Business purpose, risk acceptance, data use, user procedures, and production decisions stay with accountable owners.
Trust / Governance
Shared Responsibility Model for Recurring AI Agents
A practical operating model for accountability, governance, and control across recurring AI work.
Use this page when you need boundary clarity: what Scaled Agents can make visible, what providers and platforms may support, and what remains a customer-owner decision.
Recurring AI agents create shared operational risk across vendors, platforms, business processes, data, permissions, and human review. The Shared Responsibility Model helps enterprises define who owns what before an agent is deployed, monitored, escalated, or remediated.
The Agent Passport is the governance record for recurring AI work. It records identity, ownership, scope, permissions, controls, evidence, and incident paths, but it does not replace the people and teams accountable for the work they control.
Context
Use this model to decide who owns each part of recurring AI work.
Shared responsibility separates what the organization owns, what providers or platforms may support, what operators must follow, and what the Agent Passport records as evidence. It helps prevent accountability gaps when AI agents operate across people, systems, vendors, data, and review paths.
Cloud, model, SaaS, and tool providers may supply infrastructure, but they do not own the organization's AI governance decisions.
The Passport records identity, ownership, scope, controls, review paths, and evidence; it does not transfer accountability away from people.
How the model assigns responsibility
The Passport connects the operating record, but accountability remains with the party controlling each layer of work. Scaled Agents provides governance platform capabilities; named owners remain responsible for business, technical, security, compliance, operational, and contractual decisions within their control.
Governance operating model
Use these views to define ownership, controls, RACI, incident accountability, and contract expectations before recurring AI work reaches production.
Scaled Agents shared responsibility model showing the Agent Passport as the governance record connecting vendor, enterprise platform, business owner, security and compliance, and operator responsibilities.
Governance record for recurring AI work
Vendor / Provider
Product reliability, security, uptime, support, updates
- Product capability and reliability
- Security and uptime
- Support and documentation
- Updates and change notices
Enterprise AI / Platform Team
Use case approval, platform guardrails, testing, monitoring
- Use case approval
- Platform configuration
- Guardrails and standards
- Pre-launch testing
Business Owner
Process fit, success criteria, review, improvement
- Process ownership
- Success and failure criteria
- Human review cadence
- Continuous improvement
IT / Security / Data / Compliance
Access, data governance, risk, compliance
- Access and permissions
- Data governance
- Risk classification
- Audit readiness
End User / Operator
Follow procedures, review outputs, escalate issues
- Follow approved procedures
- Review outputs
- Escalate unusual behavior
- Provide feedback
Vendor / Provider
Product reliability, security, uptime, support, updates
Enterprise AI / Platform Team
Use case approval, platform guardrails, testing, monitoring
Business Owner
Process fit, success criteria, review, improvement
IT / Security / Data / Compliance
Access, data governance, risk, compliance
End User / Operator
Follow procedures, review outputs, escalate issues
Accountability follows control
The Shared Responsibility Model defines how responsibility is assigned across the product, process, data, permissions, review, and incident layers of recurring AI work. Each party is responsible for the risks and decisions they control.
Passport as governance record
The Agent Passport records who owns the agent, what the agent is approved to do, what systems it can access, what controls apply, who reviews outputs, and how incidents are handled.
Clear accountability
The Passport creates a shared source of evidence without replacing accountable owners. Shared accountability does not mean unclear accountability.
- Define ownership before deployment.
- Document approved scope and prohibited actions.
- Map system access and permission limits.
- Set human review points and stop conditions.
- Preserve audit evidence.
- Clarify incident ownership and remediation paths.
Use the Passport to make the operating model visible before recurring AI work creates operational dependency.
Vendor / Provider
Owns
- Product capability and reliability
- Platform uptime and availability
- Product defects
- Security controls within the vendor-controlled system
- Logging features made available to customers
- Model or version change notices where applicable
- Contracted support obligations
Does not own by default
- Customer business process decisions
- Enterprise data quality
- Customer-granted permissions
- Customer user misuse
- Customer's internal review process
Enterprise AI / Platform Team
- Use case intake and approval workflow
- Agent configuration standards
- Prompt, tool, and workflow design standards
- Guardrails and policy enforcement patterns
- Pre-launch testing
- Monitoring design
- Operational governance
- Platform lifecycle management
Business Owner
- Business process fit
- Task scope and intended outcome
- Success and failure criteria
- Human review cadence
- Exception handling
- Downstream business impact
- Process improvement decisions
IT / Security / Data / Compliance
- System access
- Permission boundaries
- Data source approval
- Data quality expectations
- Privacy and legal review
- Risk classification
- Security policy controls
- Evidence and audit readiness
- Compliance requirements
End User / Operator
- Following approved procedures
- Reviewing assigned outputs
- Escalating unusual behavior
- Reporting issues
- Not bypassing safeguards
- Providing operational feedback
Responsibility rule
Responsibility is assigned based on control. The Passport records each party's role, but it does not transfer accountability away from the party that controls the work.
