{
  "abstract": "A practical operating model for meaningful agent work: begin with a job, encode the work, bound the assignment, supervise through evidence, measure results, and expand autonomy only when repeatable proof earns a larger trust envelope.",
  "author": {
    "email": "tony@malott.ai",
    "email_url": "mailto:tony@malott.ai",
    "id": "person:tony-malott",
    "name": "Tony Malott",
    "resume_url": "https://malott.ai/resume/",
    "url": "https://malott.ai/"
  },
  "card": {
    "kicker": "Agent worker operating model",
    "orientation": "A dependable agent is built by its management system, not by discovering a perfect prompt.",
    "visual_motif": "worker-control-manual"
  },
  "claims": [
    {
      "caveat": "The exact Agent Worker Operating Contract remains Tony Malott's prescriptive synthesis.",
      "id": "claim:190:01",
      "posture": "supported-synthesis",
      "support": [
        "source:190:nist-ai-600-1",
        "source:190:joint-agentic-adoption-guidance"
      ],
      "text": "Meaningful delegation requires explicit roles, bounded authority, procedures, validation, monitoring, and escalation."
    },
    {
      "id": "claim:190:02",
      "posture": "supported",
      "support": [
        "source:190:anthropic-trustworthy-agents",
        "source:190:joint-agentic-adoption-guidance"
      ],
      "text": "An operational agent is a system of model, instructions or harness, tools, data, permissions, and environment rather than a model or prompt alone."
    },
    {
      "id": "claim:190:03",
      "posture": "strongly-supported",
      "support": [
        "source:190:joint-agentic-adoption-guidance",
        "source:190:owasp-agentic-top-10",
        "source:190:anthropic-trustworthy-agents"
      ],
      "text": "Ambiguous goals, excessive privileges, and weak boundaries can cause agentic systems to take unintended or harmful actions."
    },
    {
      "caveat": "The article's exact scorecard is an operating proposal, not a standardized benchmark.",
      "id": "claim:190:04",
      "posture": "supported-synthesis",
      "support": [
        "source:190:agents-that-matter",
        "source:190:nist-ai-600-1",
        "source:190:anthropic-agent-autonomy"
      ],
      "text": "Agent evaluation should extend beyond apparent accuracy to application-specific outcomes, cost, reproducibility, failure, and intervention evidence."
    },
    {
      "caveat": "The promotion metaphor is Tony Malott's framing.",
      "id": "claim:190:05",
      "posture": "supported-prescription",
      "support": [
        "source:190:joint-agentic-adoption-guidance",
        "source:190:anthropic-agent-autonomy"
      ],
      "text": "Agent authority should expand incrementally only after observable success, with retained human control and reversibility."
    },
    {
      "caveat": "Do not generalize software-task time horizons to all organisational work.",
      "id": "claim:190:06",
      "posture": "qualified",
      "support": [
        "source:190:metr-time-horizons",
        "source:190:agents-that-matter"
      ],
      "text": "Measured agent capability on software tasks has increased, but dependable performance remains task-, environment-, and success-threshold-specific."
    },
    {
      "id": "claim:190:07",
      "posture": "supported",
      "support": [
        "source:190:joint-agentic-adoption-guidance",
        "source:190:nist-ai-600-1"
      ],
      "text": "Humans remain accountable for deploying agentic systems, granting access, setting safeguards, monitoring operation, and responding to consequences."
    },
    {
      "id": "claim:190:08",
      "posture": "strongly-supported",
      "support": [
        "source:190:joint-agentic-adoption-guidance",
        "source:190:owasp-agentic-top-10"
      ],
      "text": "Agentic systems can use tools and take actions across connected systems, increasing capability and attack surface together."
    },
    {
      "id": "claim:190:09",
      "posture": "owner-authorized",
      "support": [
        "source:github:issue-190"
      ],
      "text": "Manage the work like an employee. Control the system like powerful machinery."
    },
    {
      "id": "claim:190:10",
      "posture": "owner-supported-synthesis",
      "support": [
        "source:github:issue-190",
        "source:190:anthropic-trustworthy-agents",
        "source:190:nist-ai-600-1"
      ],
      "text": "Agent adoption pressures organisations to convert tacit management into executable management."
