Skip to main content
Back to newsletter

NEWSLETTER

Someone Approved That Agent. Can Anyone Say Why?

August 25, 2026

An approval in the agent registry records that an agent may run. It does not record the business purpose, the prohibitions, the accountable sponsor, or the signature behind that decision. Microsoft Digital's guide of August 6, 2026 states that approval, vetting and escalation for its own agents run through a workflow built outside Agent 365, which leaves the authorization record as something each organization has to write and keep for itself.

Microsoft Digital, which is the company’s IT organization, published a guide on August 6 on governing its own agent estate. Amidst the dashboards and the role diagrams, in the middle of the first chapter, there is a paragraph written, as I see it, almost like an aside. The company outright tells us that "We didn't create Agent 365 to handle every IT workflow", because approval, vetting and escalation depend on an organization's own risk posture. At Microsoft, that currently works through a risk assessment and publishing workflow that the company built itself. Integration with Agent 365 is shown further down the same page as something on the list of forthcoming capabilities. (Microsoft Inside Track, Alex Fleck, August 6, 2026)

Several paragraphs earlier, the same document states visibility into more than 500,000 agents.

Read those two facts together. The vendor that created the agent control plane, for the largest documented agent estate in existence, is still making the decision to publish an agent through a process external to the product it sells for that purpose.

That is not a criticism. It is one of the most useful sentences Microsoft has published about agent governance this year. Almost nobody appears to have noticed it, perhaps because it sits inside chapter one of a guide rather than headlining a press release.

The figure 500,000, labelled as agents Microsoft can see in its own tenant through Agent 365, sourced to Microsoft Digital Customer Zero, 6 August 2026. Below it, a highlighted panel stating that approval, vetting and escalation still run through a separate workflow Microsoft built itself, with building this into Agent 365 listed as forthcoming.
The company that sells the control plane still decides somewhere else.

The question worth asking is what the product holds and what the organization still holds.

Microsoft Learn documents the approval path clearly. An administrator opens the request, reviews the agent's capabilities, data sources and custom actions, and publishes it or rejects it. Only the AI Administrator and Global Administrator roles can take that action, while the Global Reader role is explicitly view-only (Microsoft Learn, agents admin guide, updated August 18, 2026, and agent management, updated August 20, 2026).

That is a true control. It stops someone from using an agent that has not been reviewed, and any organization without it is worse off. What it creates is a permission.

Does the agent have permission to run? That answer does not record why anyone wanted it, which business outcome it was meant to serve, who accepts the consequences when it produces a wrong one, or when somebody looks at the decision again. A registry does record ownership, lifecycle state, creation platform and user scope. All are facts about the agent. None are decisions about the organization.

The gap becomes evident the moment someone external asks a question about a decision already made.

Two columns. The Agent 365 registry holds owner, lifecycle state, creation platform and user scope, each checked. An authorization record needs Business Purpose, Explicit Prohibitions, Business Sponsor and Authorization Signature, each shown as an empty dashed box. Headline reads that the registry knows what the agent is but does not know why it exists.
An accurate inventory and an unanswerable question are not the same artifact.

The American Arbitration Association polled 500 senior legal and executive leaders across the United States and Canada, at organizations with annual revenues of $100 million or more, and published the results on May 14, 2026 as "From Principles to Practice: A Benchmark Study in AI Governance". Eighty-seven percent reported having a formal AI governance framework. Twenty-two percent were very confident they could produce evidence of governance decisions for a regulator or auditor if asked. Thirty-three percent had defined escalation pathways for when AI systems misbehave.

Three numbers, one condition. There are frameworks. The evidence is much thinner. There are 65 percentage points between having a governance program and being very confident that you can show it worked.

One particular meeting makes this real, and most people reading this have sat in a version of it. A committee gets together quarterly to review agents deployed weekly. Somebody produces the registry export. It is accurate. It is complete. It is current. And it answers none of the questions actually being asked.

The registry passed. The organization failed.

Governance Debt is what builds in that distance. Each agent published with no recorded reason for existence is one decision the organization will have to reconstruct later, under time pressure, from the memory of whoever happens to still be around. The debt is invisible while the agents keep working. It comes due in one afternoon, and it comes due for whoever holds the role that day rather than whoever made the call.

Microsoft's own guide names this problem in a sentence worth taking seriously. A principal product manager on the Agent 365 Customer Zero team advises establishing a governance rhythm before the agent count outgrows the organization's ability to manage it. The vendor is telling customers that the product is not the whole answer, on Microsoft's own site. Since August 6. It sits there.

There is only one document needed to address this particular part of the problem, and it is smaller than it sounds.

What does the organization keep for every agent that touches a consequential process? An Agent Authorization Document. Ten fields across four sections, and four of them carry the weight of this argument. The Business Purpose, one to three sentences on the problem this agent solves, written by the person who wanted the agent rather than the person who built it. Explicit Prohibitions, what the agent must not do, with the rule that a blank field means the record is incomplete. The Business Sponsor, one named accountable human, which is where the Consequence Owner is recorded and which the document states is not the Technical Owner who configured the agent. And the Authorization Signature, a name, a title and a date belonging to the accountable business owner rather than only the developer or IT administrator.

A fifth section, added in August, adds four more fields for any agent that runs unattended on a timer or a schedule, completed once per trigger. A standing trigger whose Consequence Owner has left the organization is treated as an unauthorized deployment from the date of departure, and reassigning the agent does not carry the trigger. (The Governance Gap, August 11, 2026)

The Agent Authorization Document version 1.5, headed "Ten fields. Four more if it runs on a schedule." Four numbered sections: identification, authorization scope, accountability, and review and approval, each listing its fields. A fifth dashed section covers standing triggers, adding four more fields per trigger, with the note that if the Consequence Owner leaves the trigger is suspended rather than inherited.
Twenty minutes per agent, and the only version that exists is the one you write.

No product is required. This requires deciding that the approval click and the authorization record are two different artifacts, and that your organization owns the second because no vendor is going to hand it to you. Microsoft has been unusually explicit about that. The guide says oversight is not a replacement for security, which is effectively the same shape of point one layer down.

The agents are already running. Pull the registry export you have, select ten that interact with money, customers or regulated data, and try filling in four fields for each. The ones you can complete from memory are the easy ones. The ones you cannot are the actual inventory.

Somebody in your organization approved every agent currently running. Ask three of those approvers why. See how many answers arrive as a business reason rather than a job title.

Who in your organization would write the business purpose line for an agent that had already been running for a year, and would anyone accept their answer as authoritative?

The scenario describing the quarterly committee meeting is constructed. Every product and survey fact is sourced above.