Every autonomous agent creates management work
Agent lifecycle systems and enterprise orchestration platforms are making machine work visible while the human labour of briefing, routing, checking and recovery remains hidden. The next management delayering may remove managers while increasing management.
Workforce intelligence · Issue 8
AyEye — Workforce Management
Human systems in the agentic enterprise
Wednesday, 23 September 2026
The organisation chart has a small visibility problem. It records who manages people, but not who spends the afternoon briefing agents, choosing models, checking their work, correcting exceptions and carrying the consequences. New workforce and enterprise systems are beginning to formalise the machine side of that relationship. Human work design has not caught up. Every autonomous agent creates management work—even when no manager appears.
The executive brief
- Beeline and Insygna are putting AI agents into the extended-workforce system. Their integration gives agents requisitions, credentials, rate cards, budgets, activity records and retirement. It is a serious attempt to make machine capacity governable—but it also imports labour-market metaphors that can conceal the human work around the agent.
- SAP is assembling an operating backbone for agentic work. Process intelligence, architecture governance, adoption, monitoring and a proposed “Company Memory” are being joined so agents can act across the enterprise. This is not HCM, yet it is beginning to perform functions analogous to work design and management.
- Workers are already managing AI in the shadows. Workday’s survey says half of respondents deliberately concealed AI use at least once in the previous month; managers and leaders reported more concealment than individual contributors. The figures are vendor-sponsored, but the trust gap is an operating signal.
- Cybersecurity shows why orchestration is real work. Palo Alto Networks says no single frontier model found more than 40% of vulnerabilities in its evaluation, so its new service routes tasks among several models and human experts. The work is not “use AI”; it is compose, compare, validate and act.
- Autonomy does not remove management; it moves it into the system. Cisco Talos has analysed malware that lets four commercial models vote on constrained actions without continuous human direction. The sample’s live deployment is unconfirmed, but its architecture makes the principle unusually visible.
- Language can quietly affect the quality of AI assistance. Johns Hopkins researchers found that four model families produced less formal, less complex workplace text when prompts contained linguistic patterns associated with women. An agent portfolio can amplify difference before any conventional performance system sees it.
ORIGINAL SYNTHESIS · Confidence: medium-high · Horizon: 6–24 months
Every autonomous agent creates management work
Agents move execution away from people, but they do not abolish briefing, allocation, review, correction, escalation or retirement. Those activities are becoming a second management system beneath the formal organisation chart.
Signal one: the contingent-workforce system now has a lane for agents
REPORTED FACT. On 22 September, Beeline and Insygna announced an integration that lets enterprises manage AI agents alongside non-employee workers in Beeline’s extended-workforce platform.
The integration is intended to cover the full lifecycle: requisition, onboarding, identity and credential checks, work assignment, rate cards, spending caps, activity records, cost attribution, offboarding and retirement. It also promises business-readable logs showing which agent acted, under whose authority and at what cost. The companies say the capability is available to Beeline customers now. These are supplier claims; field evidence about accuracy, adoption and control quality is not yet public. Beeline–Insygna announcement, 22 September
ANALYSIS. This is more than an agent register. Procurement and workforce systems are beginning to treat machine capability as something that can be requested, priced, assigned, observed and withdrawn.
That is useful because an agent costs money, consumes permissions and contributes to an objective. But the apparent neatness creates a trap. The digital record may show an agent’s rate and activity while missing the employee who prepared its context, rewrote its brief, compared its answer, repaired its error and absorbed the interruption.
A machine can become legible before its human complement does.
Signal two: enterprise architecture is becoming a management substrate
REPORTED FACT. SAP set out on 22 September how its business-transformation tools are intended to support agents at scale. SAP Signavio models and measures processes; LeanIX maps applications, data and governance; WalkMe guides users and puts agents inside workflows; Cloud ALM tests and monitors operations.
