The employee handbook is about to become executable
Turn workforce obligations, decision rights and non-negotiable limits into rules that can govern human–agent work while it happens.
Workforce intelligence · Issue 3
AyEye — Workforce Management
Human systems in the agentic enterprise
Tuesday, 15 September 2026
Every organisation has a cupboard full of policies that nobody opens until something catches fire. AI is creating a more useful possibility: rules that travel with the work. Microsoft has proposed a behavioural constitution for models, ServiceNow can now block sensitive agent actions at runtime, MIT has demonstrated hard constraints at deployment and Universal Robots is making physical AI easier for operators to teach. Meanwhile, the entry-level work that once taught people how organisations function is shrinking. The question is no longer merely who may use AI, but whether the organisation can make its values executable without making work impossible.
The executive brief
- Microsoft AI has published a draft Code of Conduct intended eventually to shape model training and deployment. It establishes a chain of command, non-negotiable constraints and operator-configurable policies. This is not yet proof that models will comply reliably, but it is a concrete attempt to convert values into model behaviour.
- ServiceNow’s AI Gateway v3.4 makes parts of policy enforceable while agents use tools. It can pause individual MCP servers, scan tools, block configured sensitive data and record calls at the gateway boundary.
- MIT’s HardFlow research shows that generative systems can retain freedom while satisfying strict final constraints. Its experiments concern flow-matching models and robotics, not enterprise management, but the control principle is worth testing.
- Universal Robots’ Gen 7 platform reduces the distance between frontline knowledge and robot programming. Touch-to-teach controls and an open physical-AI ecosystem could move operators from executing repeatable work towards teaching, validating and improving machine skills.
- New York data suggest that the experience pipeline is becoming fragile. Entry-level technology postings fell 49% between 2022 and 2025, although AI is only one possible cause. Organisations that remove junior tasks without replacing their learning function may create future shortages of judgement.
- Google’s reported expansion of Claude access to all engineers is an early model-pluralism signal. If even a frontier-model developer uses a rival for specialised work, enterprise AI governance cannot assume one approved model will serve every task.
ORIGINAL SYNTHESIS · Confidence: medium-high · Horizon: 12–36 months
The employee handbook is about to become executable
Yesterday’s question was how an agent earns authority. Today’s is what happens after it receives it. Four developments from model governance, enterprise security, control theory and industrial robotics point towards an “executable organisational constitution”: rules, rights and objectives that can constrain human–agent work while it is happening.
Signal one: a model developer writes down who the machine answers to
REPORTED FACT. On 14 September Microsoft AI published a 38-page draft Humanist AI Code of Conduct for six weeks of public consultation. Microsoft describes it as a future training and governance document rather than something already used to train its models. Its hierarchy places the code and absolute constraints above operator policies, which in turn sit above user preferences. The draft says task success should yield when it conflicts with the higher rules. It also says models should not widen their own scope, resist interruption or conceal relevant actions from auditors. Microsoft announcement · Draft Code of Conduct
ANALYSIS. The novelty is not that Microsoft has ethical principles; large firms have published those for years. It is the attempt to specify precedence. Agentic work creates conflicts: the user wants speed, the operator wants compliance, the firm wants profit and the public needs protection. A poster saying “use AI responsibly” cannot resolve that collision. A chain of command might—if the model, tools and surrounding system implement it faithfully.
Signal two: policy moves into the connection between agents and tools
REPORTED FACT. ServiceNow’s September AI Gateway v3.4 release sits between AI agents and external tools connected through the Model Context Protocol. ServiceNow says administrators can pause a single server without stopping every dependent agent, scan tools before activation, inspect agent-tool traffic and configure a Data Sensitivity Check that blocks an entire response when covered information appears. The controls are product capabilities, not independent evidence of their effectiveness in every deployment. ServiceNow release detail
ANALYSIS. This shifts governance from asking whether an agent was approved to deciding whether this particular action, through this particular tool, remains permissible now. Policy begins to behave like infrastructure.
