Nothing But Thinking Makes It So · Part Five · Chapter 16 · pp. 200–213
The Inventory Problem
The first thing to build at scale is a register, not a better model
The scale changes the question
One agent in one workflow is a technical matter. Tens of millions of agents distributed across an organisation is an administrative matter, and it fails in administrative ways. The recurring incident is not a model producing a wrong answer. It is nobody being able to say which agent produced the answer, who authorised it, what it was permitted to touch, and whether anyone was supposed to check.
That is an attribution problem. Improving the model does not touch it.
What a register has to hold
Identity
A stable identifier for the agent that survives redeployment and version change.
Sponsor
The named human or role accountable for the agent's existence and its continued operation.
Scope
The systems it may read, the systems it may write, and the actions it may take unattended.
Provenance
Base model, version, tooling, prompt lineage and the date each last changed.
Standing
Whether output may be relied upon directly, requires review, or is advisory only.
Retirement
The condition under which the agent is switched off, and who is obliged to do it.
None of these fields is about capability. Every one of them answers a question that will be asked after something goes wrong.
The four failures
- An agent keeps running after the team that created it is reorganised, and no one is obliged to retire it.
- Output is relied upon at a standing higher than it was certified for, because the standing was never recorded.
- An incident review cannot establish which agent acted, on whose authority, or against which version of a policy.
- Two agents hold overlapping write scope on the same system and neither sponsor knows the other exists.
Certification is a standing claim
Certifying an agent is not declaring it correct. It is recording the conditions under which its output may be relied upon, and by whom. That is the same move the volume makes about physical claims: state the standing, keep it attached, and do not let a strong result lend its authority to a weak one.
Policy boundaries follow the same logic. A boundary that is not written into the register is not a boundary; it is an expectation.
Why it belongs in this volume
The framework holds two claims: judge content on merit, keep responsibility human. The second claim is empty at organisational scale without a register, because responsibility that cannot be traced is not held by anyone.
The register is where the human half of the framework stops being a sentiment and becomes a record.