← Blog

Guide · 13 September 2026

Who owns an AI agent? Roles, audit and accountability

The first agent in a company usually belongs to whoever built it. By the fifth, nobody is sure who changed the outreach agent's instructions last week, or who is supposed to answer its approvals. As agents take on real work, they need what any other part of the business has: an owner, clear permissions, and a record of changes.

Every agent needs an owner

An owner is the person who answers for an agent: they know what it is for, they review its failures, they decide when it changes. Without one, an agent that starts failing is everybody's problem and nobody's job.

Make it explicit. Every agent has a named owner, and the owner is who gets asked when something about it looks wrong.

Separate building from deciding

Three kinds of permission matter, and they don't have to belong to the same people:

  • Running the workspace: settings, billing, members, provider keys.
  • Building and changing agents: instructions, tools, schedules.
  • Deciding: approving an agent's actions and answering its questions.

In AgentOS these map to three roles:

RoleCan
OwnerEverything, including billing and transferring ownership
AdminRun the workspace: settings, billing, members, provider keys
MemberBuild and change agents in the folders they have access to, and decide approvals

Members see the folders they have been given and the agents they created, so a team can own its own agents without seeing everyone else's.

A table of workspace members: each person's role, how many agents they own and built, and how many runs they started in the last 30 days.
Who owns, built and ran what, by person · Demo workspace

Keep a record nobody can edit

When an agent does something surprising, the first question after "what did it do" is "what changed". A good audit log answers it:

  • who changed an agent's tools, or paused or deleted it, and when,
  • who added or removed an approval gate,
  • who created an API key, and for what,
  • who invited whom, and with which role,
  • who set or changed a budget.

The record is only worth something if it can't be rewritten after the fact. In AgentOS the audit log is append-only: nobody can edit or remove an entry, owners included. The audit log is part of the Enterprise plan.

An audit log: each entry's action, the person who did it, the details of the change and when it happened.
The audit log: action, who, what changed, when · Demo workspace

A short checklist

  • Every agent has a named owner.
  • Only the people who should change agents can.
  • Everyone who can decide approvals knows the queue is theirs to answer.
  • Changes to agents, keys and members leave a record.

See your own agents like this

AgentOS records every run, pauses risky actions for approval, and tells you when an agent breaks.