the evidence behind it and how sure we are.
OUTSIDE THE FIRM
INSIDE THE FIRM
Explore · Law
High on what the texts say: every quote was checked by script. The AI-law count rests on 4 provisions on changes, coded by one coder.The law shows overseers for high-risk uses, not owners of rules, and no law registers agents
Of 111 provisions in 19 laws and policies, only trading rules and AI labs’ own voluntary policies name who decides a rule change. Binding AI law names no one. Filter by family.
For high-risk uses (hiring, lending, insurance, health and similar decisions), the EU AI Act and Colorado will require deployers to name trained overseers: Colorado from January 2027, the EU from December 2027. Most agents in support, sales or internal work fall outside that. In the EU a deployer is any organisation using an AI system professionally, so this applies to ordinary companies, not just AI labs.
Context · Where it sits
High: the gap between technology and business functions is wide and holds across all three measures, with intervals that do not overlap for the largest functions.Job postings show AI and agent hiring sits in technology functions; business functions barely hire for it yet
Each row is a business function; each column is a different measure on its own scale. Technology functions are shaded. All three columns come from 118,526 job postings. Dots show estimates, lines their 95% intervalsFunctions were assigned from job titles and occupation codes: about 82% right on a blind check, 95% counting defensible alternatives. Agent-duty shares for data and AI and for security are conservative. Governance duties are counted from a keyword family checked at 85% precision. Only 7.8% of AI-titled postings state who the role reports to, so reporting lines cannot be mapped yet..
Scroll sideways for all three measures.
Explore · Decision rights
Medium that agent rule duties carry decision rights as often as other rule systems, or more. Low on the split between standards and change approvals: it is an exploratory re-code.Mature rule systems pair a standards owner with change approvals; agent rule work so far has only the first
We coded rule duties in job ads as editing, applying or deciding a rule, for agents and eight other rule systems. About a quarter of agent rule duties carry decision rights (9 of 40), above the 9.1% median elsewhere. So our pre-registered test that agents are an exception, with too few deciders, failed.
Every agent decision duty sets standards up frontAn exploratory re-code of all 35 decision duties, coded without seeing the domain. The split is significant (p ≈ 0.03) but fragile: it rests on IT change, and without it p ≈ 0.14. Role type may explain part of it: agent items come mostly from AI-titled senior architect postings, and identity-and-access duties, done by similar architects, also all set standards. “Change management” also catches change that is not IT change.. In other systems many approve individual changes or exceptions.
set the engineering standards that define how agentic AI gets deployed at scaleSalesforce job posting, 2026
CAB approvalsNorthern Trust job posting, 2026 (CAB: change advisory board)
Review and approve complex chargeback claims … pricing exceptionsAmgen job posting, 2026
Written documents tell the same story. In all eight comparison domains, a public document names who approves rule changes. For agents, documents name deciders for AI use in general; only Microsoft Entra’s vendor documentation names approvers for changes to an agent’s access.
Context · Compared with other control paradigms
Agent operations differs from data and financial controls in what is controlled, who edits it, and where it runs
Data teams and financial controllers have run rules for decades. Set side by side, agent operations stands out in five ways. Each row carries its own confidence.
