The operating model for agentic AI
Don't prompt.
Design.
A one-page canvas and an AI coach for the nine decisions that make an agent useful, governable and worth building, before code turns assumptions into operating reality.
Agentic AI design is org design: settle the job, the authority, the knowledge and the accountability before the worker shows up.
Developed by Michael Freeman, INSEAD
The diagnosis
The model keeps improving.
The failure rate does not.
The cause is not in the technology. An un-designed agent is still designed, only by accident, in code, by whoever shipped first, and the briefing nobody wrote is the one the model ends up inventing for itself. A person you hire restrains themselves, remembers, and can be held to account; an agent brings none of that, so every design decision you skip to close the gap is a debt, and model capability is the interest rate.
new hire
Worker the LLM
Capable, articulate, probabilistic. It arrives trained on the world and briefed on none of your work.
Harness the operating system around it
The part you control. Five things, each already familiar from managing people:
Tools the systems it can act on
A web search, a database query, an email sent. The worker issues a command, the harness catches it, the system executes. An LLM in a loop, with tools.
The Agent Operating Model
Every agent has an anatomy.
Each of the three layers supplies one term of the same equation. Most failures trace to the same blind spot. The worker is chosen with care, then wrapped in a harness and a governance regime that nobody designed.
power = cognition × control × reach
It is a product, not a sum, which is why a brilliant worker with wide reach and no control is a liability. Add a calendar and the worker becomes a scheduler; give it the authority to move money and it becomes a fiduciary actor. The more reach you grant, the more control the harness has to hold.
The canvas
Nine decisions, before the build.
One North Star, four design questions and nine operating decisions. The Agentic AI Design Canvas turns the Agent Operating Model into choices a team makes on paper, before anyone writes a line of code.
Agentic AI Design Canvas
North Star
What business outcome should this agent's work ultimately contribute to?
Target Workflow & Agent Role
Which workflow is it part of, and what contribution is the agent responsible for making within it?
01Users & Stakeholders
Who uses it directly, and who else is affected by what it does?
02Success Measures & Standards
What measures will show that the workflow improved, and what performance standards must the agent meet?
03Context & Knowledge
What information may it use, and which sources should take priority when they disagree?
07Memory & Learning
What should it remember across interactions, what must it forget, and how should it learn and improve over time?
08Ownership & Oversight
Who owns the workflow outcome, who is accountable for how the agent operates, and how will it be reviewed?
09
- Assist
- helps a person do the work.
- Advise
- recommends a course of action.
- Prepare
- assembles a ready-to-use output for approval.
- Decide
- selects the outcome, but does not carry it out.
- Execute
- carries out the authorised action or workflow.
Choose the highest rung the agent reaches anywhere in the scoped workflow.
Select a cell for its question, or a category for its territory
What business outcome should this agent's work ultimately contribute to?
One outcome the whole design serves, and every cell below answers to it.
Job what it's for
01Target Workflow & Agent Role
Which workflow is it part of, and what contribution is the agent responsible for making within it?
An agent left to infer its own job from an outcome or a task list has nothing telling it what its activities are meant to add up to.
02Users & Stakeholders
Who uses it directly, and who else is affected by what it does?
If the people the agent can harm never appear on the canvas, nobody designs for them.
03Success Measures & Standards
What measures will show that the workflow improved, and what performance standards must the agent meet?
Two different things: whether the work got better, and whether the agent performs well enough. Without both, nothing defines "good enough" before it acts.
Authority what it may do
Knowledge what it may know
07Context & Knowledge
What information may it use, and which sources should take priority when they disagree?
An agent grounded on nothing, or on unvetted sources, cannot meet a serious accuracy bar, and when two trusted sources disagree, something has to govern.
08Memory & Learning
What should it remember across interactions, what must it forget, and how should it learn and improve over time?
What persists between sessions is a privacy and liability choice, not a technical detail.
Accountability who answers
09Ownership & Oversight
Who owns the workflow outcome, who is accountable for how the agent operates, and how will it be reviewed?
If no one owns the outcome when the agent errs, the design is not ready to ship. Accountability without the power to change or stop the agent produces stakeholders, not an owner.
Cell 04 · autonomy by action
Five rungs. The rung attaches to the action, not the agent.
Every rung is a pair: what the agent does, and what it leaves to a person. Take the consequential actions one at a time. The highest rung any of them reaches is what the rest of the canvas is sized to.
-
01
Assist
Returns a bounded contribution: an answer, lookup, summary or calculation.
The human integrates it and completes the work.
-
02
Advise
Returns an assessment: frames the issue, compares options, may recommend a path.
The human chooses what action to take.
-
03
Prepare
Returns a complete, ready-to-use output: an email, plan, booking or report.
The human reviews it before use or execution.
-
04
Decide
Makes a binding choice: the option, the classification, the go or no-go. It does not carry it out.
The human implements the decision.
-
05
Execute
Makes and implements the choice: sends, files, books, pays, updates records.
