Executive Leadership
Delegation of Authority for AI Agents: The Matrix a CEO Should Sign
Your finance team knows exactly who can sign a $40,000 purchase order. Ask them which agent can spend $40 and watch the room go quiet.
Every company past its first real financing has a delegation of authority matrix. It is usually a spreadsheet nobody loves, owned by the CFO, approved by the board once a year, and it answers a boring question with great precision: who is allowed to commit the company to what.
A director can pull it up and see that a VP may sign contracts up to a certain value, that hiring above a certain level needs the CEO, that anything touching debt goes to the board. It is dull. It works. It is also the single most useful governance document I know of for running AI agents, and I have yet to meet a CEO who has extended it to cover them.
That omission is getting expensive. Agents at most companies I talk to can now send email to customers, change prices in a test environment that turns out to be less isolated than everyone believed, publish to a website, open tickets with vendors, and in a few cases initiate refunds. None of those permissions went through the process that governs the humans who sit next to them.
Agents already have authority. Nobody granted it.
Here is how it happens. An engineer wires an agent to the email API because the demo needs it. The demo becomes a pilot, the pilot becomes the way support works, and eighteen months later an agent is sending four thousand customer messages a week under a permission that was granted in a Slack thread by someone who has since left the company.
I did a version of this myself. My own fleet runs content, research, and a fair amount of operations work, and when I finally sat down to list what each agent could actually do, as opposed to what I thought it did, the gap was humbling. One agent that I thought of as a researcher had write access to a production site because it had once needed to fix a typo. It had never misused the access. That was luck.
The fix was to stop thinking about agent permissions as an engineering configuration and start treating them the way the company already treats a signature.
Sort decisions by how hard they are to undo
The human DOA sorts mostly by dollar value. For agents, dollar value matters, but reversibility matters more, because an agent can make the same small mistake nine hundred times before lunch. I use four tiers.
- Internal and reversible. Drafting, summarizing, tagging, routing a ticket to the wrong queue. If it goes wrong, someone fixes it and nobody outside the building knows. Agents act freely here, and the owner reviews samples weekly.
- External but correctable. A support reply, a social post, a published blog update. A customer or the public sees it, but a correction or deletion repairs most of the harm. Agents act here within written limits on volume and topic, with a human reading a daily sample.
- Commitments. Anything that obligates the company: a refund, a discount, a quote, a contract term, a promise about a delivery date, a message to a regulator or a journalist. Agents propose. A named human approves every single one, and the approval gets logged.
- Irreversible. Deleting customer data, moving money out of the company, changing access controls, terminating a service. Agents do not touch these at all.
Tier three is where the arguments happen, and it is where I have changed my mind the most. A support agent offering a ten dollar credit to an angry customer feels trivial until you do the multiplication across a bad week. The spend is small. Customers screenshot everything, though, and a credit an agent offered once becomes a credit the next customer expects.
What goes on the page
The agent section of the DOA should fit on one page, in the same spreadsheet as the human section, so that the CFO and the board see them side by side. For each agent or class of agents it records:
- A human owner by name. One person, accountable for what the agent does the way a manager is accountable for a direct report. A team is not an owner.
- The highest tier it may act in without approval, plus hard numeric ceilings inside that tier: messages per day, dollars per transaction, dollars per week in aggregate. The aggregate cap is the one people forget, and it is the one that saves you.
- Its approver for tier three, which is usually a different person from the owner, for the same reason the person who submits an expense report does not approve it.
- A review date. Agent authority expires every six months unless someone renews it on purpose.
That last line does more work than the rest combined. Permissions granted to agents only ever ratchet up; I have never seen one taken away without an incident forcing it. Expiry flips the default.
Who signs when an agent wants more
Eventually an agent will perform well enough that its owner asks for a higher ceiling or a move up a tier. That request should follow the same path as a human promotion into a role with signing authority, which means evidence and a signature from someone at least one level above the owner.
The evidence I ask for is simple: ninety days of logged actions at the current tier, the error rate a human reviewer found in samples, and one example of the agent correctly refusing to act because something was outside its limits. That last one is the tell. An agent that has never hit its ceiling has not been tested, and one that hits it and pushes through with a workaround is a problem I would rather find in a review than in an incident postmortem.
For moves into tier three with no human approval, meaning an agent that can commit the company on its own, the CEO signs. Not a delegate. I have held to this even when it felt bureaucratic, because it forces me to read the evidence, and because when that agent eventually makes a commitment someone regrets, the board is going to ask who allowed it, and the honest answer should be a person who looked.
It will be out of date by spring
Mine was wrong within six weeks, when an agent picked up a new vendor integration nobody thought to log, and I kept the page anyway because a stale matrix with an owner gets fixed while a perfect one that lives in an engineer’s head never gets read.
Bring it to the board once a year
Boards already approve the human DOA annually. Adding the agent page to that same vote costs about ten minutes of meeting time and answers several of the oversight questions directors should be asking before they ask them. It also gives the audit committee something concrete to test, which they will appreciate far more than another slide about responsible AI principles.
The directors I respect most do not want to approve individual agents. They want to see that a matrix exists, that it has owners and expiry dates, and that the number of agents in tier three is small and known.
Start with the list of what your agents can actually do today.
Most CEOs who build that list find at least one permission that surprises them, and the surprising ones tend to cluster where an early experiment quietly became production without anyone deciding it should. Fix those first, write the page second, and put it in front of the board at the next annual DOA review, which is probably already on somebody’s calendar.
This article is part of the Executive Leadership cluster, focused on board governance and the operating discipline required to run AI systems responsibly at the executive level.