| What differs | Data operations | Financial controls | Agent operations |
|---|---|---|---|
| The unit you control Documented on every agent platform we examined: a design lasts, runs created from it last minutes or hours. Bank model-risk guidance gives each model an owner. | Lasting pipelines, datasets and models; a bank model has a named owner | Lasting algorithms, credit policies and price lists, each with an owner | A lasting design plus many short-lived runs: designs can be owned, runs only traced |
| How rules are written and changed 15 of 26 products document an admin role that edits agent limits; practitioners describe changing guardrails themselves. | In code and schemas, by data engineers | In risk systems and policy documents, by specialist teams | In plain language, in each vendor’s admin settings, by whoever holds the admin role, often the staff running the agent |
| Who decides changes Exploratory re-code: all 9 agent decision duties set standards; elsewhere 11 of 26 approve specific changes. Fragile, and partly explained by architect roles. | Data owners approve access to their data | Committees and named approvers sign off individual changes and exceptions | A standards owner is emerging; approval of individual changes is not yet assigned |
| What the law asks for From the legal texts read in full: trading rules, GDPR, the EU AI Act and Colorado SB26-189. | A named data protection officer (GDPR) | Named owners of algorithm changes, licensed algorithm designers, a CEO who certifies controls | A trained overseer for high-risk uses only (hiring, lending, insurance, health); no law names agents |
| Where the work runs Company controls reach only what the company owns; personal subscriptions on personal devices sit outside them. The personal-device cells are reasoned from how controls work. | On company platforms | On company and exchange systems only | Also on staff members’ own AI subscriptions, beyond the reach of company controls |
| How fast it formalised Dated milestones from our role profiles and Internet Archive captures; start dates are a judgement. | Data science: about 5 years to a certification, 9 to an occupation code | Decades to binding law | About 2.4 years to an agent-named credential; deployer duties scheduled within 4 to 5 |
Data operations is covered here through data-science milestones and bank model-risk guidance, not a separate study.
Context · Is it DevOps again?
Inside teams, agent work is spreading the way DevOps did. In hiring, it looks like a race for scarce AI skills
DevOps formed when existing developers and operators took on each other’s work to coordinate, without a new profession or a law. Switch lenses to compare the evidence.
Roles that ended up with a law took fifteen years or more to get one; the dates point to agent work moving faster, with a first credential in about two and a half years and deployer duties for high-risk uses within five
Agent work reached its first agent-named vendor credential (Salesforce’s Agentforce Specialist, March 2025) about 2.4 years after the practice went public in October 2022, roughly twice as fast as DevOps (5.4 years) or data science (5.0 years). It already sits under a general EU duty on deployers, the firms that use AI (AI literacy, from February 2025). Substantive deployer duties for high-risk uses are scheduled within four to five years: Colorado from January 2027 and the EU’s high-risk rules from December 2027. Most agents in support, sales or internal work fall outside them. We found no binding text aimed at DevOps or data-science work over a comparable span. None of these laws names agents.
See the dates
| Milestone | DevOps | Data science | Security officer | Algorithmic trading control | AI agents |
|---|---|---|---|---|---|
| Practice goes public | Jun 2009Flickr’s talk on daily deploys | Apr 2009Facebook’s data team described in public | 1985a head of information security at JP Morgan | 1976 to 2009contested; drawn from 1987 | Oct 2022ReAct paper (6 Oct); LangChain repository (17 Oct), its first commit named agents on 22 Nov |
| Job titles appear | Mar 2011+1.7 years, 134 “devops engineer” ads | 2008title coined before the practice went public; 806 ads by Jan 2012 | 1995+10 years, Citibank names a Chief Information Security Officer | Not dated | Jun 2023+0.7 years, “AI engineer”; no archived count of “agent engineer” titles before late 2025 |
| First credential | Nov 2014+5.4 years, AWS DevOps Engineer | Mar 2014+5.0 years, Cloudera data science certification | By 1998+13 years, CISSP | Jan 2017+30 years, Series 57 exam, required by regulators for those who design or change algorithms | Mar 2025+2.4 years, Salesforce Agentforce Specialist, a rename of its AI Specialist credential (exams from Sep 2024); general AI credentials from Sep 2023 |
| Shared metrics | Mar 2013+4 years, State of DevOps survey | None found | None found | None found | Research benchmarks onlyno shared operating measure |
| Official occupation | None of its owna job title under Software Developers (15-1252) | Nov 2017+8.6 years, its own code: Data Scientists (15-2051) | By 2010within 25 years, Information Security Analysts (15-1122, now 15-1212) | None of its ownfalls under securities traders | Not expectedour forecast: none in the 2028 US classification (70%) |
| Binding law | None found | None found | Dec 2002+17 years, FISMA and the FTC Safeguards Rule require a designated security officer | Nov 2010+23 years, SEC Rule 15c3-5: the CEO certifies trading controls. Later: FINRA registration of algorithm designers (Jan 2017); EU RTS 6, a designated approver of changes (Jan 2018) | Feb 2025+2.3 years, general EU duty: deployers take measures to support AI literacy (Art. 4, wording since weakened). Scheduled, for high-risk uses only: Colorado deployer obligations for consequential decisions apply from 1 Jan 2027 (+4.2); EU Art. 26 duties for Annex III high-risk systems from 2 Dec 2027 (+5.2), already postponed once from Aug 2026 |
| Split or successor | Apr 2023+13.8 years, platform engineering | 2017 to 2019+8 to 10 years, ML and analytics engineers | 2000chief privacy officers split off | None found | From Sep 2024vendors rename agent products within about three years |
Context · Annual reports
High for the counts, which are phrase hits on the full text of the filings. Medium for what the passages say. 2026 is a partial year, though most annual reports are filed by March.Annual reports show agent language surging, mostly written by vendors describing their products
Share of companies filing a 10-K, the annual report US-listed companies file, that use an agent phrase. Vendors write about 60% of these passages. “Employers studied” are the employers in our job-posting sample that file 10-Ks. Select a year.