SAP also previewed “Company Memory”, described as a consistent source of enterprise rules, standards and process knowledge for people and agents. The announcement is a product vision from the supplier, and availability varies. It nevertheless shows the management problem appearing outside the HCM suite: agents need context, boundaries, placement, observation and change control. SAP, 22 September
ANALYSIS. An organisation chart tells an employee where they sit. This emerging stack tells an agent what the process is, which systems exist, which policy applies, how to enter the work and whether its behaviour remains healthy.
Those are management functions expressed in software. They do not make human managers obsolete. They create a distributed managerial layer shared by business owners, architects, process teams, risk functions, frontline workers and platforms.
Signal three: people are already hiding the new work
REPORTED FACT. Workday says half of 5,400 employees in its August global survey deliberately concealed their AI use at least once in the previous month. Reported concealment was higher among managers and senior leaders, at 58–61%, than among individual contributors, at 35%.
Only 42% trusted their employer to deploy AI in ways that benefit employees; 25% expressed distrust and 33% were neutral. Among individual contributors, 53% said they had not discussed AI with their manager, and only 7% reported regular conversations. This is a vendor-sponsored survey relying on self-report, and the published summary does not establish what “hiding” covered in each workplace. Workday, 22 September
ANALYSIS. Concealed use is often framed as a security problem or evidence of poor policy. It is also hidden organisation design.
When a person privately assembles prompts, tools and agents to deliver an outcome, they are deciding how work is decomposed, allocated, checked and integrated. That is management—just without a title, capacity allowance, common method or learning loop.
The manager who hides AI use is not necessarily evading work. They may be building a second operating model because the official one has no language for what they are doing.
Signal four: a model portfolio requires an orchestrator
REPORTED FACT. Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense on 22 September. The service combines human offensive-security experts with a harness that routes work among Anthropic, OpenAI and open-weight models.
The company says no single model found more than 40% of vulnerabilities in its evaluation and that leading models overlapped on fewer than 10% of the exposures they identified. It reports that internal use compressed more than a year of traditional testing into three weeks, found 3.2 times more high or critical vulnerabilities per product and reduced mean remediation time by 51%. These performance figures come from the supplier and need independent replication. The structural evidence is stronger: different models found materially different things, so coverage depended on orchestration and expert validation. Palo Alto Networks, 22 September
ANALYSIS. The unit of productive capacity is not the model. It is the managed assembly: objective, context, routing, comparison, verification and remediation.
Companies often budget for model licences and infer labour savings. The expensive managerial activity between the licence and the outcome is easily left in somebody’s calendar.
The agent-management loop
| Management work | What the person or platform does | Where it currently hides | Evidence worth retaining |
|---|---|---|---|
| Frame | Translate an objective into a bounded assignment | Prompting, meetings and private notes | Objective, trade-offs and success test |
| Equip | Supply context, tools, data and permissions | Search, file preparation and access requests | Sources, version and mandate |
| Route | Choose the agent, model or human best suited to the step | Tool choice and individual habit | Reason for allocation and alternatives |
| Judge | Check quality, combine outputs and notice missing context | “Quick review” and cognitive load | Tests, disagreements and corrections |
| Intervene | Stop, narrow, escalate or repair an exception | Unplanned recovery work | Trigger, decision and consequence |
| Learn or retire | Improve the pattern, withdraw authority or remove the agent | Local workarounds and unused licences | Performance history and exit decision |
ORIGINAL SYNTHESIS. These signals reveal a shadow management layer: the people, platforms and routines that translate business objectives into machine assignments, keep those assignments inside bounds and turn their outputs back into organisational action.
The work within it is orchestration labour. It includes briefing, context assembly, routing, evaluation, exception handling, cost control and retirement. Some of it can and should be automated. What remains is often cognitively dense, interruption-prone and consequential.
Yesterday’s edition argued that responsibility should follow effective control rather than the nearest user. Today’s evidence adds a changed implication: before responsibility can be fair, management work must be visible. An employee cannot be credibly accountable for an agent portfolio if the organisation treats the time needed to govern it as free.
