Docker Inc

Who Answers for the Agent?
Security work assumes that whoever took an action can be asked about it afterward. Incident response starts by finding the person and asking what they were doing.
Agents break that assumption. The agent acted and cannot be questioned afterward. The engineer whose name sits on the merge did not make the decision and may not be able to explain it. On one repository that is a curiosity. Across an engineering organization it is structural.
This is bigger than coding agents. Every company is deciding what agents should be allowed to do. Very few are asking who will answer for those actions six months later, during an incident or an audit.
I spent this year building an answer in one narrow place. We designed an approval process in which agents review and approve production changes and the control still has to hold up under audit.
The answer is not to put a human name on the agent's decision. It is to build accountability into the moment the agent acts. You decide in advance what the agent must record, what authority it has, and who owns the role it is performing.
That also answers the scale problem. Accountability attaches to each role the agent is given, not to the agent as a whole.
We are testing the model now.
The next time you hear "the agent did it," you will not hear an explanation. You will hear a missing control.
Bio:
Chad Fryer is a Senior Manager of GRC and Privacy at Docker, where he works on GRC engineering, treating compliance as a technical discipline built on automation and code rather than documents. He writes for the GRC Engineering Community Blog, builds open source GRC tools adn co-founded BSidesFortWayne, Indiana's largest security conference.