The Approval Chain Was Built for Humans: Orphaned Authority and Decision Rights Under Agentic AI

Agentic systems now commit spend and sign obligations that no human ever approves, with every control firing exactly as designed. The exposure is unassigned accountability rather than model accuracy, and this piece names the condition Orphaned Authority and sets out the decision-rights redesign that repairs it.

Small Purchases, Long Obligations

A mid-sized manufacturer runs an agentic procurement stack across its tail spend, and every purchase order it produces is small. Under the category manager’s threshold, correctly priced, inside policy. A sourcing agent shortlists suppliers, a negotiation agent works the commercial terms against the supplier’s own selling agent, and an execution agent commits through the procurement API.

What the agents optimize is unit price, and the currency they pay in is duration. A better rate arrives attached to a thirty-six-month volume commitment. Another comes with an auto-renewal and a minimum-order tier. A third carries a take-or-pay floor that will not bind for two quarters. Each of those is a good trade on the metric the agent was given, and each one clears every control the company owns, as no control in the stack prices a future obligation. The signature thresholds are denominated in dollars committed today.

By the end of the quarter the firm sits contractually bound well past any authority anyone in it holds, and the audit trail records no moment when that happened. There is no single approval to point at, no exception to investigate. Every control fired as designed.

Executives braced for the rogue agent are watching the wrong thing. A rogue agent is a control failure, and control failures come with owners, playbooks, and a moment on a timeline. The compliant agent leaves none of those. What it exposes is an approval chain that still runs, still produces its audit trail, and no longer contains the human it was built around.

This exposure grows as the technology improves, which is the part that catches people. A better model exercises unowned authority more competently, competence earns trust, and trust is what a human converts into a grant of wider autonomy. Every improvement in the models widens the gap. Capability gains accelerate the problem, and they never retire it.

The Person at the Bottom of Every Instrument

Strip any decision-rights instrument down to its mechanics and the same figure appears at the bottom. RACI assigns the A to someone with a name and a boss, RAPID gives the D to an individual who can explain the call afterward, and delegation-of-authority matrices cascade spending power down from the board in discrete signature limits, until every dollar the enterprise can commit maps to a person who answered for it. Even the four-eyes principle assumes a second person who can be named.

None of that is decorative. Approval thresholds track human cadence, and a category manager who works through forty purchase requests a week can apply judgment to each one; the limit reflects that pace, not four thousand transactions an hour. Escalation presumes a person above who can absorb context and decide under ambiguity. Accountability runs on consequence, as an organization can promote, sanction, or replace an approver, which is what gives a signature its weight.

The law settled part of this a long time ago, and not in the direction the argument wants. Section 14 of the Uniform Electronic Transactions Act and the parallel provision in the Uniform Commercial Code have held since 1999 that a contract may form through the interaction of electronic agents even where no individual was aware of or reviewed what those agents did, and eIDAS seals let a legal person authenticate without a natural one standing behind the signature. Machines have been able to bind companies for a quarter of a century. What the law never addressed, for anyone, is which human inside the company answers for the commitment once it exists. Formation validity and internal authority are separate questions, and only the first one has a settled answer.

Someone to Punish

Organizational economics worked the internal question hard, and the results fit this problem better than their age suggests. Jensen and Meckling argued in 1992, building on Hayek, that firms perform when decision rights sit where the relevant knowledge sits, and they were explicit that assigning those rights is not sufficient on its own. Rights have to be paired with a control system, meaning performance measured and rewards and punishments attached to the measurement. Fama and Jensen had already partitioned the decision process nine years earlier into decision management, which is initiation and implementation, and decision control, which is ratification and monitoring, and argued that the two must be separated wherever the decision agent is not the residual claimant.

So the vocabulary exists, and it fits better than most of what gets written about agents. Give the agent decision management and keep decision control in a human. The difficulty sits one layer down, in what all of these frameworks quietly assume about the agent being delegated to.

An agent in this literature is a legal person with interests of its own, and that is exactly what makes the machinery work. Interests can be aligned, behavior can be bonded, performance can be monitored, and a person who fails can be sanctioned. An AI agent holds no residual claim, posts no bond, and cannot be sanctioned in any sense that changes what it does next. Every mechanism by which agency theory closes its loop runs through a consequence landing on somebody. Against an agent that cannot feel one, the loop does not close, and the full weight of it falls back onto a human who now has to be named in advance. Naming in advance is the step almost no firm is taking.