The human steps in only to handle exceptions.
So take the consequential actions one at a time, and place each of them. A consequential action is one where getting it wrong, or letting the agent act on its own, could materially affect an outcome, a person, or the organisation. The same agent may execute one action, prepare another for approval, and only advise on a third. Oxford NHS's Dora executes the follow-up call and the classification that follows it, but only prepares the discharge recommendation, which a clinician confirms. Start by naming the actions that could actually cause harm, and place those.
Want to run it in the room? Download the workshop canvas (A1 PDF) →
The canvas coach
A coach, not a grader.
Fill the nine cells, then let a Claude-backed coach press the gaps a good workshop facilitator would: per cell, plus cross-cell contradictions and an overall readiness read.
- Socratic, per-cell feedback. It surfaces gaps, vague answers and danger signals, and never invents facts about your company.
- Cross-cell contradiction flags. A "decide"-level autonomy sitting above an empty Rules cell is a post-mortem waiting to happen, caught now.
- Autonomy-aware. It judges every cell in proportion to the highest rung any action reaches in Cell 04, and flags one rung asserted for the whole agent when the role plainly holds actions of different consequence.
- Built for the room. Fill from a photo of a hand-drawn sheet, iterate in rounds, export JSON, print a clean PDF handout. Works in English and Japanese.
Nothing here stops the agent once it is wrong. Draw the stop conditions before you raise the rung.
What must this agent never do with a refund, and what forces it to stop and hand the case to a person?
One unresolved question, surfaced before anyone builds.
The cases
Three agents, designed on the record.
Three organisations, three rungs of the autonomy ladder, one canvas. Each is reconstructed from public sources, filled in cell by cell, and then run through the coach.
CoreMate
the thirteenth chair in the boardroom
- assist
- advise
- prepare
- decide
- execute
The AI received a role, not decision authority. It challenges proposals before and during senior meetings, and executives keep the vote.
Open the full canvas → AllianzProject Nemo
the agent that audits the agents
- assist
- advise
- prepare
- decide
- execute
Seven agents settle a claim in minutes. The pipeline calculates the payout but cannot pay it. That one action is withheld from every agent in the system.
Open the full canvas → Oxford NHS · UfoniaDora
the agent on the telephone
- assist
- advise
- prepare
- decide
- execute
Executes the follow-up call and its routing end to end; the discharge decision stays with a clinician. Autonomy earned through published evidence, a tight scope and an explicit hand-off.
Open the full canvas →Good design does not always mean lower autonomy. It means autonomy matched with evidence, boundaries, tools and accountability.
The canvas as a diagnostic
It also reads backwards.
The three agents above show deliberate design choices in the public record. Run the same nine questions over an agent that does not, and the canvas stops being a design tool and becomes a post-mortem.
The compass set to the wrong north.
A little over a year later, it narrowed what the agent was allowed to handle and hired people back for the conversations that needed them.
Bloomberg · May 2025 ↗- Cell 03 · the measureMeasured cost saved and agents replaced, not the quality of the outcome.
- Cell 04 · the rungPlaced at execute: handling two-thirds of all interactions, end to end.
- Cells 06 to 09 · the controlsBlank. No never-do list, no way to detect a distressed customer, no owner.
How to run it
Five moves. Half a day.
The canvas is built to be worked over in a room. Answer its nine questions in half a day now, or discover them the hard way after you ship. In real cases, that has meant months of rework, a public reversal, or an apology to a federal judge.
Print it large, fill the room
Put it on an A1 sheet. Gather product, engineering, design, legal or risk, and someone who does the work the agent will touch.
Start with the job. Always.
Name the workflow, the contribution the agent is responsible for inside it, the people it serves and the standard it must meet. Do this before anyone discusses what the technology can do. Teams that start with the capability design a clever agent in search of a job.
Set the authority envelope
List the consequential actions, place each on the autonomy spectrum, then decide which tools the agent may reach and where its boundaries lie. Every later cell is sized to the highest rung you pick here.
Decide what it may know and remember
Which sources it may use, and which one governs when two of them disagree. Then what it carries from one session to the next, what it must forget, and how it should improve over time. Ground the agent, then set its memory.
Name accountability, then walk the canvas
Say who owns the workflow outcome, who answers for how the agent operates, and how it will be reviewed. Then walk the whole sheet: the empty cells and the contradictions are the deliverable.
The LLM provides cognition.
You provide control.
For the first time, you have to write it all down before the worker shows up. And the better the model becomes, the more that control is worth. Start on the canvas.
The book
The book behind the canvas.
- The theoryAgent Operating Model
- The methodThe Design Canvas
- The applicationThe coach
- The argumentThe Undesigned Agent
The canvas and the Agent Operating Model are the spine of The Undesigned Agent, a book I'm writing on building agentic AI an organisation can trust. Leave your email and I'll send the occasional update, new worked examples, and early chapters as they take shape.