Personal AI at work
High on what the controls do: each is stated in vendor documentation or follows directly from how it works. How common unmanaged personal use is cannot be measured from public sources.Vendor documentation shows company controls reach only what the company owns: the device, the browser, the network path or the account
Staff increasingly use their own AI subscriptions and agents for work. Every control we found works only where the company owns something: the device, the managed browser, the network path, the sign-in on the company’s email domain, or the company’s own apps. A personal account on a personal device sits outside all of them, and no source can measure how common that is. A dashed edge marks an inferred cellA dashed edge means the cell follows from how the control works, but no document we collected says it outright. The other cells are stated in vendor documentation or guidance, fetched 11 October 2026. Sources and quotes are in the repository..
| Control layer | Company devicework account | Personal devicework sign-in | Personal devicepersonal AI account |
|---|---|---|---|
| Devicedevice management, managed AI settings, endpoint data-loss rules | Reachede.g. Claude Code managed settings pin logins to the company organisation, with documented exceptions; Microsoft Purview endpoint DLP covers devices once they are “onboarded” | Not reached (inferred)the company doesn’t manage the device | Not reached (inferred) |
| Browserenterprise browser or extension with data rules | Reachedin the managed browser profile: Chrome Enterprise “restricts access to unapproved external generative AI tools” | Not reached (inferred)unless work sign-in requires the managed browser | Not reached (inferred) |
| Networkproxy, secure web gateway, tenant restrictions (blocking other organisations’ sign-ins on the company network) | Reachedonly traffic the company routes: Microsoft Entra tenant restrictions apply to “users on their network” and can block personal Microsoft accounts | Not reached (inferred)traffic doesn’t pass through the company network | Not reached (inferred) |
| Identitysingle sign-on, domain capture (claiming every account on the company’s email domain) | Reachedcompany sign-in enforced | PartlyClaude Enterprise domain capture means “no non-Enterprise accounts can exist on your verified domain”; Team plans can only block new ones | Not reached (inferred)a private email address sits outside the company’s domain |
| Company apps and dataapp-side controls, managed accounts | Reachedthe company’s own tenants: Microsoft Purview flags sensitive data shared with registered ChatGPT Enterprise workspaces | Reachedthe work account is the company’s | Partly (inferred)only when the personal agent uses company credentials to reach company data |
| Policy, training and lawacceptable-use rules, the EU AI-literacy duty on deployers; overseer duties cover high-risk uses only | Applies | Applies | Appliesthe only lever left |
Companies are licensing, not banning
Only 16% of organisations block public generative AI by default, according to Gartner (2025). The 2023 bans were narrower than they sounded: Samsung’s covered “company-owned devices as well as internal networks”. On the company paths that vendors can see, personal-account use of AI apps fell from 78% to 47% of users in a year while approved accounts rose from 25% to 62%.
is unlikely to disappear completelyUK National Cyber Security Centre on shadow AI, 7 September 2026
Inside firms, it is a security job
In our job postings, duties to find, monitor or block unapproved AI sit mostly in security roles: about 19 of 31 such duties, at 14 employers. Elsewhere, postings only ask staff to use approved AI tools, and annual reports mostly name the risk of unapproved tools without a control.
discover unsanctioned AI tools, browser extensions, and API-level agentsAlphaSense job posting, security role, 2026
Control features have documented gaps too: Anthropic notes that one Claude Code sign-in route can create a credential in a different organisation.