Every Prior Wave Left Discretion Alone

Governance survived the last three automation waves without being redesigned, and the reason is narrower than it looks. EDI moved documents, and workflow tools routed the same approvals to the same approvers only faster, while robotic process automation went further and executed decisions a human had already made, keystroke by keystroke. Discretion stayed human and only execution traveled, so governance had no reason to travel with it.

Two exceptions matter, and they turn out to be the whole story. Algorithmic execution in capital markets and automated credit decisioning did move discretion, and governance moved with them, under regimes a regulator compelled into existence in sectors that already ran a risk organization ready to receive them.

Agentic systems automate the discretion itself, and they are doing it well outside those sectors. Instead of routing the vendor decision to the category manager, the agent makes it, hands the result to another agent, and that agent calls an API that creates a legal commitment. Someone approved each hop as a reasonable integration. No one approved the chain, which never appeared on any desk as a single object to approve, and autonomy arriving in single integrations never registers as a governance event from inside any one of them.

Whatever human oversight survives degrades along a familiar gradient, from human in the loop to human on the loop to human near the loop. At the end of it sits a reviewer nominally supervising a flow whose volume no person can evaluate, stamping approvals at a pace that proves no judgment occurred. Bainbridge named the shape of this in 1983 as one of the ironies of automation: the better the automation runs, the less practice the supervising human retains, and the more that residual role depends on skills the system has quietly taken away.

Orphaned Authority

What has no name does not get inventoried, and this condition has gone unnamed long enough to spread. Orphaned Authority is what remains when an organization delegates the execution of a decision without delegating its ownership. The agent holds the capability. No one holds the consequence.

The idea has neighbors worth naming. Matthias described the responsibility gap for learning automata in 2004, and Dan Davies gave the general shape a memorable name for a management readership in 2024 with the accountability sink. Both are retrospective and largely moral, asking who deserves blame once harm has landed, and what neither hands an operator is a test that runs beforehand.

This one does. Walk any agentic workflow node by node, and at each consequential point ask whether the design already names who owns the outcome when the action goes wrong. Every node returns one of two answers, assigned or orphaned. The orphans cluster where autonomy grew one integration at a time.

The identity layer makes the condition concrete. A Cloud Security Alliance study in January 2026 found 43 percent of organizations running agents under shared service accounts, and a survey of 235 large-enterprise security leaders that spring found 92 percent without full visibility into the AI identities operating on their systems. An actor the organization cannot individually identify is an actor it cannot hold to account, whatever the design documents say.

Model risk is what boards are watching, and they are right to watch it. Accuracy, hallucination, and drift are real, and they are the kind of problem that shrinks every quarter as somebody ships a better model. The accountability question behaves differently, and the difference is one any risk officer applies reflexively. Model quality governs how often the question gets asked. It does nothing at all to the answer. A firm running a flawless agent still cannot name who owned the commitment, and that deficit sits fully intact on the day it finally matters.

The agent approval chain is the newest instance of the Undesigned Layer, the structure nobody designed and everybody inherited. Here the inheritance is a human approval chain that quietly lost its actor and kept its paperwork.

Brussels Moved One Deadline

Regulation is a weaker forcing function here than the compliance calendar suggests. The Digital Omnibus on AI entered into force on July 27, 2026 as Regulation (EU) 2026/1744, moving the AI Act’s high-risk obligations for standalone Annex III systems from August 2, 2026 to December 2, 2027. Article 50 was left untouched and applied on schedule, with a grace period to December 2, 2026 for generative systems already on the market to machine-label their outputs.

Read against the manufacturer, though, none of it was ever going to bind. Annex III covers biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration, and justice. Vendor selection appears nowhere in it. A procurement agent inside a mid-sized US manufacturer sits outside the high-risk regime entirely and quite possibly outside the territorial scope, so deferring obligations it was never subject to changes nothing for the firm in the opening scene.

Most commentary is making a conflation worth avoiding. High-risk obligations attach to the system, covering risk management, logging, technical documentation, and human oversight. Which human inside the firm answers for a commitment the system produced is a corporate governance question the AI Act never addressed for anyone, and no deadline is coming for that one.

Forcing arrives anyway, diffusely and on no one’s calendar. It comes through an external auditor asking how an automated commitment was authorized, through D&O underwriters adding questions at renewal, through customer attestations, through Section 404 for public companies, through Article 22 of the GDPR wherever a decision carries legal effect, and through DORA for financial entities. Diffuse forcing produces late, expensive, uncoordinated compliance, which is worse than a deadline and considerably worse than design.