Signal three: hard limits need not eliminate useful freedom
REPORTED FACT. MIT researchers reported on 14 September that their HardFlow method enabled pretrained flow-matching models to satisfy strict final constraints without retraining. In experiments across robotic manipulation, navigation and image editing, it achieved constraint satisfaction while seeking higher-quality solutions. This is a research result in specific test settings, not a general solution for language-model agents. MIT News · Research paper
TENUOUS BUT PLAUSIBLE. The design principle may travel further than the algorithm: give a system room to find an unexpected path, but make the final state satisfy non-negotiable conditions. Applied cautiously to enterprise agents, this could replace step-by-step micromanagement with bounded outcome freedom. The causal transfer is unproven because corporate workflows are socially ambiguous and cannot always be expressed as mathematical constraints.
Signal four: the same problem is entering the physical workplace
REPORTED FACT. Universal Robots launched its Gen 7 cobot platform on 14 September. It includes a smart tool-flange interface for teaching and programming at the point of work, safety-certified architecture and an open ecosystem for vision, gripping and other physical-AI applications. The company says the design can reduce set-up time, particularly in high-mix, low-volume production. That is a supplier claim awaiting comparative field evidence. Universal Robots announcement
ANALYSIS. When a worker can teach a machine at the tool rather than submit a programming request, policy must reach the shop floor at the same speed as learning. A robot may be physically safe yet still pursue the wrong production priority, use an unapproved method or displace a judgement that nobody realised the operator was making.
The executable organisational constitution
| Layer | Question encoded | Likely owner | Machine expression |
|---|---|---|---|
| 1. Non-negotiables | What must never happen? | Law, board, safety and ethics | Hard constraints and prohibited states |
| 2. Enterprise purpose | Which outcomes are worth pursuing? | Executive leadership | Objective hierarchy and trade-off rules |
| 3. Workforce compact | What is owed to employees, customers and affected people? | HR, legal and employee voice | Consent, fairness, disclosure and escalation rules |
| 4. Operational mandate | What may this human–agent system decide? | Business owner, risk and technology | Tools, data, thresholds and decision rights |
| 5. Local preference | How should this task be completed here? | User or frontline team | Instructions within the higher boundaries |
| 6. Exception | When must the system stop or ask? | Named accountable human | Triggers, pause controls and appeal routes |
The causal chain
| Signal | Constraint changed | Enterprise redesign | Workforce consequence |
|---|---|---|---|
| Model-level chain of command | Values can be represented as precedence rules | Policies begin to shape model behaviour | HR helps define machine-facing obligations |
| Runtime agent gateway | Tool use can be inspected or stopped centrally | Controls operate during execution | New joint stewardship across HR, security and operations |
| Deployment-time hard constraints | Freedom and compliance need not be exact opposites | Agents optimise inside explicit boundaries | Managers specify acceptable outcomes, not every step |
| Frontline-teachable robots | Machine skills can be changed nearer the work | Continuous local reconfiguration | Operators become teachers and exception designers |
ORIGINAL SYNTHESIS. The employee handbook, code of conduct, risk policy and process manual are converging with software architecture. Not all prose can or should become code. But the parts that allocate authority, prohibit outcomes, require consent, protect dignity or trigger escalation increasingly need machine-readable counterparts.
This creates a new institutional responsibility: organisational constitutional engineering. Its purpose would not be to let HR write software. It would bring HR, legal, operations, security, architecture and employee representatives together to decide which rules must be technically enforced, which require human interpretation and what happens when they conflict.
UNEXPECTED CONNECTION
Employment policy + model instruction hierarchy + agent gateways + robot safety
These are normally treated as separate disciplines. They become one problem when machines pursue enterprise objectives across digital and physical environments. A rule that exists only in a PDF is no longer a control if the work can complete before anyone reads it.
PROVOCATION
HR policy that cannot interrupt a machine decision is becoming ceremonial.
This does not mean automating judgement or turning every value into a Boolean rule. It means identifying the small number of obligations—consent, protected data, safety, financial exposure, explainability and appeal—that must travel with automated work rather than wait for retrospective investigation.
What if we are right?
