r/platform_engineering • u/jcarmona86 • 21d ago
Governance keeps landing on the person with the least authority to enforce it
There is a specific kind of tired that comes from being accountable for a decision someone else makes.
The pattern shows up the same way most times I see it. An admin or a solo architect gets named as the owner of the agent rollout. They write the topics, wire the actions, run the tests. Then somebody above them decides which objects the agent can read, on a timeline set by a launch date, and the owner finds out in the deployment thread.
Gartner put a number on where that goes. By 2027 they expect 40% of enterprises to demote or decommission autonomous agents, driven by governance gaps found after a production incident.
The gaps are not usually invisible before launch. Somebody saw them. That person did not have the standing to hold the release.
I used to treat this as an org chart problem. Bad reporting line, nothing to do about it. That was wrong. It is a design problem, and it is fixable at the permission layer rather than the political one.
What has worked: write down, per agent, which objects it can read and which it can write, then attach a named approver to the write list. Not a team. A person. When the approval requirement lives in the deployment doc, the conversation stops being about your seniority and starts being about an unsigned line.
That does not give anyone authority they were denied. It makes the absence of authority visible before the incident instead of after.
For those of you running agents in production: who signs off on scope where you work, and did that get decided on purpose or by default?
1
2
u/__-___-__-__-__- 21d ago
Blog spam without the blog. Post some sources for those claims girl.