Who Convenes This

Ask who owns this work inside a large company and the honest answer is that no one does, which is the practical reason it does not get done. Deloitte’s 2026 State of AI survey of 3,235 leaders across 24 countries found 21 percent reporting a mature governance model for agentic systems, and the missing 79 percent are not a product of indifference. Fixing this means reconciling the RACI, the delegation-of-authority matrix, and the model inventory. They sit in three different functions, and none of the three can move the other two.

So the work defaults to security, which picks up orphaned governance problems because it is the only function that will take one without being asked. Security then does what security can do, which is controls, and the design question goes unanswered inside a different backlog.

What this needs is a standing body convened by the transformation office, holding the delegation-of-authority owner from Finance, the second line, legal, and the platform owner, with a mandate narrow enough to finish. In regulated firms the sensible move is to extend the existing model inventory with decision-rights fields instead of standing up a parallel register, since the model risk function already knows how to run one and internal audit already knows how to test it. Mapped against three lines of defense, the inventory and the charters are first-line work, the tiering standard is second line, and the auditability requirement is third. Name that split and five design moves become a funded workstream. Leave it unnamed and they stay an article somebody agreed with.

Size the Authority by What Cannot Be Undone

Every tool in this market enforces a design, and most firms have no design for it to enforce. That is the case for treating this as architecture, and it is not a case against tooling, which is where the design eventually has to live or it stays a document.

Begin with a decision-rights inventory. Walk every agentic workflow, mark each consequential node assigned or orphaned, and resist the urge to fix anything mid-walk. A consequential node is one where the action creates an external obligation, moves money, writes to a record other decisions rely on, or cannot be reversed inside the detection window. The walk starts in the identity and integration layer, as a workflow running under a shared service account cannot be attributed node by node at all, which makes per-agent credentials step zero and puts security upstream of this work, not alongside it. Two warnings from practice. The register is discoverable, so settle with counsel how it will be held before it exists. And “orphaned” reads as an accusation to the people who built those integrations, which makes the column heading matter more than it should.

Then tier the authority, on three axes instead of one. Reversibility, blast radius, and detection latency together price what an action can cost the firm. Monetary value feeds blast radius; it does not stand in for the other two. Detection latency is the axis most often left out and the one the opening scene turns on, since an action reversible in principle but undetected for ninety days is irreversible in practice.

A workable first structure has four bands. Actions the agent can reverse itself within the same session need only logging. Actions a human can reverse inside the detection window need an owner and an alert. Actions reversible only through a counterparty need pre-authorization against a standing envelope. And actions that create an external obligation, move money irreversibly, or write to a system of record other decisions depend on need a named human in the path, whatever the value.

Here the practical constraint has to be stated plainly, because it is where this move usually dies. The delegation-of-authority matrix is a Finance instrument, board-approved, tied to the financial statements, externally audited, and encoded in the ERP as currency values. Reversibility is not a field in SAP, Coupa, or Ariba, and adding a second axis to the matrix means a board resolution, a controller who does not want one, and a conversation with external audit about whether the matrix still ties. That is a two-year change. What fits inside two quarters is reversibility as a design constraint on agent scoping, sitting outside the matrix and governing what an agent may be built to do, not what it may spend. Version one of this move lives in the charter.

An Owner Who Can Stop the Thing

Every agent then needs a bounded decision-rights charter, and every charter a named human owner per decision domain. What that owner answers for has to be stated precisely, or the role becomes the thing this article argues against. The owner does not answer for outcomes inside a correctly enforced envelope, which no person could observe at volume. The owner answers for whether the envelope was designed, tested, enforced, and monitored, which is how SR 11-7 model owners and Section 404 control owners already work and is falsifiable at audit. Accountability without matching powers produces a designated blameholder, so the charter has to grant unilateral authority to stop the agent, a veto over scope changes, a monitoring budget, and an acceptable-loss envelope agreed above them. An owner who cannot stop the thing is not an owner.

One further owner is needed, and the opening scene is what requires it. That chain crossed sourcing, negotiation, and execution, so three domains and three owners produced a harm that was emergent from the composition and resident in no node. Node-level ownership does not catch a chain-level failure. Name an owner for the composed chain, with a cumulative-exposure envelope spanning it.

Escalation has to be designed as structure and not handled as an exception, and the design carries an arithmetic constraint that decides whether it survives contact with volume. If a chain takes N actions a day and escalates p percent of them, and a competent reviewer handles M a day across H reviewers, then p is bounded by M times H over N. Any escalation design violating that inequality rebuilds review theater by arithmetic, however good its triggers are. Triggers worth defining include confidence floors, value at risk, novel counterparties, and cumulative-envelope breaches. Escalation load is a headcount conversation, and treating it as anything else is how the control comes back as ritual.