This creates a management displacement paradox. Organisations may remove managerial layers as agents take on coordination and execution, yet the total amount of managerial activity may increase and spread sideways. Fewer people hold “manager” titles while more people continuously manage machine capability.
The paradox is not an argument for preserving hierarchy. It is an argument for recognising work.
Unexpected connection
Contingent-workforce systems + process architecture + hidden employee AI use + multi-model cyber defence
These developments come from HCM, enterprise software, employee research and cybersecurity. Together they describe the same operating system: digital capacity must be admitted, briefed, routed, reviewed, paid for, challenged and removed.
Once that connection is visible, “AI adoption” stops looking like tool usage. It becomes a redistribution of management work across formal managers, individual contributors and technical platforms.
PROVOCATION
The next management delayering may remove managers while increasing management
If routine allocation, monitoring and reporting move into agents, some managerial roles will shrink. Yet every person supervising a portfolio of machine work inherits choices about objective, context, quality, exception and consequence. The organisation can become flatter and more managed at the same time. The risk is not managerlessness; it is management performed everywhere and recognised nowhere.
What if we are right?
Opportunity. Managerial capability could be distributed more widely without forcing talented specialists into people-management careers. Employees could gain authority to compose human and machine capability around outcomes, with explicit time, training and recognition for judgement rather than only production.
Organisational consequence. Workforce planning would represent agent portfolios and orchestration load alongside roles and headcount. Job design would separate execution saved from management added. Pay, progression and performance systems would recognise reliable delegation, challenge and recovery without automatically converting every orchestrator into a line manager.
Likely horizon. Individual teams can expose the work now. Agent lifecycle records and model-routing platforms are appearing during 2026; HCM representations of orchestration capability, portfolio load and contribution are plausible within 12–24 months.
What would prove us wrong?
The thesis weakens if enterprise agents remain narrow tools that require only trivial prompting and occasional checking; if reliability improves so rapidly that orchestration falls rather than rises; or if platforms absorb the full management loop without creating new exception or accountability work for people.
It also fails if reported hidden use reflects momentary experimentation rather than durable work redesign, or if agent-lifecycle products remain a niche procurement category. Most importantly, “orchestration labour” would be the wrong explanation if teams using more agents do not show greater briefing, review, interruption or recovery demand after controlling for output.
The test is empirical: measure the human time and cognitive load around one agent-assisted objective, not merely the minutes the agent saves while executing its part.
Optimistic possibility: management becomes a craft, not a rung
Organisations have long bundled coordination, status and people responsibility into the same career step. Agents create a chance to pull those strands apart.
A scientist, designer, adviser or frontline operator might lead a temporary constellation of agents and specialists without acquiring a permanent hierarchy. People who excel at framing work, judging evidence and integrating perspectives could be recognised as accomplished practitioners of management while remaining close to their craft.
Done well, the shadow layer need not stay shadowy. It can become an enabling layer in which authority travels with the objective, support follows the work and more people learn how to turn machine abundance into humane outcomes.
CYBERSECURITY · OUTSIDE-IN ANALYSIS
Even autonomous malware needs an operating model
REPORTED FACT. Cisco Talos published an analysis on 22 September of CLOSEDQUORUM, a Windows malware sample that can ask up to four commercial language models to vote on its next action. The selected action must fit a constrained schema and map to a predefined capability such as stealing credentials, injecting code or establishing persistence.
Talos says the binary can operate without continuing instructions from a human or a dedicated command-and-control server. It has not confirmed in-the-wild deployment, and the public build contains placeholder keys and a dummy webhook, so this is evidence of architecture rather than a demonstrated active campaign. Cisco Talos, 22 September
ANALYSIS. The uncomfortable lesson is organisational, not instructional. Removing the operator did not remove management. The developer still defined the objective, gathered context, limited the decision language, selected the panel, set tie-breaking rules, connected actions and preserved telemetry.
