# AI Agent Ownership Matrix

Use this matrix to assign five distinct responsibilities before an agent reaches production. Replace job titles with named people, add backups, and review the row whenever the agent gains a new tool, data source, or level of autonomy.

| Agent type | Business Owner | Technical Owner | Security Owner | Approver | Escalation Owner |
|---|---|---|---|---|---|
| Customer support, refunds, or exceptions | Head of Support / VP Customer Operations | Support engineering or automation lead | Product Security and Privacy lead | Support manager; Finance approver above refund threshold | VP Customer Operations or executive on call |
| Sales outreach or pipeline | VP Sales / Revenue Operations owner | GTM engineering or CRM systems owner | Privacy and Security lead | Sales manager; Legal or Brand reviewer for regulated/high-impact outreach | CRO / VP Sales |
| Finance payment, invoice, or procurement | CFO / Controller / Head of Procurement | Finance systems or automation lead | Security / IAM owner | Finance approver; CFO or Controller above threshold | Controller, CFO, or Finance incident lead |
| HR, hiring, compensation, or employee workflow | CHRO / Head of People Operations | HRIS or internal tools owner | Privacy and Security lead | HR business partner or compensation authority | CHRO, Legal, or employee-relations lead |
| Security, IAM, incident, or access change | CISO / Head of IAM / IT owner | Security engineering or platform engineering | GRC or security architecture owner | IAM owner, incident commander, or privileged-access approver | CISO or security executive on call |
| Engineering deploy, production, or infrastructure | VP Engineering / Platform or SRE owner | Service-owning engineering team | Product Security owner | Release manager, service owner, or SRE on call | Incident commander or VP Engineering |

## Role definitions

- Business Owner: accountable for the workflow, outcomes, authority boundaries, and accepted business risk.
- Technical Owner: accountable for implementation, reliability, integration, rollback, and change management.
- Security Owner: accountable for identity, access, data exposure, security controls, and security review.
- Approver: authorized to decide a specific action at runtime; may vary by amount, risk, or policy.
- Escalation Owner: receives timeouts and incidents, can stop the agent, and resolves ownership gaps.

Source: Contro1 AI Agent Ownership Matrix, 2026. Adapt it to your organization and record named owners in the agent inventory.