Auditability comes last and needs redefining. Action logs answer what the agent did, which is the easier question and the one most vendors have solved. The accountability question is older and harder: who did the design say owned this, before it happened? That is answerable afterward only if it was recorded beforehand, which means stamping the charter version, the authority tier, the owner of record, and the policy hash into every action log at execution time. Without it, the design gets reconstructed from memory under investigation, which is the condition this entire exercise exists to avoid.

The Case That This Is Just a Missing Control

Two objections come from readers worth taking seriously, and they arrive from opposite directions.

The first comes from financial services and medical devices, and it is correct on its facts. Named human accountability for an automated actor is not an unsolved problem. SR 11-7 assigns model owners and tiers them by materiality. SEC Rule 15c3-5 requires pre-set thresholds on automated order entry with an annual certification from a named executive, and MiFID II RTS 6 requires kill switches, pre-trade limits, and identified responsible persons. Section 404 has assigned named control owners to automated application controls for two decades, and the FDA authorizes an envelope of autonomous model change against an accountable manufacturer. Every one of those patterns shares three properties, though. A regulator compelled it. The automated actor it governs is narrow and largely non-discretionary. And it landed inside a function that already ran a risk organization, a control inventory, and someone whose job was to own the register. What is new is not the absence of a pattern but the arrival of general discretionary delegation in functions holding none of those three things. Procurement, marketing operations, HR service delivery, and revenue operations are all deploying agents that exercise judgment, and not one of them holds a model inventory, a sectoral regulator, or a control-ownership tradition ready to receive the pattern. This is a diffusion problem and not an invention problem, which matters, since the two have entirely different remedies.

The second comes from a competent engineering leader, and it is half right. Nothing in the opening scene, that objection runs, is an accountability problem. It is a missing aggregate control. The firm granted per-transaction authority and never set a cumulative envelope, an obligation ceiling, or a rate limit. Four lines of policy in the procurement system fix it, and that is a sprint, not a transformation program. Nor is the liability orphaned, since the firm is bound by what its systems commit and always has been, the chief procurement officer owns procurement outcomes whether a person or a process produced them, and residual accountability flows upward through the org chart by default, which is what an org chart is for.

Most of that holds. What does not hold is the assumption that somebody will notice the missing control and set its parameters. A cumulative envelope is a number, and that number is a decision right. Somebody has to choose it, defend it, and answer for it when it turns out wrong. Engineering controls with no owner degrade quietly, drift with every release, and get widened by whoever is closest to a deadline. The four lines of policy are the right answer and they are the second step. The first is that a named person sets the ceiling and can be asked why.

The org-chart argument has the same shape. Residual accountability does flow upward, and that is precisely the problem, since it arrives at an executive who could not have known, held no mechanism to intervene, and will be asked in a deposition why the firm allowed it. Accountability landing somewhere by gravity is not accountability functioning. It produces the answer nobody wants, in which everybody owned this a little and no one owned it enough.

One Quarter, Rerun

Run the manufacturer’s quarter back through a design carrying these pieces and the arithmetic changes at three points.

Tiering on reversibility and detection latency puts any term longer than twelve months into the band requiring a named human in the path, whatever the unit price, so the thirty-six-month commitment stops. The cumulative envelope on the composed chain is denominated in committed months rather than dollars, so the auto-renewal and the take-or-pay floor register against a ceiling somebody set on purpose. And the action log carries the charter version and the owner of record, so the question of who authorized a multi-year obligation has an answer that predates the obligation.

None of that stops the agents, and none of it returns the work to human review. It changes what the agents may trade duration for, and who has to say yes.

Accountability Before the Fact

Executives keep asking whether the agents can be trusted. The question has no operational answer, and it aims the inquiry at the technology, where the exposure does not live. The designable question aims at the organization. For any consequential action an agent can take, can the firm name who was accountable before it happened?

Two clocks run at different speeds, which is what makes the timing matter. Autonomy scales linearly, deployment by deployment, while orphaned authority compounds, as every new agent inherits the unowned authority of every chain it joins. An accountability architecture built after the fact gets built under investigation conditions, with regulators or plaintiffs in the room and an audit trail proving that every control fired while no one decided anything.

A board that has already approved an agentic program does not need telling that the exposure compounds. It needs one request it can act on: an inventory of the agents already in production, every consequential node marked assigned or orphaned, reported to the audit committee. That is a few weeks of work, and it is the last point at which the answer can still be designed rather than discovered.


Discover more from Adolfo Carreno

Subscribe to get the latest posts sent to your email.

← Previous Mientras Mejor Entregan los Consultores, Más Dependiente se Vuelve el Cliente