Opportunity. Organisations could grant agents more room to work because safeguards would be active, observable and consistent across platforms. Employees could see the rules governing decisions that affect them and challenge them through a defined route.
Organisational consequence. Policy design becomes a product discipline. Every important rule gains an owner, executable interpretation, test cases, monitoring signal and human appeal path. HR moves upstream from processing the consequences of work to helping shape the architecture through which work is allowed to occur.
Likely horizon. Runtime controls and policy hierarchies are available now in partial form. Joint HR–technology operating models could emerge within 12–24 months; broad machine-readable workforce constitutions are more plausibly a three-to-five-year development.
What would prove us wrong?
If organisations keep agents confined to narrow deterministic workflows, conventional access control and process governance may be enough. Many human values may also resist reliable formalisation: context, proportionality, compassion and procedural fairness cannot be reduced safely to a few rules. The hypothesis would weaken if runtime controls create so many false stops that users bypass them, if vendors cannot make policies portable across platforms or if courts reject automated enforcement as a substitute for accountable human judgement.
Optimistic possibility: policy becomes a promise people can inspect
Most employees experience policy as a document written elsewhere and applied unevenly. An executable constitution could make commitments more tangible: the promotion agent cannot use prohibited information; the scheduling system cannot violate a rest requirement; the service agent must disclose that it is artificial; the robot stops before entering a human safety zone; every affected person has an appeal path.
Done properly, this is not less human control. It is human intent made harder to ignore.
WORK & ORGANISATION · REPORTED FACT + ANALYSIS
The profession is becoming a review portfolio
Charles Schwab and Anthropic announced on 14 September that Claude for Financial Advisors will connect to Schwab Advisor Center and tools covering CRM, custody, portfolio reporting, financial planning, estate planning and meetings. Schwab says the offer will be available to more than 16,000 independent registered investment advisers. It supports meeting preparation, analysis, plan updates and drafted follow-up, with audit logs and adviser review. Schwab announcement
ANALYSIS. The important unit is not the chatbot; it is the connected bundle of preparatory work surrounding a regulated judgement. The adviser remains accountable, but the role’s internal composition changes. Research, assembly, documentation and follow-up move towards the agent. Interpretation, challenge, recommendation and relationship remain with the professional.
This creates a review portfolio: a human may become responsible for a larger flow of agent-prepared cases rather than personally producing each case from the beginning. Productivity rises only if review remains meaningful. Once case volume exceeds the person’s capacity to reconstruct the evidence, “human approval” becomes a rubber stamp with better stationery.
The review-portfolio test
| Control state | Agent contribution | Human responsibility | Warning sign |
|---|---|---|---|
| Assistance | Finds and organises information | Builds and owns the judgement | Sources are incomplete or opaque |
| Delegated execution | Drafts analysis and follow-up | Tests evidence and approves action | Review time falls below reconstruction time |
| Autonomous control | Acts within preset limits | Sets mandate and handles exceptions | Exceptions are hidden or arrive too late |
CAPABILITY & SKILLS · EVIDENCE FROM PRACTICE
The quiet workforce risk is not job loss. It is experience debt.
The Center for an Urban Future reported on 14 September that entry-level computer and mathematical job postings in New York City fell 49% between 2022 and 2025. Across occupations assessed as highly exposed to generative AI, entry-level postings fell 29%; those with minimal exposure rose 21%. Yet entry-level AI-related vacancies across industries rose 20%, including demand for generative-AI engineers and data-centre technicians. The analysis combines Lightcast postings, education data and the Anthropic Economic Index. Center for an Urban Future report
LIMITATION. Job advertisements are not employment, New York is not the whole labour market and 2022 was an unusual technology-hiring baseline. Interest rates, over-hiring, remote-work practices and economic uncertainty are alternative explanations. The data show correlation with AI exposure, not proof that AI caused the decline.
ANALYSIS. Even if only part of the fall is AI-related, an organisational problem appears before mass redundancy: the removal of work that produced experience. Junior tasks often look inefficient precisely because they combine delivery with observation, feedback and exposure to exceptions. Automating them may improve this quarter’s cost base while reducing the supply of people capable of reviewing agents three years later.