Every recurring production agent should have defined controls
The person or team accountable for the business process and outcome expectations.
The person or team accountable for configuration, integration, platform behavior, and technical maintenance.
What the agent is approved to do, where it can operate, and under what conditions.
What the agent must never do, including actions requiring human approval or actions outside policy.
Approved systems, documents, records, or knowledge sources the agent may use.
Applications, APIs, tools, or environments the agent can access.
Whether the agent can read, write, send, approve, modify, purchase, delete, or escalate.
When a human must review or approve the agent's work.
Error rates, unusual activity patterns, policy violations, or confidence thresholds that trigger review.
What pauses, disables, or escalates the agent when risk exceeds tolerance.
What evidence is captured, retained, and made available for review.
Who is notified, how quickly, and what workflow is followed when something goes wrong.
How often the agent, scope, permissions, outputs, and controls are revalidated.
The Passport should capture these controls before recurring AI work reaches production.
Shared Responsibility and Runtime Authority Matrix v2.0
The matrix keeps responsibility details on the left and source markers on the right. It maps relevant CoSAI accountability concepts while preserving the Scaled Agents distinction between organizational accountability, standing Passport scope, and action-specific runtime authorization.
| ID / Layer | Responsibility | Accountable party | Responsibility detail | Runtime and evidence boundary | Scaled Agents | CoSAI | Combined | Decision needed |
|---|---|---|---|---|---|---|---|---|
| SRM-001 L1 Business & Usage | Approve business purpose and acceptable risk. | Customer AI system or business owner | The customer defines the outcome, risk tolerance, production decision, and accountable human authority. | Human Review and decision records preserve the approval evidence; they do not transfer accountability. | X | |||
| SRM-002 L2 Information | Approve data sources, classifications, and permitted use. | Customer data owner | Customer data, privacy, security, and governance reviewers define the allowed data boundary. | Passport and connector scope record the boundary; Runtime Permit checks apply when an action is requested. | X | |||
| SRM-003 L3 Application | Define prompts, retrieval, guardrails, tool boundaries, and prohibited actions. | Customer application or technical owner | The application team configures the customer use case within customer-approved policy and review requirements. | Tolls, Human Review, Runtime Permits, and the Action Broker support governed decision and evidence paths where implemented. | X | |||
| SRM-004 L3 Application | Authorize one consequential AI-worker action. | Customer-designated action owner | The accountable human approval authority remains customer-designated. | Scaled Agents may evaluate Passport scope, policy, evidence, approval state, Runtime Permit, and Action Broker mediation before the action proceeds. | X | |||
| SRM-005A L3/L4 Application & Platform | Operate the Scaled Agents governance control plane. | Customer platform owner | Scaled Agents supplies the licensed governance platform capability; the customer hosts or manages its instance and retains production decisions. | Passport, Toll, Human Review, Runtime Permit, Action Broker, Stamp, and evidence capabilities depend on the implemented and configured product stage. | X | |||
| SRM-005B L4 Hosting & Model Serving | Secure hosting, infrastructure, and the model-serving runtime used with Scaled Agents. | Customer or selected provider, per deployment | The customer selects its cloud, on-premises, AI-PaaS, Agent-PaaS, or model-serving environment. | Provider infrastructure controls and customer configuration evidence remain outside Scaled Agents ownership; customer Scaled Agents gates may still govern AI-worker use. | X | X | ||
| SRM-006A L3 Application / L5 Dependency | Select and configure the LLM or SLM used for AI-help fields or the website AI-help widget. | Customer AI system or product owner | The customer chooses its model, provider, route, configuration, data boundary, and approved use. | Scaled Agents records the approved model route and may gate use; the customer-selected model performs inference. | X | |||
| SRM-006B L5 Model Provider | Disclose model limitations, provenance, vulnerabilities, version changes, and service conditions. | Chosen model provider; customer for a customer-developed or self-managed model | The chosen source supplies model evidence. The customer reviews and accepts the model route for its use case. | The customer may restrict, replace, or block the selected model through Scaled Agents policy, approval, and Permit paths. | X | |||
| SRM-007 Cross-layer | Suspend or revoke AI-worker authority. | Customer lifecycle or incident authority | The customer names the pause, disable, suspension, revocation, restart, and residual-risk authorities. | Passport lifecycle state, connector revocation, Permit denial, Broker blocking, and Evidence Records support the governed intervention trail. | X |
External alignment source: Coalition for Secure AI, AI Shared Responsibility Framework V1.0, approved May 26, 2026. This mapping does not imply CoSAI endorsement, certification, conformity, or approval of Scaled Agents.