    }
  ],
  "collections": [
    {
      "id": "collection:from-prompts-to-governed-work",
      "position": 2,
      "title": "From prompts to governed work"
    }
  ],
  "dates": {
    "created": "2026-07-18",
    "updated": "2026-07-21"
  },
  "featured": true,
  "format": {
    "depth": "Evidence-backed operating manual",
    "interaction": "Canonical manual with two alternate native teaching views",
    "label": "Teaching architecture",
    "reading_time": "18 min"
  },
  "graph_order": 2,
  "id": "artifact:stop-prompting-agents-start-managing-workers",
  "lifecycle": {
    "merge_authority": "granted-for-pr-60-after-receipt-only-lock-projection",
    "owner_review": "review:issue-59-worker-manual-platform-v01",
    "state": "MERGE_READY"
  },
  "migration": {
    "admission_id": "admission:stop-prompting-agents-start-managing-workers",
    "content_fidelity": "Exact accepted predecessor article bytes preserved; the canonical manual and alternate teaching views are rendered natively inside the Platform shell.",
    "disposition": "redesign",
    "source_locators": [
      "Issue #190",
      "PR #214",
      "docs/publication/issue-190/ARTICLE.md at blob d389b18680694f8a931161a77cc96c90aa5bccc7"
    ],
    "source_repository": "pinklon/pinklon-shareplane-next"
  },
  "presentation": {
    "motif": "worker-control-manual",
    "public_entry": {
      "canonical_slug": "worker-manual",
      "chooser_slug": "presentation-family",
      "mode": "canonical-article-family",
      "pattern_id": "pattern:canonical-article-with-teaching-lenses",
      "variants": [
        {
          "label": "The Worker Manual",
          "slug": "worker-manual"
        },
        {
          "label": "Worker and Machine",
          "slug": "worker-and-machine"
        },
        {
          "label": "The Promotion Ladder",
          "slug": "promotion-ladder"
        }
      ]
    },
    "visual_blocks": [
      {
        "section_id": "references-and-evidence",
        "type": "evidence-group"
      }
    ]
  },
  "presentation_status": "locked",
  "provenance": {
    "ai_assistance": {
      "role": "source-register reconciliation, claim-evidence projection, native information design, relationship audit, rendering, and validation",
      "used": true
    },
    "boundary": "The employee analogy governs work design, not personhood or accountability. The checklist, scorecard, promotion model, and governing thesis are Tony Malott's operating synthesis; external sources support bounded factual claims without becoming outsourced authority.",
    "posture": "Exact accepted article and evidence records from SharePlane Next PR #214, rebuilt as a platform-native presentation family under SharePlane Platform Issue #59.",
    "sources": [
      {
        "description": "Security guidance for organisational adoption; it is not a general productivity benchmark.",
        "id": "source:190:joint-agentic-adoption-guidance",
        "locator": "https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services",
        "publiclyExposed": true,
        "role": "Supports bounded access, monitoring, accountability, incremental adoption, and planning for failure",
        "title": "Careful adoption of agentic AI services",
        "type": "joint-government-guidance"
      },
      {
        "description": "Vendor-authored guidance; use for architecture context, not neutral market comparison.",
        "id": "source:190:anthropic-trustworthy-agents",
        "locator": "https://www.anthropic.com/research/trustworthy-agents",
        "publiclyExposed": true,
        "role": "Supports the model, harness, tools, environment, and human-control architecture",
        "title": "Trustworthy agents in practice",
        "type": "vendor-practice-guidance"
      },
      {
        "description": "Voluntary cross-sector guidance; it does not validate this article's specific operating model.",
        "id": "source:190:nist-ai-600-1",
        "locator": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence",
        "publiclyExposed": true,
        "role": "Supports governance, measurement, evaluation, and lifecycle-risk management",
        "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile",
        "type": "public-standard-guidance"
      },
      {
        "description": "A research analysis of agent benchmarks; it does not prescribe one universal operating scorecard.",
        "id": "source:190:agents-that-matter",
        "locator": "https://arxiv.org/abs/2407.01502",
        "publiclyExposed": true,
        "role": "Supports evaluation beyond accuracy through cost, reproducibility, and application fit",
        "title": "AI Agents That Matter",
        "type": "research-paper"
      },
      {
        "description": "First-party programming observations that do not necessarily transfer to other domains.",
        "id": "source:190:anthropic-agent-autonomy",
        "locator": "https://www.anthropic.com/research/measuring-agent-autonomy",
        "publiclyExposed": true,
        "role": "Supports environment-specific observations about approval, interruption, and monitoring",
        "title": "Measuring AI agent autonomy in practice",
        "type": "vendor-empirical-study"
      },
      {
        "description": "Software-oriented task results do not establish dependable performance in every domain.",