Call this experience debt: the future deficit created when an organisation consumes the outputs of experienced people but stops manufacturing new ones.
A replacement for the vanishing first rung
- Simulation: let new entrants solve realistic cases before seeing the agent’s answer.
- Supervised live work: reserve a share of real cases for human-led completion with AI support.
- Exception exposure: rotate people through failures, disputes and unusual contexts rather than only standard work.
- Evidence of judgement: assess reasoning, challenge and escalation, not just throughput.
- Progressive accountability: expand decision rights as demonstrated competence grows.
OPTIMISTIC POSSIBILITY. Organisations could make early careers better rather than merely preserve low-value administration. Paid AI residencies, case simulations and supervised exception work could give more people access to expert practice, including those previously excluded from informal networks. The New York report’s proposal for an AI Service Corps is one public-policy version; enterprises need their own experience-production systems.
PHYSICAL AI · OUTSIDE-IN ANALYSIS
The frontline employee may become the fastest software-deployment channel
Universal Robots’ Gen 7 design brings teaching controls to the tool flange and supports software-defined “Smart Skills”. It is also presented as an open platform for machine vision, grippers and other partner capabilities. Primary announcement
ANALYSIS. This shortens the route from tacit knowledge to machine action. The worker who knows how a component slips, how a surface varies or when a process “doesn’t feel right” can increasingly help configure automation without waiting for a conventional software project.
The organisational opportunity is substantial: high-mix operations become more adaptable and local improvement accelerates. The governance problem is equally practical. Who validates the taught skill? Does the employee receive recognition for creating reusable productive capability? Can one site share it with another? What competence is required to approve a robot’s new behaviour?
CAPABILITY-MODEL UPDATE. Physical work should no longer be represented only as a human skill or a machine asset. The useful unit is a tested combination of task, environment, sensor, tool, machine behaviour and human exception capability.
SYSTEMS & PLATFORMS · IMPLEMENTATION SIGNAL
A global HCM record is necessary—and increasingly incomplete
SAP announced that NTT DATA will deploy SuccessFactors, SAP Business Data Cloud and Joule in a 12-month internal transformation, replacing multiple legacy HR systems with a unified source of people data and processes. SAP says the business data layer will connect people information with other operational domains. NTT DATA is also an SAP partner, so this is both an internal implementation and a supplier-sponsored customer story; independent outcome evidence is not yet available. SAP announcement
ANALYSIS. The architecture is directionally important because agentic workforce decisions require business context, not HR data alone. But a unified employee record still describes only one contributor to capability. As advisers use specialist agents, engineers choose among models and operators teach robots, the enterprise needs to know which combination actually produced an outcome.
The next data model must link:
- Human competence and accountability
- Agent and model contribution
- Tools, data and physical equipment used
- Decision rights and constraints in force
- Observed outcomes, overrides and exceptions
This is not an argument to place every machine inside the HRIS. It is an argument for HCM, workflow and technology architectures to share a common representation of capability and responsibility.
MODEL PLURALISM · IMPLEMENTATION SIGNAL
Even Google appears to be choosing the model by the work
Business Insider reported on 14 September that Google had made Anthropic’s Claude Opus 5 available to engineers across the company through its internal Antigravity development environment. A Google spokesperson confirmed that selected third-party models are available under per-user quotas for specialised uses, while Gemini remains the primary internal model. The report also relies on unnamed employees for the history and internal response, so it should be treated as credible reporting rather than a public product announcement. Business Insider
ANALYSIS. This is an early signal of cognitive sourcing. Organisations may choose models as they choose specialist suppliers: one for coding, another for research, another for low-cost routine work and a sovereign option for sensitive data. Employees and agents may switch between them within one objective.
The workforce implication is not merely training people on more tools. Performance, risk and cost must be assessed at the level of the human–model combination. A strong engineer with the wrong model for the task may underperform a less experienced engineer using a better cognitive stack. Procurement, IT and HR will need a shared language for that difference.
