The question the paper answers
The question that separates one generation of business AI from the next is not whether a company uses artificial intelligence but whether an AI system holds authority to act. A tool that drafts a message for a person to review operates under a different set of concerns than a tool that sends the message itself, schedules the delivery, executes the payment, or changes the record. The second kind of system is an agent, and an agent requires a form of governance most organizations have never applied to software: the deliberate grant, limitation, and audit of authority.
This paper gives management a control framework to apply before that authority is granted. It is written for executives, owners, and the counsel and advisors who support them, in the language of controls they already operate: access authorization, signature authority, spending limits, segregation of duties, and accountability for actions taken.
No system, however it arrives, exercises authority to act until the decisions have been made and recorded. The rule can be adopted without purchasing anything, and it converts the vendor update path from a surprise into a routine review.
From the paper, on the standing ruleThe eight decisions
The framework consists of eight management decisions, made and documented before an agent operates. What the agent may read, stated positively by data class, with external content treated as untrusted input. What actions it may execute, with financial and operational limits stated as numbers and tested before deployment. Where human approval is required, set by consequence and reversibility rather than model quality. What identity and privileges the agent operates under, distinct, attributable, and least-privileged, with segregation of duties intact. How its actions are logged, monitored, and reconstructed through an observable evidence trail at the system boundary. What the vendor is responsible for, in writing, before authority is granted. How the agent is shut down and its actions reversed, tested in advance. And how its authority expires and is renewed on a risk-based cycle, with agent incidents routed through the processes the company already runs.
The decisions are consistent with risk management and governance themes in the NIST AI Risk Management Framework and ISO/IEC 42001, and with the agent-specific standards work NIST opened in 2026 on agent identity, authorization, and the monitoring of deployed AI systems. The references anchor every regulatory and framework claim to its canonical source.
How agents actually arrive
The paper examines three arrival paths: deliberate procurement, a vendor update that adds an agentic capability to a tool the company already approved, and unapproved adoption by an employee. The vendor update path deserves the most attention, because it bypasses every existing checkpoint. The tool was approved before it could act, and no procurement review is triggered because nothing was procured. The framework is built so that this path becomes a routine review rather than a discovery after the fact.
A worked example with a completed decision record
The framework is applied end to end at a 50-person precision machining business, the same company that appears throughout this series, when a platform vendor ships a release adding a send-on-behalf assistant and an auto-reply capability, both enabled by default. The review runs the eight decisions in a single meeting, sets numerical limits and an approval threshold, tests the boundaries, declines one capability the vendor enabled by default, and produces a signed AI Agent Authority Decision Record. The completed record appears in the paper as a filled-in form, not a blank template, covering risk classification, owners, authorization scope, limits, identity, logging, monitoring, testing, vendor responsibility, shutdown, reauthorization, and incident routing.
A governance process that produces no refusals over time is worth examining, since the pattern suggests the review is confirming decisions rather than making them.
From the paper, on the declined capability