        "id": "source:190:metr-time-horizons",
        "locator": "https://metr.org/blog/2025-03-19-measuring-ai-ability-to-complete-long-tasks/",
        "publiclyExposed": true,
        "role": "Supports task-, environment-, and success-threshold-specific capability measurement",
        "title": "Measuring AI Ability to Complete Long Tasks",
        "type": "empirical-research"
      },
      {
        "description": "A practitioner security taxonomy, not empirical evidence of model performance or organisational value.",
        "id": "source:190:owasp-agentic-top-10",
        "locator": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "publiclyExposed": true,
        "role": "Supports the taxonomy of agentic security risks and mitigations",
        "title": "OWASP Top 10 for Agentic Applications 2026",
        "type": "peer-reviewed-practitioner-framework"
      },
      {
        "description": "Owner authority for this artifact; it is distinct from external empirical support.",
        "id": "source:github:issue-190",
        "locator": "https://github.com/pinklon/pinklon-shareplane-next/issues/190",
        "publiclyExposed": true,
        "role": "Authorizes the owner thesis, employee-and-machinery metaphor, exclusions, and accepted source package",
        "title": "SharePlane Next Issue #190",
        "type": "semantic-authority"
      },
      {
        "description": "Platform publication authority; it does not replace the accepted source or its evidence boundaries.",
        "id": "source:shareplane-platform-issue-59",
        "locator": "https://github.com/pinklon/shareplane-platform/issues/59",
        "publiclyExposed": true,
        "role": "Governs admission, native presentation, relationship expansion, validation, and Platform UAT",
        "title": "SharePlane Platform Issue #59",
        "type": "governing-issue"
      }
    ]
  },
  "public": true,
  "public_safe_status": "reviewed",
  "relationships": [
    {
      "label": "Authored by Tony Malott",
      "target_id": "person:tony-malott",
      "type": "authored_by"
    },
    {
      "label": "Governed by Platform Issue #59",
      "target_id": "issue:shareplane-platform:59",
      "type": "governed_by"
    },
    {
      "label": "Uses one canonical article with native teaching lenses",
      "target_id": "pattern:canonical-article-with-teaching-lenses",
      "type": "uses-pattern"
    },
    {
      "explanation": "The memoir supplies the operational failures behind explicit context, authority, validation, receipts, and the shift from magical agents to governed workers.",
      "label": "See why the worker model became necessary",
      "reader_group": "foundations",
      "target_id": "artifact:i-was-summoning-ghosts-until-i-learned-to-build-the-machine",
      "type": "foundation"
    },
    {
      "explanation": "This companion locates useful agent execution in the repositories, access, tools, authority, validation, and completion paths that make the worker model operational.",
      "label": "Build the workbench around the worker",
      "reader_group": "companions",
      "target_id": "artifact:the-agents-were-never-the-bottleneck",
      "type": "companion"
    },
    {
      "explanation": "Once bounded agent workers execute reliably, the constraint moves upstream to human specification, supervision, validation, integration, memory, and closure.",
      "label": "What changes after worker execution accelerates",
      "reader_group": "continue",
      "target_id": "artifact:the-agents-are-not-the-bottleneck-you-are",
      "type": "continuation"
    },
    {
      "explanation": "Demo Debt shows why a compelling output is not dependable operation and why evidence, maintenance, failure behavior, and ownership must remain part of the evaluation.",
      "label": "Apply the scorecard beyond the polished demonstration",
      "reader_group": "applications",
      "target_id": "artifact:demo-debt",
      "type": "application"
    },
    {
      "explanation": "The architecture essay reinforces the same boundary: useful model behavior does not replace durable state, observability, ownership, recovery, and explicit operating controls.",
      "label": "Separate useful intelligence from production architecture",
      "reader_group": "companions",
      "target_id": "artifact:your-second-brain-is-not-a-production-architecture",
      "type": "companion"
    }
  ],
  "schema_version": "2.0.0",
  "semantic_status": "locked",
  "slug": "stop-prompting-agents-start-managing-workers",
  "source": {
    "content_status": "canonical-full",
    "format": "markdown",
    "path": "content/artifacts/stop-prompting-agents-start-managing-workers/source.md",
    "predecessor_sha": "50870fd5c0cb71dd78f72f8ccee99ffc5af9dc96"
  },
  "subtitle": "Manage the work like an employee. Control the system like powerful machinery.",
  "thesis": "Agent workers become dependable only when organizations stop treating them as intelligent prompt boxes and start managing their work through explicit roles, encoded procedures, bounded authority, evidence, measurement, and earned autonomy.",
  "title": "Stop Prompting Agents. Start Managing Workers.",
  "topics": [
    "agent-workers",
    "operating-contracts",
    "earned-autonomy",
    "evidence",
    "management-systems"
  ],
  "type": "teaching-architecture"
}
