Loop Custody: The Audit Question for Agent-Run Work · The Pritam Edge

For every loop an agent runs, one named human owns the goal, the budget, and the verdicts. The audit question, agent by agent: who can kill its goal, who approves its consequential actions, and where is the record?

Expanded from a post I published on July 5. The question kept getting forwarded, so here is the full essay.

The scene is a boardroom, and it is not hypothetical in spirit. Last Tuesday, an agent made a consequential call: it reprioritized a remediation queue, and a customer-facing defect that should have shipped Friday slid two weeks. Real money, real customers. The CIO listens to the walkthrough of what the agent did, why its reasoning was locally sensible, and how the queue logic worked. Then she asks one question.

"Who owned that loop?"

Silence. Not because the room is incompetent. The room is full of capable people. The silence is because the question has no answer in the org chart. The agent had an owner in the sense that someone deployed it. The workflow had a designer. The model had a vendor. But the loop, the ongoing cycle of goal, action, consequence, that thing had no name attached to it.

That silence is this essay. Let me pull it apart in three threads.

1. What loop custody is

Here is the definition I run my own systems on: for every loop an agent runs, a named human owns setting the goal, funding the work, and judging the consequences. That human is the loop's custodian.

Loop custody: a named human custodian owns the loop — sets the goal, funds the work, judges consequences — while the agent owns the steps. Agents can hold the work; only humans can hold the loop.

Three ownerships, deliberately chosen:

Setting the goal. Someone decides what the loop is for and, crucially, can kill that goal. An agent pursuing a goal nobody currently endorses is not autonomy; it is drift with a budget.

Funding the work. Loops consume tokens, compute, and attention. The custodian owns that spend. When nobody owns the cost, nobody notices when the cost stops matching the value, and the loop becomes organizational dark matter: work that happens because it was once started.

Judging the consequences. When the loop produces outcomes, good or bad, one person is accountable for the verdict: was this acceptable, does the loop continue, does it lose autonomy?

Notice what custody is not. Custody is not supervision of every step. A custodian does not review every agent action any more than a VP reviews every line of code. If your governance model requires a human to watch every step, you have not deployed agents; you have hired very expensive interns and one very tired babysitter. Custody is ownership of the loop: its purpose, its budget, its verdicts. The steps belong to the agent. The loop belongs to a human.

2. The audit question, and what a custody trace looks like

Here is the tool of this essay, and you are welcome to steal it verbatim for your Monday meeting:

For each agent in production: who can kill its goal, who approves its consequential actions, and where is the record?

The audit question for agent-run work, in three clauses: who can kill the goal, who approves the consequential actions, where is the record. A passing custody trace gates only at consequential steps, records verdicts, and earns autonomy by evidence.

Three clauses, three failure modes. If nobody can kill the goal, you have an unowned objective running on autopilot. If nobody approves consequential actions, your risk appetite is whatever the agent improvises. If there is no record, you will reconstruct history from log fragments in the worst week of your quarter, in front of your own CIO.

Ask it literally. Go agent by agent. The agents with three crisp answers are governed. The agents that produce a pause, a "well, sort of," or a name of someone who left the company, those are your incidents in waiting.

What does a passing answer look like? Here is the custody trace from my own systems, an agent workforce I run with human-in-the-loop gates. Three properties:

Gates only at consequential steps. Agents draft, screen, and score without me. But nothing publishes, nothing spends beyond its envelope, and nothing touches an external surface without a human verdict. The gate sits where the consequence is, not where the activity is. Gating every step is as much a custody failure as gating none: it means you never decided which steps matter.

Verdicts recorded. Every gate decision lands in a log: what was approved, what was rejected, why. The record is what turns governance from a personality into a system. When something goes wrong, the question "what did the human know and decide" has a lookup, not an archaeology project.

Autonomy earned by evidence. No agent starts autonomous. An agent that clears its gates cleanly, over a recorded run of verdicts, gets wider latitude. One that drifts gets its latitude pulled back. Autonomy in my systems is not a setting; it is a credit score.

That is a custody trace: gates at consequences, verdicts on record, autonomy moving on evidence. It fits on an index card, and it answers the CIO's question in one breath.

3. What breaks without custody

Now run the counterfactual, because this is where the stakes live.

Without custody, the first thing that breaks is incident response. An agent does something consequential and wrong, and the organization discovers, mid-incident, that accountability was never assigned. The postmortem devolves into the one thing postmortems must never be: a search for someone to blame, conducted among people who all plausibly believed someone else owned it. Unowned loops are how agent incidents become organizational incidents. The technical failure was the agent's; the institutional failure was that the loop had no custodian, and institutions are judged on the second kind.

The second thing that breaks is scale. Ironically, the companies most nervous about agents respond by adding review layers everywhere, which is just custody-by-committee, and committees do not hold loops; they dilute them. The companies that scale agent work safely are the ones where every loop has one name on it. Clear custody is not the brake on autonomy. It is the enabling condition for it, because an organization will only extend real latitude to systems whose consequences someone has visibly agreed to own.

The third thing that breaks is quieter: the loops themselves rot. Goals nobody can kill keep running past their relevance. Budgets nobody owns keep draining. Verdicts nobody records keep evaporating. You end up with a portfolio of agent activity that no one can enumerate, which is the state most enterprises are drifting toward right now, one ungoverned deployment at a time.

The fix does not require a framework, a platform, or a committee. It requires a list of loops and a name next to each one. Start Monday. Ask the question.

Agents can hold the work. Only humans can hold the loop.