What firms can do. Offer a good sanctioned AI account so staff have a reason to use it; enforce company sign-in where the company owns the email domain; put controls on the company apps and data that any agent, personal or not, has to touch; and rely on clear rules and training for the rest.
What to do
Set a standard for agent controls, name its owner, and reserve sign-off for exceptions
In most products the change itself is already an admin permission. What firms need is a written standard that says which changes are routine and which need a named reviewer. Four moves follow from the findings; the deadlines apply to high-risk uses. Select one.
Talk to us about agents in your firm
Protocol Vision Advisory meets firms to talk through agent adoption and control. Request a meeting and we’ll be in touch to set one up.
Thanks. We’ll be in touch to set up a meeting.
Protocol Vision Advisory
Request a meeting
Leave your work email and we’ll be in touch to set up a meeting on agent adoption and control in your firm.
Don’t hire one senior “protocol lead”: no such posting exists among 25,512, and lasting roles in the past did not start senior. And don’t let vendor consoles hold the only copy of an agent’s rules.
Try this in your firm
Public sources show who edits an agent’s rules but not who approves a change; you can find out inside your own firm in an afternoon
Pick one agent that matters, such as a support, finance or sales agent, and work through five checks, in order. Each one tests a finding in this report against your own records.
0 of 5 done
Your ticks stay in this browser only.
If you’d like to discuss this research, come to the Protocols for Business research group: open sessions every other Monday, with readings, observations and case studies.
How we know
Across 300,000 job duties, only one kind of AI work recurs consistently: security review of AI systems
We read postings the way a labour economist reads tasks: by duties, not titles. Step through the method on real data.
Fork the data and analysis on GitHub: designs, scripts, codes, cluster assignments and reviews. The results are under results/rerun-2026-10-10/.
What these findings rest on
- Public sources only: postings, filings, recordings, laws and vendor documentation. Rule changes agreed informally inside firms do not appear.
- 59% of employers in scope have no crawlable job board, including Alphabet, Apple, Meta, Microsoft, Amazon, Goldman Sachs and JPMorgan.
- Speech extraction catches about half of what is said, and the statements about changing agents in tools rest mainly on two speakers.
- Product documentation shows what products allow, not what firms do; four products’ documentation could not be retrieved.
- No time series: the job-board crawl is one point in time.
Checks
- Tests, thresholds and refutation rules were fixed before any data were read.
- Duty statements were checked against their source postings: precision 0.97, recall 0.89.
- A red team and fresh reviewers checked every result.
- Every quote on this page is checked by script against the stored source.
- Personal AI: the 16% blocking figure is Gartner’s (2025). The fall in personal-account use is Netskope telemetry as reported in the press, and covers only company network paths that vendors can see.
Sources quoted on this page
- Sales leader, podcast, 2026 (practitioner recording). Amgen, Senior Machine Learning Engineer, AI Studio, job posting, 2026. Merck and AlphaSense security job postings, 2026.
- Salesforce, “Understanding Agentforce guardrails and trust patterns”, Trailhead. Microsoft, “Agent owners, sponsors and managers”, Entra Agent ID documentation. Both fetched 10 October 2026.
- EU AI Act, Regulation (EU) 2024/1689, Articles 4 and 26(2). Colorado SB26-189. Bank of England PRA, Supervisory Statement SS5/18, Algorithmic trading (guidance).
- UK National Cyber Security Centre on shadow AI, 7 September 2026. Gartner, 2025.
- SEC EDGAR full-text search, 10-K filings 2022–2026.