# Human accountability

The operating discipline that assigns a named human role authority and answerability for an agent’s purpose, risk, decision rights, authorization, intervention, outcomes, and lifecycle.

core-concept · Security & governance · maturing · Reviewed 2026-08-09

## Definition

The operating discipline that assigns a named human role authority and answerability for an agent’s purpose, risk, decision rights, authorization, intervention, outcomes, and lifecycle. Agency can be delegated. Enterprise accountability cannot.

Human accountability is established; agent-specific roles and decision models are still being operationalized.

## Why it matters

Agency can be delegated. Enterprise accountability cannot.

The operating shift is from “A human somewhere in the loop” to “A named human with decision authority.”

## System anatomy

- **Practice 1:** Assign exactly one accountable role per consequential decision
- **Practice 2:** Publish decision rights and escalation paths
- **Practice 3:** Keep override, suspension, and risk acceptance human-authorized



## Important distinctions

- **A human somewhere in the loop:** This concept moves the engineering system toward a named human with decision authority.



## Implementation signals

- Assign exactly one accountable role per consequential decision
- Publish decision rights and escalation paths
- Keep override, suspension, and risk acceptance human-authorized

## Failure modes

- Accountability diffused across a committee or vendor
- A review click treated as ownership of the outcome



## Related knowledge

- [Agent identity & delegated authority](https://aisdlc.ai/agentic-engineering/agent-identity) — The identity and authorization discipline that treats an enterprise agent as a non-human principal with attributable, purpose-bound, time-bound permissions.
- [Risk-tiered autonomy](https://aisdlc.ai/agentic-engineering/risk-tiered-autonomy) — The practice of classifying an agent by impact, data sensitivity, action scope, and reversibility, then binding that tier to maximum autonomy, required controls, approval authorities, and monitoring depth.
- [Continuous recertification & retirement](https://aisdlc.ai/agentic-engineering/continuous-recertification-retirement) — Scheduled and event-driven reassessment that renews, restricts, transfers, suspends, or ends an agent’s authority—and verifiably revokes its identities, credentials, tools, dependencies, and retained data at retirement.

## Sources and further study

- [Microsoft Agentic Center of Excellence — Define roles, responsibilities, and decision rights](https://learn.microsoft.com/en-us/agents/center-of-excellence/roles-responsibilities) — An operating model that assigns one accountable role per decision and distinguishes domain, platform, risk, and runtime responsibilities. **Use:** Official guidance. **Limitation:** Guidance describes recommended practice; citation does not prove that a control is implemented or effective in a particular environment.
- [Microsoft Entra Agent ID — Administrative relationships in Microsoft Entra Agent ID](https://learn.microsoft.com/en-us/entra/agent-id/agent-owners-sponsors-managers) — Separates technical ownership from business sponsorship and assigns sponsors lifecycle, access-review, and incident-response decisions. **Use:** Official guidance. **Limitation:** Guidance describes recommended practice; citation does not prove that a control is implemented or effective in a particular environment.
- [NIST NCCoE — Identity and Authority for Software Agents concept paper](https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf) — A concept paper exploring how established identity and authorization practices can apply to software and AI agents. **Use:** Official guidance. **Limitation:** Guidance describes recommended practice; citation does not prove that a control is implemented or effective in a particular environment.

---

This library synthesizes cited research, standards, official documentation, and clearly attributed practitioner perspectives. Maturity describes the state of a concept—not vendor endorsement, production readiness, or permission to deploy. Benchmarks and demonstrations do not replace use-case evaluation, governed controls, independent verification, or named human release authority.