The matrix supports responsibility clarity and review preparation. Customer owners, selected providers, and qualified reviewers retain their respective legal, security, privacy, compliance, operational, and production decisions.
Incident accountability matrix
When an agent makes a mistake, the first question should not be "Who can we blame?" It should be "Which layer failed, who controlled that layer, and what evidence does the Passport show?"
Product failure
ExampleVendor platform failed, logs were unavailable, product defect caused bad behavior, or an unannounced product/model change materially affected output.
Primary accountabilityVendor / Provider
Passport evidenceVersion, vendor, capability, support terms, logs, change notices, incident records
Configuration failure
ExampleAgent instructions, tools, routing rules, or guardrails were configured incorrectly.
Primary accountabilityEnterprise AI / Platform Team
Passport evidenceConfiguration owner, approval record, prompts/workflow version, test results
Process design failure
ExampleA high-impact recurring task lacked human review, escalation, or stop conditions.
Primary accountabilityBusiness Owner / Enterprise
Passport evidenceApproved scope, success criteria, review cadence, stop conditions
Permission failure
ExampleThe agent had excessive access or could take actions without required approval.
Primary accountabilityIT / Security / Enterprise
Passport evidenceSystem access, permission limits, approval records, access review history
Data failure
ExampleThe agent used stale, incomplete, inaccurate, or unauthorized data.
Primary accountabilityData Owner / Enterprise
Passport evidenceApproved data sources, data owner, freshness requirements, retrieval configuration
User misuse
ExampleOperator bypassed safeguards, ignored required review, or used the agent outside approved procedure.
Primary accountabilityEnd User / Operator / Manager
Passport evidenceUser procedure, warnings, review assignment, audit log, escalation history
Monitoring failure
ExampleRepeated errors occurred without detection or escalation.
Primary accountabilityBusiness Owner / Operations / Enterprise AI Team
Passport evidenceMonitoring rules, thresholds, alerts, review cadence, incident path
Contract failure
ExampleVendor did not meet agreed support, audit, availability, notification, or remediation terms.
Primary accountabilityVendor / Provider through contract path
Passport evidenceSLA, support terms, incident timeline, audit log access, change notice obligations
The enterprise remains accountable to its customers, employees, and regulators. Vendor accountability determines recourse, remediation, support, and contractual remedies.
Vendor and contract expectations
For recurring AI work, vendor agreements should define the evidence, support, security, notification, and remediation expectations needed to operate agents responsibly.
Define what constitutes a product defect, platform failure, support failure, or material product behavior issue.
Specify what logs are available, how long they are retained, and how customers can access them during review or incident response.
Require notice when model, system, workflow, or platform changes may materially affect agent behavior.
Document security controls, access controls, encryption, vulnerability management, and incident handling obligations.
Define how customer data is processed, retained, deleted, isolated, and protected.
Document third-party services or processors used to deliver the product.
Define response windows, escalation paths, notification timelines, and evidence-sharing expectations.
Set support channels, severity levels, response times, and escalation paths.
Define whether customers can disable, suspend, roll back, or restrict agent behavior.
Clarify how repeated or material failures are fixed and what remedies apply.
Document known limitations, intended use, prohibited use, and customer responsibilities.
Define credits, remediation obligations, termination rights, and other agreed remedies where appropriate.
Contracts should reinforce the same principle as the Passport: clarify responsibility before an incident occurs.
What the Agent Passport does, and does not do
The Passport does
- Records agent identity and approved purpose
- Maps owners and responsibility domains
- Documents scope and prohibited actions
- Captures data sources and system access
- Defines permission limits and review points
- Records audit evidence and incident paths
- Supports governance, review, and remediation
The Passport does not
- Become the accountable actor
- Replace business ownership
- Replace technical ownership
- Replace security, compliance, or data governance
- Absorb responsibility for user misuse
- Transfer customer operational accountability to Scaled Agents
- Eliminate the need for contracts, controls, and review
Scaled Agents enables accountability by making ownership, controls, and evidence visible. Accountable owners remain responsible for the layers they control.
Make recurring AI work governable before it scales.
Use the Agent Passport to document ownership, scope, permissions, controls, evidence, and incident paths for recurring AI agents.