
Most organizations skip all five for an AI agent entering their systems.
Currently, if an enterprise does take the step to secure internal agents, their approach is similar to the way APIs were secured a decade ago: with keys and tokens that prove what something is, not what it’s allowed to do or who answers for it if it goes out of bounds. That gap is concerning. With so many organizations deploying agents quickly, there is massive uncertainty about how they’ll behave in production.
Here’s a familiar pattern. An agent gets built, gets a credential and gets access to something like a CRM or a calendar. It works fine for months. Then it does something nobody expected, and the postmortem often turns up the same root cause: The credential was never tied to anything. No defined role. No record of who approved the access or why. The agent had a key. It never had an identity. That distinction sounds academic until something breaks, and then it’s the only thing that matters.
An API key is not an identity.
A better way to think about this is agent accountability. For every agent running in production, an organization should be able to answer five basic questions. Who are you? What are you here to do? What can you see, and what can you do? Are you doing what we expect? And what happens if it goes wrong? An agent without clear answers to all five isn’t secure, no matter how tightly its key is scoped.The first three questions that refer to identity, role and authority are where most current thinking stops. But an agent that’s authenticated and scoped can still act on stale context, chain into tools nobody expected or drift from the task it was given. That’s why the fourth question, oversight, is so important. It isn’t a dashboard you check once a quarter. It’s the continuous, provenance-level record of what an agent actually did and why, so that a drifted agent can be caught before it causes damage rather than explained afterward.
And then there’s recourse, the question almost nobody asks until they’re forced to. When an agent does something wrong, who answers for it? According to research by my company, which surveyed enterprise leaders, nearly half (48%) of agents in production run with no monitoring at all, and 85% of organizations have no formal accountability structure for the agents they’ve already deployed. That’s not a technology gap. It’s an ownership gap.
Every agent needs a named human who is accountable for its actions, just as organizations establish clear ownership and responsibility for the work their employees do.
Accountability is what powers autonomy.
None of this is an argument for slowing agents down. It’s the opposite. Teams don’t hold agents back because the technology isn’t ready. They hold them back because nobody trusts an agent enough to give it more room to operate.Accountability is what builds that trust. An agent with a clear identity, a scoped role, defined authority, active oversight and a clear line of recourse is an agent you can actually give more autonomy to. The organization knows exactly what the agent can do and exactly who’s responsible if something goes wrong.
The technical standards underneath all this will keep changing. New protocols, new specs, a new acronym every few months. The need for accountability won’t.
Before scaling the next wave of agents, the organizations that succeed will be able to answer the five questions above for each one. If those answers aren’t clear, that’s the gap to close first, not the one to build around. Building agent accountability from the start gives teams the confidence to let agents do more without losing control, and it gives organizations the foundation to safely put agents to work on more than ever thought possible before.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
