Former Microsoft Identity President, Joy Chik, Joins NewCore Board

Every Agent Action Needs an Owner: Building Accountability into AI Agents

AI agents need accountability. Learn how identity, delegation, approval, and audit controls give every agent action a clear owner.

Noa PressmanProduct ManagerOct 05, 20268 min read

AI agents no longer just suggest what to do; they do it. They open pull requests, send emails, provision accounts, move money, and change production systems. Sooner or later, one of them will do something it shouldn't, and someone will ask the oldest question in any organization: who is responsible for this?

For people, we have good answers. Every employee has a name, a manager, a role, and a set of permissions someone signed off on. When something goes wrong, there is a chain of accountability to follow. For most AI agents today, that chain doesn't exist. The agent ran under a shared service account, with credentials nobody remembers issuing, doing something nobody explicitly approved.

Human oversight is how you rebuild that chain. It isn't a brake on autonomy. It's what makes autonomy accountable, and accountable autonomy is the only kind you can safely scale.

The accountability gap

When a chatbot gives bad advice, accountability is simple: a person has read the output and chose to act on it. Agents remove that person from the moment of action. That creates a gap, and three properties of agents make it wider.

First, responsibility gets diffused. An agent's action involves the model, the person who launched it, and the owner of every system it touched. When everyone was involved, it's far too easy for no one to be accountable.

Second, actions can drift from anyone's intent. Agents misread ambiguous instructions, take shortcuts nobody sanctioned, and can be hijacked by instructions hidden in the documents, pages, and emails they process. An action nobody intended is an action nobody owns, unless you design for it.

Third, agents act on borrowed authority. When an agent calls an API, it uses permissions that belong to a person or a service. If that authority isn't traced back to someone who granted it, you have created a privileged actor with no one answerable for it.

Regulators and auditors are closing this gap from the outside. Frameworks like the EU AI Act and the NIST AI Risk Management Framework put meaningful human oversight at the center of responsible deployment. Whether or not a rule applies to you, customers and security teams will increasingly expect you to show who approved what an agent did.

Four questions every agent action must answer

Accountability for agents comes down to four questions. If your systems can't answer all of them for any action, after the fact and without guesswork, you don't have oversight.

QuestionWhat it requires
Who acted?A distinct identity for every agent
On whose behalf?A traceable link to the person or process that delegated the task
Who authorized it?A recorded decision for any action above a risk threshold
Can we prove it?A tamper-resistant audit trail of every action and approval

Not every workflow will require human oversight. An agent summarizing tickets or drafting internal notes can run on its own, with logs as the only record needed. But many critical workflows do: anything that touches production, customer data, money, permissions, or external communication. Accountability should scale with consequence, judged by how much damage an action could do and how reversible it is.

ImpactExample actionsWho answers for it
Low, fully reversibleReading a file, searching a knowledge base, drafting a documentThe delegating owner, via logs
Moderate, usually reversibleUpdating a record, creating a ticketThe delegating owner, with after-the-fact review
High, often irreversibleDeleting data, sending external messages, granting permissions, deploying to production, spending moneyA named approver, before the action runs

This avoids both failure modes. Demand sign-off for everything and approvers start rubber-stamping, which spreads accountability so thin it means nothing. Demand it for nothing and the first serious incident has no owner at all.

Building the accountability chain

Accountability can't live in a system prompt. Telling an agent to "ask before doing anything risky" is a request, not a control, and a well-crafted injection can talk the model right past it. The chain has to be built into the infrastructure around the agent, one link at a time.

Identity: know who acted. Every agent should authenticate as itself, not as the person who launched it and not through a shared service account. A distinct identity is the anchor for everything else: you can scope its permissions, attribute its actions, and revoke its access without touching anything else.

Delegation: know on whose behalf. Every agent should have a named human owner, and every task should record who delegated it. When agents spawn sub-agents, the link has to carry down the chain, so an action five layers deep still traces back to a person.

Least privilege: limit what anyone can be accountable for. An owner can only answer for authority they understood when they granted it. Give agents only the permissions a task requires, for only as long as it takes. Just-in-time, task-scoped credentials keep the blast radius, and the owner's exposure, small.

Approval: know who authorized it. High-consequence actions should be unable to run without a human decision, enforced in the tool or API the agent calls rather than in its instructions. The system pauses, routes the request to the accountable person, and proceeds only on an explicit yes. The model can't argue its way past a gate it doesn't control.

Informed consent: make approvals mean something. An approver is only accountable for what they could see. "Agent wants to run delete_records. Approve?" invites a reflexive click. Show what will happen, to which resources, why the agent thinks it's needed, and how to roll it back. Route requests to someone with the context to judge them, and let unanswered requests expire as denials.

Audit: be able to prove it. Every action should produce a record of the agent, its owner, the delegator, the action, the target, the outcome, and who approved it. That record is how you investigate incidents, satisfy auditors, and spot behavior drifting before it becomes a problem.

Revocation: know who can stop it. Accountability includes the power to intervene. The owner should be able to halt an agent, revoke its credentials, and stop in-flight work immediately. Test that path before you need it. A kill switch nobody has used is a hope, not a control.

Rubber stamps aren't accountability

The quiet threat to accountability is volume. An approver who sees fifty requests a day stops reading them by day three, and a signature given without attention is accountability in name only. Protect your approvers' attention as carefully as you protect your systems.

Batch related low-risk actions into a single review. Let owners approve a plan up front, then gate only the steps that deviate from it. Track approval rates, and treat a near-100% rate as a warning sign: either the gate covers actions that don't need it, or people have stopped paying attention. Revisit your tiers regularly.

Trust follows the track record

The goal isn't to keep humans approving every step forever. It's to make every extension of trust a deliberate, recorded decision by someone who can answer for it. Start new agents with tight gates and narrow permissions. As the audit trail shows consistent, correct behavior on a class of actions, the owner can move those actions down a tier. When something goes wrong, the trail shows exactly where to tighten.

This is how we already treat new employees. Nobody gets production access on day one, and nobody earns the keys to everything without a track record. Agents deserve the same treatment: not suspicion, but accountability proportional to power.

How NewCore makes agents accountable

Every link in the accountability chain runs through identity. That's why NewCore, a next-gen IdP built for humans and agents alike, treats agent accountability as an identity problem, not a model problem.

Who acted. Most identity platforms were built for people and later stretched to cover machines. NewCore was built from the ground up to treat software agents as first-class identities rather than as traditional machine credentials, so every agent has its own identity and every action has an owner.

On whose behalf, and with what authority. NewCore manages the full lifecycle of AI agents, provisioning them with minimal access before they operate and governing sub-agents and short-lived workloads at machine speed. As people spawn agents that spawn their own sub-agents, authority stays traceable all the way down the chain.

Who authorized it, and who can stop it. The NewCore mobile app puts the accountable human in the loop, letting people approve, audit, and terminate agent permissions biometrically, in real time. Approval, audit trail, and kill switch sit in one place, on a bound device, in the hands of the person who answers for the agent.

Proof you can trust. Accountability is only as strong as the credentials behind it. Agentic Skill packages for tools like Claude Code, Codex, and Cursor give agents managed access without anyone handing out keys manually, so the accountable path is also the easy one.

The result is the model this post describes: every agent has an owner, every action has a record, and every high-stakes decision has a name attached. That doesn't slow your agents down. It's what lets you trust them enough to move fast.

Subscribe to our blog.

New posts, sent when published.