The operating model for agentic AI

Don't prompt.
Design.

A one-page canvas and an AI coach for the nine decisions that make an agent useful, governable and worth building, before code turns assumptions into operating reality.

Agentic AI design is org design: settle the job, the authority, the knowledge and the accountability before the worker shows up.

Developed by Michael Freeman, INSEAD

95%
of enterprise generative-AI pilots showed no measurable impact on profit and loss. MIT Project NANDA, The GenAI Divide, 2025 ↗
~5%
of companies are capturing value from AI at scale. BCG, The Widening AI Value Gap, 2025 ↗
40%+
of agentic-AI projects forecast to be cancelled by the end of 2027. Gartner press release, June 2025 ↗

The diagnosis

The model keeps improving.
The failure rate does not.

The cause is not in the technology. An un-designed agent is still designed, only by accident, in code, by whoever shipped first, and the briefing nobody wrote is the one the model ends up inventing for itself. A person you hire restrains themselves, remembers, and can be held to account; an agent brings none of that, so every design decision you skip to close the gap is a debt, and model capability is the interest rate.

A brilliant
new hire
The worker
An LLM is capable on day one: trained, articulate, and not yet trustworthy. It optimises plausibility, not truth. None of the context, rules, or tools it needs arrives in the box.
40+ errors
What un-design looks like
In April 2026, Sullivan & Cromwell, the Wall Street firm that also advises OpenAI on safe AI, filed an emergency motion in federal bankruptcy court with fabricated citations and misquotes. The model was state of the art; the system around it was not. Bloomberg ↗
9 decisions
The fix
Everything you'd give any capable hire: a briefing pack, a job description, the rules, the tools, a team. All designed on paper, before the worker shows up.
Layer 01 · provides cognition

Worker the LLM

Capable, articulate, probabilistic. It arrives trained on the world and briefed on none of your work.

Layer 02 · provides control

Harness the operating system around it

The part you control. Five things, each already familiar from managing people:

Briefing pack Professional code Job description Memory Discretion
Layer 03 · provides reach

Tools the systems it can act on

A web search, a database query, an email sent. The worker issues a command, the harness catches it, the system executes. An LLM in a loop, with tools.

The Agent Operating Model

Every agent has an anatomy.

Each of the three layers supplies one term of the same equation. Most failures trace to the same blind spot. The worker is chosen with care, then wrapped in a harness and a governance regime that nobody designed.

power = cognition × control × reach

It is a product, not a sum, which is why a brilliant worker with wide reach and no control is a liability. Add a calendar and the worker becomes a scheduler; give it the authority to move money and it becomes a fiduciary actor. The more reach you grant, the more control the harness has to hold.

The canvas

Nine decisions, before the build.

One North Star, four design questions and nine operating decisions. The Agentic AI Design Canvas turns the Agent Operating Model into choices a team makes on paper, before anyone writes a line of code.

Agentic AI Design Canvas

North Star

What business outcome should this agent's work ultimately contribute to?

Select a cell for its question, or a category for its territory

★ North Star · the frame, not a tenth cell

What business outcome should this agent's work ultimately contribute to?

One outcome the whole design serves, and every cell below answers to it.

Job what it's for

01Target Workflow & Agent Role

Which workflow is it part of, and what contribution is the agent responsible for making within it?

An agent left to infer its own job from an outcome or a task list has nothing telling it what its activities are meant to add up to.

02Users & Stakeholders

Who uses it directly, and who else is affected by what it does?

If the people the agent can harm never appear on the canvas, nobody designs for them.

03Success Measures & Standards

What measures will show that the workflow improved, and what performance standards must the agent meet?

Two different things: whether the work got better, and whether the agent performs well enough. Without both, nothing defines "good enough" before it acts.

Authority what it may do

04Autonomy by Action

For each consequential action in its role, how independently may the agent act?

The rung attaches to the action, not to the agent as a whole. The highest rung any action reaches is the pivot every other cell is sized to.

  • assist
  • advise
  • prepare
  • decide
  • execute
05Tools & Action Channels

Which tools, systems or channels may it use to get information, make changes, communicate or take action?

A consequential tool with no matching boundary in Cell 06 is an action with nothing to stop it.

06Rules & Boundaries

What must it always do, what must it never do, and when must it stop, escalate or hand off?

The boundaries you do not draw are the ones the model will improvise. Empty Rules beneath high autonomy is the highest-risk pattern on the canvas.

Knowledge what it may know

07Context & Knowledge

What information may it use, and which sources should take priority when they disagree?

An agent grounded on nothing, or on unvetted sources, cannot meet a serious accuracy bar, and when two trusted sources disagree, something has to govern.

08Memory & Learning

What should it remember across interactions, what must it forget, and how should it learn and improve over time?

What persists between sessions is a privacy and liability choice, not a technical detail.

Accountability who answers

09Ownership & Oversight

Who owns the workflow outcome, who is accountable for how the agent operates, and how will it be reviewed?

If no one owns the outcome when the agent errs, the design is not ready to ship. Accountability without the power to change or stop the agent produces stakeholders, not an owner.

Cell 04 · autonomy by action

Five rungs. The rung attaches to the action, not the agent.

Every rung is a pair: what the agent does, and what it leaves to a person. Take the consequential actions one at a time. The highest rung any of them reaches is what the rest of the canvas is sized to.

