Nobody Owns the Agent
We hired thousands of autonomous coworkers this year and never gave a single one a manager.
Real John here, life is VERY exciting right now. My day job (Fora Travel), just closed Series D round for 60 million at 1B valuation. In addition to that, we are still hiring here. Pretty exciting times… but let’s get into this week’s newsletter. We are all leaning into AI and getting things done faster, until they break. Last week, I talked about the invisible tax and it was only the tip of the iceberg. Now, people are using Fable like it is going away (because it is, but they keep extending it, so thanks Anthropic, we love Fable). However, when we trace the source of code back to the author, it is now an agent. Not a person. Why does that matter? Well, it removes the accountability. It removes the blame. But most importantly it removes any consequence. If production goes down because an agent wrote some bad code, you update a markdown file and say it is fixed. You don’t know but you hope that new one line “never do this” instruction in your AGENT.md or CLAUDE.md file will prevent it from every happening. You don’t know but you hope.
Anyway, I get deeper into this later, but that is a summary of the problem, and I do talk about solutions that remedy a lot of the risk.
2 of hearts today, if you know you know. Now, I’m wondering the best way to prove it is me rather than a random card each week. My bot has gotten so good at work people are wondering what slack messages are me. :) Now, that is real progress. Got Blanka up to Triple platinum (again). I still want Diamond, and then master. I’m grinding when I can, but not a top priority for me right now.
Ok, on to the newsletter…
A few weeks ago I found myself staring at a log trail trying to answer a question that should have been simple: who did this?
Something had run. It had made a decision, taken an action, and moved on. The decision wasn’t catastrophic — it was just wrong in the quiet way that things are wrong before they become expensive. And when I traced it back, I didn’t find a person. I found an agent. And when I traced the agent back, I found... nothing. A config file. A prompt someone wrote in a hurry three months earlier. No owner. No on-call. No name.
I’ve been doing this for thirty years, and I’ve spent a lot of that time on the receiving end of incident reviews. The hardest part of an incident was never the technical fix. It was the honesty. Somebody had to sit in a room and say I made that call, here’s what I was thinking, here’s what I missed. That moment is uncomfortable, and it’s also the single most valuable thing that happens in the whole process. It’s where the learning lives.
I sat there realizing that moment had quietly gone missing. And nobody had noticed, because nothing had technically broken.
The number that should scare you isn’t the capability one
Gartner is projecting that 40% of enterprise applications will have embedded agents by the end of this year — up from under 5% in 2025. That’s not a gradual adoption curve. That’s a cliff we all cheerfully drove off together.
Meanwhile, the honest reporting out of the field says the constraint on agent adoption isn’t model capability at all. It’s organizational design, fragmented data, and a shortage of people who actually know how to implement this stuff. The models are fine. We’re the bottleneck. And the phrase I keep seeing — that agent governance is the new cybersecurity — sounds right to me, but I think it undersells the problem.
Because cybersecurity, for all its pain, has an owner. There’s a CISO. There’s a budget line. There’s a person whose job is on the line.
Agents have none of that. We deployed a workforce and skipped the org chart.
Here’s what I think actually happened, and I say this with no superiority because I did it too. Agents entered our systems through the side door. Not as a platform decision with a review board and a rollout plan — as a convenience. One engineer wires up an agent to triage tickets. Someone in ops automates a reconciliation step. A PM builds a workflow in an afternoon that would have been a quarter of work last year. Every one of those was a good decision in isolation. That’s the trap. Nothing arrived that was big enough to require a decision about it.
So we ended up with dozens of small, capable, unsupervised things making judgment calls inside our companies, and no answer to the only question that matters when one of them is wrong: whose is it?
What ownership actually looks like
I don’t think the answer is a governance committee. I’ve sat on those committees. They produce documents, and documents don’t get paged at 2am.
The answer is smaller and more boring than that, which is usually a sign it’s correct.
Every agent gets a human name attached to it. Not a team, not a Slack channel — a person. The same way a service has an owner. If you can’t name the owner, the agent doesn’t ship. This one change does more than the next four combined.
Every agent gets a written job description. What it’s allowed to decide, what it must escalate, and what it must never touch. If you can’t write that in five sentences, you don’t understand what you deployed. Write it before you build it, not after.
Agent actions go in the same incident review as human ones. No separate process, no “well, that was the AI.” When an agent makes a bad call, the owner sits in the room and explains what the agent was optimizing for and why that was wrong. Keep the honesty moment. It’s the whole point.
Inventory what you already have. Not what you approved — what’s actually running. I promise the list is longer than you think and at least one item on it will surprise you. Do this one this week. It takes an afternoon and it’s the only step that requires nothing but willingness.
Give every agent an off switch a non-engineer can find. If killing a misbehaving agent requires a deploy, you don’t have control. You have hope.
None of this is glamorous. Nobody’s writing a conference talk about naming conventions and kill switches. But this is what “responsible AI” actually means at the implementation layer — not a values statement on your website, just a person willing to put their name on a thing that acts on their behalf.
I keep coming back to something I’ve believed my whole career: the tools change constantly, and the accountability never should. We spent the last two years arguing about whether AI would replace engineers. It didn’t. What it quietly did was let us deploy decision-makers without deploying anyone to answer for them, and that’s a much stranger problem than the one we were all bracing for.
The good news is that this is a fixable problem, and it’s fixable by exactly the kind of unglamorous, execution-shaped work that most companies won’t bother to do. Which, as always, is the opportunity.
Go find out what’s running in your systems this week. Put your name on the ones that are yours.
Then go build something amazing.
John Mann is the founder of Startups and Code LLC, a software engineering executive, and the guy who built Cash Critters for $50/month because constraints are a feature, not a bug. Subscribe for weekly takes on AI, startups, and building things that matter.