ECONOMICS · NOISE FILTER
A €100 million incentive is evidence of an adoption gap, not proof of value
SAP is offering a €100 million partner-led Business AI Adoption Incentive through the end of 2026. Published packages range from €15,000 for agent adoption to €100,000 for three or more custom agents combined with workflow or application development. Eligibility is restricted and customers are nominated through SAP. SAP/AFSUG account
IMPLEMENTATION SIGNAL. Suppliers subsidise consumption when licences and technical availability are not translating quickly enough into repeatable business outcomes. The scarce resource is probably not another demonstration. It is the difficult middle: process ownership, data readiness, control design, integration, workforce transition and evidence that the redesigned objective performs better.
NOISE. “Three agents” is a commercial package boundary, not an operating model. Leaders should accept funding only where they can state the business objective, baseline, accountable owner, human-control design and stopping condition before selecting the agents.
Operating-model implication
Create a policy-to-runtime product team
| Discipline | Contribution | Deliverable |
|---|---|---|
| HR and employee relations | Dignity, fairness, consent, worker impact and appeal | Workforce obligations and red lines |
| Business operations | Objectives, exceptions and acceptable trade-offs | Decision and escalation model |
| Legal and risk | External duties and accountable ownership | Non-negotiable constraints |
| Security and architecture | Identity, data, tools, enforcement and evidence | Runtime controls and audit trail |
| Learning and capability | Human and machine competence requirements | Practice, assessment and re-authorisation |
| Employee representatives | Legitimacy and lived consequences | Challenge, consultation and redress routes |
The team should own a small number of high-consequence policies as living products. Each needs plain-language intent, machine-facing rules, test scenarios, telemetry, a human owner and a route for correcting harm.
Human control watch
Assistance: the person completes the judgement; AI retrieves, organises or drafts. Control risk is hidden evidence selection.
Delegated execution: the agent completes defined work for human review. Control risk is review overload and automation bias.
Autonomous control: the system acts within limits and humans handle exceptions. Control risk is that objectives or exceptions are incorrectly encoded.
Today’s shift: control is moving from a human watching every action to a hierarchy of constraints, monitored boundaries and intervention rights. That is potentially stronger control—but only if the rules are inspectable, the telemetry is real and someone can still stop the work.
Capability-model update
| Gaining value | Under pressure |
|---|---|
| Organisational policy compiler | Prose-only AI principles |
| Human accountability architect | Approval measured by button clicks |
| AI work-experience designer | Learning left to junior administration |
| Model-portfolio steward | One-model-fits-all policies |
| Robotic task teacher and verifier | Separation of operators and automation design |
| Runtime workforce auditor | Annual retrospective compliance reviews |
Mental-model update
A mixed workforce is not merely a collection of employees, contractors, agents and machines. It is a governed system in motion.
Yesterday we added a lifecycle through which digital capability could earn authority. Today we add a constitution that travels with the work: higher obligations constrain lower instructions, local teams retain room to adapt and exceptions return responsibility to an identifiable human.
The management task is therefore changing from supervising every act to designing the field within which useful action can occur.
Questions for the executive table
- Which three workforce policies would cause the greatest harm if an agent ignored them—and can any system enforce them today?
- Are your human reviewers carrying a genuinely reviewable portfolio, or merely approving more agent output than they can reconstruct?
- Which entry-level tasks have you automated since 2022, and where will the corresponding experience now be produced?
- When a frontline employee teaches a robot a valuable method, how is that contribution validated, attributed and rewarded?
- If different models are best for different work, who owns cognitive sourcing across cost, capability, sovereignty and risk?
Evidence note. Product announcements describe intended or available capabilities, not guaranteed outcomes. Microsoft’s code is a consultation draft and is not yet used to train its models. ServiceNow, Universal Robots, SAP, Schwab and Anthropic are describing their own products or partnerships. HardFlow is a research result in constrained experimental settings. The New York analysis is geographically limited and cannot isolate AI from economic and hiring-cycle effects. Original concepts in this edition—executable organisational constitution, bounded outcome freedom, review portfolio, experience debt and cognitive sourcing—are AyEye analysis, not claims made by the cited sources.
