The Signal #7

The Signal #7 - AI Agent Governance for Project Managers: The One-Hour Charter

· 4 min read

The Signal #7 - AI Agent Governance for Project Managers: The One-Hour Charter

Governing the AI agents in your project takes three steps: register every automation with a named owner, assess each one for what breaks when it fails, and match controls to that risk - nothing more. That’s an agent governance charter, and for most projects the first version takes about an hour.

Most projects need one and don’t have it. There’s a scheduled prompt drafting the status report. A Make.com flow chasing overdue actions. AI features switched on inside Jira, Notion, and someone’s email rules.

Each was set up by a capable person, in an afternoon. Most have never been reviewed since. Nobody decided that was fine - it just happened, one useful automation at a time.

Which leaves a question with no current answer: when the sponsor asks “who approved that?”, what do you say?

The Signal: AI agent governance is delegation discipline, not new process

You already govern delegation. When you hand work to a person, you know who owns it, what happens if it goes wrong, and who they escalate to. RAID logs, decision registers, escalation paths - years of discipline, all pointed at human delegation.

Agents are delegation. The same discipline applies, and none of it needs inventing. An agent register is a stakeholder register for non-human workers. An escalation path is an escalation path. The only new skill is assessing agents honestly: what specifically breaks when this fails, how reversible is it, and has it earned trust in this context - or just avoided scrutiny so far?

The teams getting this right aren’t using agents better. They just know what they’re running.

The Noise: “Governance will slow the team down”

The objection is fair - most governance efforts die of their own weight, and nobody wants a review gate on a bot that formats meeting notes.

Proportionate matching solves this. Every control has to trace to a specific risk factor, which means a low-stakes, mechanical, easily corrected automation gets exactly one lightweight control: an occasional glance at its behaviour. The heavyweight controls are reserved for agents whose failures reach stakeholders or the project record - where you’d want them anyway. Deciding what not to govern is half the value of the exercise.

The Tool: a four-question risk assessment for any agent

Paste this into Claude, ChatGPT, or Gemini and describe one automation from your project. It returns a risk profile and the single control that matters most.

You are a governance analyst assessing the risk profile of a single
AI agent or automation.

I'll describe one agent: what it does, what it produces, and where
its output goes. Work through these four questions and give me a
clear assessment for each - don't just restate my description back
to me.

1. CONSEQUENCE OF FAILURE
   What specifically breaks if this agent produces a bad output?
   Classify as:
   - Minor (formatting error, missed item - easily spotted)
   - Meaningful (wrong data populated, missed flag - correctable)
   - Significant (affects a decision, stakeholder action, or
     project record)

2. REVERSIBILITY
   If the agent produces a bad output, how easy is it to correct
   after the fact?
   Classify as: Easy / Moderate / Difficult

3. TASK TYPE
   What kind of work is the agent doing?
   Classify as:
   - Mechanical (clear inputs, clear outputs, no judgement required)
   - Mixed (mostly mechanical with some interpretation)
   - Judgement-dependent (requires contextual assessment - right
     answer varies by situation)

4. TRACK RECORD
   How established is this agent in this specific context?
   Classify as: New / Developing / Established

Based on these four answers, give me:
- An overall risk profile: Low / Moderate / High
- A one-sentence justification for that rating
- A recommendation for the MINIMUM control needed right now (not
  every possible control - just the one that matters most given
  this profile)

CONSTRAINTS:
- Be specific. "It could go wrong" is not an answer - name the
  actual failure mode
- If I haven't given you enough information to assess a question,
  ask for it rather than guessing
- Use British/Australian English

AGENT DESCRIPTION:
[Describe what this agent does, what it produces, where the output
goes, and how long it's been running]

Run it on the automation you’d least like to explain to your sponsor. That’s usually the right place to start.

The Toolkit

The free Agent Governance Starter covers the full cycle, one agent at a time:

  • The Agent Inventory Builder - surface every agent running in your project
  • The Consequence Assessor - the four-question risk profile above
  • The Control Recommender - proportionate controls, never bureaucracy
  • The Escalation Path Drafter - who notices, who’s told, who fixes it
  • The Charter Summary Email - a stakeholder-ready governance update

Get all five free at projectorpm.xyz/agent-governance-charter


Yes, AI helped me to write this :)