Autonomy appeared because managerial choices were encoded earlier. Legitimate enterprises should make those choices far more carefully, but the same anatomy applies: machine freedom is produced by a prior act of organisation.
EQUALITY & PERFORMANCE · RESEARCH SIGNAL
The quality of AI assistance may depend on how a person sounds
REPORTED FACT. Johns Hopkins researchers tested GPT-4, Llama, Gemma and Mistral using workplace correspondence prompts containing linguistic patterns associated in prior research with women, including hedging, collective phrasing and expressive adjectives.
Across the four model families, the resulting emails and applications were shorter, less formal or less complex than those generated from male-associated patterns. The difference persisted after tone was accounted for, while changing a male or female signatory name had little effect. The study is due to be presented at the Conference on Language Modeling in October; this report does not establish downstream promotion or pay effects. Johns Hopkins University, 21 September
ANALYSIS. Agent management begins with language. If systems infer competence, desired formality or task difficulty from subtle style cues, two employees can appear to receive the same tool while being allocated different quality of assistance.
The design response is not to coach everyone towards one supposedly neutral voice. It is to test whether equivalent objectives receive equivalent capability, and to give users a way to specify the intended audience, standard and outcome directly.
TENUOUS BUT PLAUSIBLE · Confidence: medium-low · Horizon: 12–36 months
AI could create a new management premium before job titles notice
The Beeline–Insygna system prices agents. SAP’s stack governs their operating environment. Palo Alto’s harness routes work among them. None of these developments establishes a labour-market premium for people who orchestrate machines.
SPECULATION. Yet an earnings and progression gap could emerge between employees who merely consume AI output and those trusted to manage an agent portfolio: define objectives, select capabilities, test disagreement, protect constraints and own recovery.
The causal chain is plausible: heterogeneous agents increase coordination value; productive outcomes depend on human judgement across the portfolio; firms begin observing reliable orchestration; scarce practitioners gain greater scope and rewards. The countervailing possibility is equally real: organisations classify the work as ordinary tool use, add it silently and create workload without a premium.
What to watch. Job descriptions naming agent portfolios; promotion criteria based on delegation and verification; pay differentials for orchestration responsibility; and evidence that the capability transfers across vendors rather than belonging to one interface.
TRUST & ADOPTION · IMPLEMENTATION SIGNAL
Hidden AI use is a weak signal from the operating model
Workday’s survey cannot tell us whether each concealed use was prudent experimentation, a policy breach or a harmless choice not to mention a tool. It should not be converted into a claim that half the workforce is secretly automating its job.
ANALYSIS. It does show why adoption counts are an unreliable guide to organisational reality. If employees conceal use, leaders cannot see which tasks have moved, which controls are being improvised or which new capabilities people are developing.
Surveillance would deepen the incentive to hide. The constructive alternative is reciprocal disclosure: employees can describe agent-assisted work without automatic penalty, while the organisation explains how evidence will be used, what support exists and which boundaries are non-negotiable.
The goal is not confession. It is to turn private operating models into inspectable, improvable organisational knowledge.
NOISE FILTER
An agent rate card is not a salary—and an agent is not a contingent worker
Workforce platforms need familiar objects with which to manage cost and access. Requisition, onboarding and retirement can be helpful metaphors. They become misleading when they imply moral or legal equivalence between software and people.
An agent has an owner, version, service cost and permission envelope. A worker has rights, livelihood, dignity, development needs and voice. Combining records can improve objective-level planning; collapsing categories can obscure obligations to people and anthropomorphise products.
The useful common denominator is contribution to work—not sameness of status.
