Skip to content
Groundplan

Governance

The four questions that sank the last generation of agent pilots

Every framework we design answers these in writing before anything gets built. This is the page to forward to the colleague whose job is to say no.

When analysts explain why agent projects get cancelled, governance is named alongside cost and unclear value — rules that were never settled while there was still time to settle them cheaply.

That is an unglamorous finding, and it is good news, because those rules are writable. What follows is how we write them.

Source: Gartner press release, 25 June 2025, on projected cancellation of agentic AI projects through 2027 and its stated causes. Figures in this area move between publications. verify before publish

  1. Question 01

    What is this allowed to decide on its own?

    A short, written list, agreed before anything is built, in the language your board already uses.

    In practice the list is narrower than people expect. A watcher may decide that a parcel deserves attention this week. It may decide the order of a queue. It may assemble a draft.

    It does not decide that a notice goes out, that a crew rolls, that a price changes, or that a claim is signed. Those are on the other list, and the other list is the one with names against it.

    Anything not written down is not permitted. That is the default, and it is deliberate — the failures we have read about almost all began with an unwritten assumption about scope.

  2. Question 02

    What always goes to a person?

    Anything that touches someone outside your organisation. A landowner, a policyholder, a supplier, a community, a regulator.

    Anything that commits money, people or equipment.

    Anything that becomes part of a legal or regulatory record.

    And anything where the system's own confidence is thin. A design that reports uncertainty is more useful than one that resolves it quietly, so the handoff is triggered by doubt as well as by importance.

  3. Question 03

    Who is accountable when it's wrong?

    A named role in your organisation, per watching function, recorded in the design document. Not a committee, not a vendor, not a system.

    It will be wrong sometimes. It will flag ground where nothing happened, and it will miss something it should have caught. Both need a route: a way for staff to record the error, and a scheduled review where those records change the design rather than sit in a folder.

    We are accountable for the design being what we said it was, and for telling you when we think you are about to build something you will regret. We are not in the accountability chain for a decision your organisation makes.

  4. Question 04

    How fast can it be turned off?

    Immediately, by someone who is not the person who set it up, from a phone, without a call to us.

    Every design includes a stop procedure written as an instruction a duty officer can follow at three in the morning, and a partial stop — pausing one watching function without taking down the rest — because the all-or-nothing version tends not to get used until it is too late.

    We ask teams to exercise the stop procedure on a schedule, the way you would test an alarm. A stop that has never been used is a stop nobody trusts.

What we won't design

Autonomous dispatch of people into a hazardous situation. We have turned down work on that basis.

Anything that reaches a member of the public without a person having read it first.

Any design we cannot explain to your board in ordinary words. If explaining a piece of it requires an acronym, it is either not ready or not necessary.

Bring us your hardest question