Back

Back

Operations

Who Owns the Agent That Emails Your Customers?

Who owns the AI agent that emails your customers? Why a register beats a policy document, and the four columns to start one with this week.

Teamwork in a modern office at night, with laptops, sticky notes, and a city view. A mix of focus, collaboration, and a casual atmosphere.

Somewhere in your business there is an automation that sends messages to customers. Name the person responsible for it. Not the person who built it, and not the department it sits in. The person who would be called if it sent the wrong thing to four hundred people on a Saturday.

Most companies cannot answer that in under a minute, and the ones that can usually name somebody who left.

Why the question is suddenly hard

Three years ago the automations in a small company were a handful of email rules and a connection somebody set up for the sales team. They were dumb, they were few, and they were obvious.

Now there is a thing that drafts replies, a thing that categorises inbound tickets, a thing that summarises calls into the CRM, a thing in the accounting tool that chases invoices, and at least one that a department bought on a credit card and never mentioned. Several of them make decisions. Several of them speak to customers. None of them appear on any list, because no list was ever started.

The reason this creeps up on people is that each addition was individually sensible. Nobody approved "forty automations with no owner". Forty people each approved one.

What a register is, and what it is not

A register is a list of every agent or automation running in your business, and against each one: who owns it, what it is allowed to do, how much it decides on its own, what happens if it is wrong, and what controls are supposed to be in place.

It is not a governance programme. It is not a policy document. It is a list, and the entire value of it is that it exists and is current. A register you have to remember to update by hand is out of date by March, which is why the version that works is the one that fills itself as things get built rather than the one somebody promises to maintain.

abi. Governance keeps that register against your process map, so an automation arrives on it as part of being built rather than as a separate administrative act somebody has to remember.

It is worth being precise about what this gives you, because the category is full of overclaiming. A register is a structured self-assessment. It records what you have declared and what you have evidenced, and it shows the evidenced count next to the required count so nobody mistakes one for the other. It is not legal advice and it does not certify anything about your business. You remain responsible for your own compliance, and any tool that implies otherwise is selling you a feeling.

Start with four columns, even on paper

If you do nothing else this month, open a spreadsheet and fill in four columns for every automation you can think of.

What it does, in one sentence a customer could read. Who owns it, by name. Whether a human sees its output before anyone outside the company does. And what you would do to stop it in a hurry.

That fourth column is the one that changes behaviour. A surprising number of automations turn out to have no stop button that anybody knows about, and the honest entry is "log into the platform, find it, disable it, hope". Writing that down is uncomfortable, which is the point.

The awkward part

You will find things with no owner. Not a few: the usual pattern is that the person who built the most useful automation in the company changed roles, and it has been running unattended for a year, and it works, so nobody has ever had a reason to look at it.

Do not delete it. Assign it. An unowned automation that works is a risk, but an unowned automation that somebody deletes in a tidying mood is an outage, and outages make people hostile to the whole exercise.

The point of the list is not to make anyone accountable for a mistake that has not happened. It is that when one does happen, the first twenty minutes are spent fixing it rather than working out whose it is.