Operating-model implication
Add the management of machine work to the work itself
| Operating decision | Question | Evidence | Primary steward |
|---|---|---|---|
| Portfolio | Which agents and people contribute to this objective? | Purpose, capabilities, cost and owner | Business owner |
| Orchestration load | How much briefing, checking, correction and exception work is required? | Time, interruptions and review depth | Team lead and workforce design |
| Allocation | Why is this step routed to this person, agent or model? | Capability, risk and alternatives | Process and technology owners |
| Recognition | Whose judgement makes the portfolio productive and safe? | Interventions, improvements and outcomes | Manager and HR |
| Exit | When should the agent, workflow or dependency be retired? | Performance, residual capability and switching cost | Business, procurement and architecture |
This is not a case for making HCM the owner of every agent. It is a case for connecting work architecture and workforce architecture. Enterprise systems can record the machine lifecycle; job and capacity design must record the human management it creates.
Human control watch
Assistance: a person uses AI inside their own task. Management work consists of setting the standard, supplying context and judging the result; it is easily mistaken for negligible tool use.
Delegated execution: an agent completes bounded work across tools. Management work expands to assignment, sampling, exception handling and portfolio capacity; it must be included in workload.
Autonomous control: agents route or execute continuously within a mandate. Human control moves into objective design, constraint setting, independent challenge, consequence limits and recovery.
Today’s shift: human presence is not the only evidence of management. The important question is where framing, allocation, judgement and intervention happen—and whether the people doing them have time, authority and recognition.
Capability-model update
| Gaining value | Under pressure |
|---|---|
| Agent-portfolio steward | Direct reports as the only management scope |
| Orchestration-load analyst | Execution time as the whole workload |
| Model-routing practitioner | One preferred model for every task |
| Reciprocal-disclosure designer | Adoption measured through surveillance |
| Linguistic-equity evaluator | Same tool assumed to mean same assistance |
| Agent-lifecycle controller | Unused or ownerless digital capacity |
ONE THING
IF I WERE TO DO ONE THING NOW
Time one agent-management loop
○ BRIEF ─── ◇ ROUTE ─── □ REVIEW ─── △ INTERVENE ─── ↺ LEARN
Take the single agent-assisted workflow covered by your responsibility card—or another current workflow if that is more practical—and ask one person who regularly oversees it to record for one working week the time spent briefing, assembling context, choosing tools or models, reviewing, correcting, escalating and recovering. Compare that management load with the execution time saved and with what the person’s job description assumes. Do not launch a survey or productivity study; examine one honest loop with the employee and its business owner, then adjust workload, training or recognition where the evidence points. This turns the previous responsibility map into a capacity test and reveals whether autonomy is genuinely releasing human attention or merely moving work out of sight.
Mental-model update
The permeable enterprise has acquired earned authority, an executable constitution, a capability border, a memory for failure, a limit on consequence and an accountability surface.
Today it gains a visible management layer.
Elastic autonomy is not produced by removing managers from a diagram. It depends on distributed acts of framing, routing, judgement and intervention, some human and some encoded in systems.
The emerging North Star is a permeable enterprise in which management follows work rather than title: machine capability can move quickly, while the human labour needed to make it useful, fair and recoverable remains visible enough to resource and value.
Questions for the executive table
- Which individual contributors already manage meaningful portfolios of agent work without time, authority or recognition for doing so?
- When an AI business case reports hours saved, where does it record briefing, review, exception and recovery time?
- Could your workforce systems connect an agent’s cost and activity to the human orchestration required around it without treating the agent as a person?
- What evidence would show that different linguistic styles receive equivalent quality of AI assistance in your workplace?
- If management layers shrink, which managerial decisions are deliberately encoded, redistributed or removed—and which simply become invisible?
Evidence note. Beeline, Insygna, SAP, Workday and Palo Alto Networks describe their own products, surveys or performance; implementation and benefit claims need independent field evidence. Workday’s results are self-reported survey data. Palo Alto’s figures come from its evaluations and engagements. Cisco Talos has not confirmed live deployment of CLOSEDQUORUM. The Johns Hopkins study concerns generated workplace text and does not establish employment outcomes.
The concepts shadow management layer, orchestration labour and management displacement paradox are original AyEye analysis, not claims made by the cited sources.
