rdlb · insights September 10, 2026 · 2 min read

An agent you can't name isn't rogue. It's invisible.

Agent governance is a counting problem before it is a control problem. Most teams write the policy first and skip the census underneath it.

Achilles, the RDLB Agentic mascot, curious head-tilt, holding a cream clipboard with a three-column grid, on a soft ivory background.

How many agents are running in your company right now.

Not how many you approved. Not how many are on the roadmap. How many are running, today, touching a system, producing something somebody will use. If the answer took longer than a breath, that pause is the whole essay.

Here is the mechanism. There are two artifacts that look alike and do different jobs. A list tells you what exists. A register tells you what is allowed to exist, who said so, and until when. Most teams reaching for governance start with policy, which is a control layer. Policy governs the agents you know about. It has nothing to say about the ones you never wrote down, because it cannot see them. The layer underneath policy is not a rule. It is a census.

A register is three columns per agent, and each column is one sentence.

Reach. What it can touch, written as systems, not intentions. Not "helps with reporting." The reporting database, the shared drive, the email account it sends from.

Sponsor. One human who would answer for it. Not the team that uses it, and not the vendor. A name.

Expiry. The date it stops unless somebody renews it. This is the column nobody writes and the only one that keeps the register honest, because an agent with no expiry is a permanent employee who was never hired.

That is the entire artifact. It is easy and it is unglamorous, and almost nobody has one, which is exactly why a market now exists for software that goes hunting for the agents an organization never filed. You can tell what an industry forgot to build by what it later has to buy.

Now the part that matters, because the obvious version of this argument is a scare piece and the scare piece is wrong.

The unregistered agent is almost never the villain. It is usually the best signal in the building. Somebody wanted to move faster, had the tools to do it, did good work, and the system gave them no place to declare it. The failure is the missing form, not the person who filled nothing in. Nothing here is rogue. It is unfiled. And the difference between rogue and unfiled is a row in a table that takes ninety seconds to write.

This is also why the register compounds with everything we have argued before. A handoff needs an owner. An owner needs standing. Standing needs a register. And a register is just a list that somebody signed.

The ten-minute version, for anyone who wants to do this before the next meeting. Whiteboard. One row per agent you can think of, three columns. Then ask the room what is missing, and watch how quickly people volunteer the ones they built on a Tuesday. Those rows are not confessions. They are your most motivated builders telling you where the work already went.

Write the policy after. It will be shorter, because it will finally know what it is governing.

Takeaway: A policy governs the agents you know about. A register is how you find out. Three columns, one row each, before anyone writes a rule. ✱

Achilles Angle · governance · agentic systems · operations

A 30-minute strategy blueprint call maps where a system takes over your highest-cost work.

Book the strategy blueprint call