Review capacity, not build capacity, is the binding constraint: 84% of firms have added agents without redesigning a single role, so accountability defaults to whoever built the thing until they change desks, at which point it defaults to nobody.

Why this matters

The gap is bookkeeping about people. In Deloitte’s survey of 3,235 leaders (fieldwork August–September 2025), 84% had not redesigned jobs or workflows around AI capabilities while 82% expected at least a tenth of jobs substantially automated within three years. More than half had considered pod-based or flatter structures; 16% had moved. Firms contemplate the org change and ship the agents anyway.

The firms most exposed are the ones furthest along: organizations that actively encourage employee-led AI building are about twice as likely to have started a hybrid human-AI workforce strategy (50% vs 26%; EY, n=975 at $1B+ firms). Read it the other way: half the firms running citizen development have no plan for what it does to roles.

Two shifts follow, landing on different people.

IT stops building and starts certifying. The 2023 projection that corporate IT would evolve into facilitating, assessing and certifying non-technical employees’ work was made about low-code and RPA. Agents sharpen it, because there is no reviewable artifact and the paved road is the only lever that scales. In a 20-to-500-person fund this is the durable technology job: run the platform, own the gates, and be measurably faster than the unsanctioned path. Resist the enterprise squad model on offer: the standard recommendation is a durable cross-functional squad of six specialist role types, which no fund this size can staff.

Someone has to own an agent nobody wrote. Every agent needs a named human owner in the registry, and it must be a person: a team owner is an unowned agent with better paperwork. The second-order requirement is a successor. Key-person risk arrives disguised as a cron job, and offboarding exists to catch it.

Two findings about framing, because the popular version of each is backwards. A 2019 lab study is cited for the claim that calling an AI a teammate improves outcomes; what it found is that the teammate framing improved affect and behaviour but not performance, while explicit goal setting and role clarification improved everything. And a randomized experiment with 1,261 HR and finance managers finds that framing agents as employees measurably degrades human review, yet 31% say their leadership already frames AI that way and 23% have agents on the org chart. The transferable move is a governance action (define the agent’s role and scope explicitly), not a vocabulary choice; risk tiers shows where this disagreement sits.

The binding constraint in pre-agent citizen programs was trust between business and IT rather than tooling. In a multi-case study of 24 companies, the practitioner’s words were that IT “had a really bad reputation” and the business could not see why things were blocked. Nothing about agents fixes that, and a certifier role held by a team the business routes around certifies nothing.

Where you stand

LevelLooks likeCheapest next move
CrawlNobody can name who built the agents that exist. IT finds out when something breaks.Add one required registry field: a named individual owner. Reject entries naming a team.
WalkOwners recorded. Review is volunteer work done by whoever is free. IT is experienced as a blocker.Designate two or three named reviewers with hours allocated in writing — see the reviewer pool.
RunA trained reviewer pool rotates. Tier-2+ agents require a second maintainer. IT runs a paved road people prefer to the alternative.Require a named successor before promotion to production, and test it by asking the successor what the agent does.
FlyAgent ownership appears in job descriptions and evaluations. Offboarding revokes automatically. Role design is revisited when the portfolio changes shape.Audit one departure after the fact: what still runs, and under whose credentials?

Concerns this dimension covers

  • Oversight decay — review capacity against build volume, which is a staffing decision before it is a discipline problem.
  • Quality debt and orphaned apps — what an unowned agent becomes.
  • Agent sprawl — sprawl measured as an ownership ratio rather than a count.
  • Shadow agents — what people build when the sanctioned path requires a conversation with a team they avoid.

Controls that answer them

The people pages

Canonical role content lives in people/; this hub routes to it rather than restating it.

Sequencing and where this is checked

Open questions

  • What reviewer-to-builder ratio actually holds? Nobody publishes one; the arithmetic in oversight decay is derived rather than measured.
  • Does merging technology and people functions help? One large biotech did it in 2025 with no published outcome: an experiment being run in public, not a model.