  1. 01

    Assist

    Returns a bounded contribution: an answer, lookup, summary or calculation.

    The human integrates it and completes the work.

  2. 02

    Advise

    Returns an assessment: frames the issue, compares options, may recommend a path.

    The human chooses what action to take.

  3. 03

    Prepare

    Returns a complete, ready-to-use output: an email, plan, booking or report.

    The human reviews it before use or execution.

  4. 04

    Decide

    Makes a binding choice: the option, the classification, the go or no-go. It does not carry it out.

    The human implements the decision.

  5. 05

    Execute

    Makes and implements the choice: sends, files, books, pays, updates records.

    The human steps in only to handle exceptions.

So take the consequential actions one at a time, and place each of them. A consequential action is one where getting it wrong, or letting the agent act on its own, could materially affect an outcome, a person, or the organisation. The same agent may execute one action, prepare another for approval, and only advise on a third. Oxford NHS's Dora executes the follow-up call and the classification that follows it, but only prepares the discharge recommendation, which a clinician confirms. Start by naming the actions that could actually cause harm, and place those.

Want to run it in the room? Download the workshop canvas (A1 PDF) →

The canvas coach

A coach, not a grader.

Fill the nine cells, then let a Claude-backed coach press the gaps a good workshop facilitator would: per cell, plus cross-cell contradictions and an overall readiness read.

  • Socratic, per-cell feedback. It surfaces gaps, vague answers and danger signals, and never invents facts about your company.
  • Cross-cell contradiction flags. A "decide"-level autonomy sitting above an empty Rules cell is a post-mortem waiting to happen, caught now.
  • Autonomy-aware. It judges every cell in proportion to the highest rung any action reaches in Cell 04, and flags one rung asserted for the whole agent when the role plainly holds actions of different consequence.
  • Built for the room. Fill from a photo of a hand-drawn sheet, iterate in rounds, export JSON, print a clean PDF handout. Works in English and Japanese.
The team writes
04 Autonomy by Action

"Autonomy: decide. It approves or declines refunds up to €500 itself."

06 Rules & Boundaries

"Be compliant and sensible."

The coach presses
06 Rules & Boundaries At risk

"Compliant" is a principle, not a boundary. There is no never-do list and no stop trigger beneath decide-level autonomy.

Cross-cell · 04 ↔ 06

Nothing here stops the agent once it is wrong. Draw the stop conditions before you raise the rung.

The question the team must resolve
What must this agent never do with a refund, and what forces it to stop and hand the case to a person?

One unresolved question, surfaced before anyone builds.

The cases

Three agents, designed on the record.

Three organisations, three rungs of the autonomy ladder, one canvas. Each is reconstructed from public sources, filled in cell by cell, and then run through the coach.

Good design does not always mean lower autonomy. It means autonomy matched with evidence, boundaries, tools and accountability.

The canvas as a diagnostic

It also reads backwards.

The three agents above show deliberate design choices in the public record. Run the same nine questions over an agent that does not, and the canvas stops being a design tool and becomes a post-mortem.

Designed by accident

The compass set to the wrong north.

A little over a year later, it narrowed what the agent was allowed to handle and hired people back for the conversations that needed them.

Bloomberg · May 2025 ↗
  • Cell 03 · the measureMeasured cost saved and agents replaced, not the quality of the outcome.
  • Cell 04 · the rungPlaced at execute: handling two-thirds of all interactions, end to end.
  • Cells 06 to 09 · the controlsBlank. No never-do list, no way to detect a distressed customer, no owner.

How to run it

Five moves. Half a day.

The canvas is built to be worked over in a room. Answer its nine questions in half a day now, or discover them the hard way after you ship. In real cases, that has meant months of rework, a public reversal, or an apology to a federal judge.

01

Print it large, fill the room

Put it on an A1 sheet. Gather product, engineering, design, legal or risk, and someone who does the work the agent will touch.

02

Start with the job. Always.

Name the workflow, the contribution the agent is responsible for inside it, the people it serves and the standard it must meet. Do this before anyone discusses what the technology can do. Teams that start with the capability design a clever agent in search of a job.

03

Set the authority envelope

List the consequential actions, place each on the autonomy spectrum, then decide which tools the agent may reach and where its boundaries lie. Every later cell is sized to the highest rung you pick here.

04

Decide what it may know and remember

Which sources it may use, and which one governs when two of them disagree. Then what it carries from one session to the next, what it must forget, and how it should improve over time. Ground the agent, then set its memory.

05

Name accountability, then walk the canvas

Say who owns the workflow outcome, who answers for how the agent operates, and how it will be reviewed. Then walk the whole sheet: the empty cells and the contradictions are the deliverable.

The LLM provides cognition.
You provide control.

For the first time, you have to write it all down before the worker shows up. And the better the model becomes, the more that control is worth. Start on the canvas.

The book

The book behind the canvas.

  • The theoryAgent Operating Model
  • The methodThe Design Canvas
  • The applicationThe coach
  • The argumentThe Undesigned Agent
The Undesigned Agent, a book by Michael Freeman

The canvas and the Agent Operating Model are the spine of The Undesigned Agent, a book I'm writing on building agentic AI an organisation can trust. Leave your email and I'll send the occasional update, new worked examples, and early chapters as they take shape.

No spam. Unsubscribe anytime. The canvas stays free.