The Signal #7 - AI Agent Governance for Project Managers: The One-Hour Charter
Governing the AI agents in your project takes three steps: register every automation with a named owner, assess each one for what breaks when it fails, and match controls to that risk - nothing more. That’s an agent governance charter, and for most projects the first version takes about an hour.
Most projects need one and don’t have it. There’s a scheduled prompt drafting the status report. A Make.com flow chasing overdue actions. AI features switched on inside Jira, Notion, and someone’s email rules.
Each was set up by a capable person, in an afternoon. Most have never been reviewed since. Nobody decided that was fine - it just happened, one useful automation at a time.
Which leaves a question with no current answer: when the sponsor asks “who approved that?”, what do you say?
The Signal: AI agent governance is delegation discipline, not new process
You already govern delegation. When you hand work to a person, you know who owns it, what happens if it goes wrong, and who they escalate to. RAID logs, decision registers, escalation paths - years of discipline, all pointed at human delegation.
Agents are delegation. The same discipline applies, and none of it needs inventing. An agent register is a stakeholder register for non-human workers. An escalation path is an escalation path. The only new skill is assessing agents honestly: what specifically breaks when this fails, how reversible is it, and has it earned trust in this context - or just avoided scrutiny so far?
The teams getting this right aren’t using agents better. They just know what they’re running.
The Noise: “Governance will slow the team down”
The objection is fair - most governance efforts die of their own weight, and nobody wants a review gate on a bot that formats meeting notes.
Proportionate matching solves this. Every control has to trace to a specific risk factor, which means a low-stakes, mechanical, easily corrected automation gets exactly one lightweight control: an occasional glance at its behaviour. The heavyweight controls are reserved for agents whose failures reach stakeholders or the project record - where you’d want them anyway. Deciding what not to govern is half the value of the exercise.
The Tool: a four-question risk assessment for any agent
Paste this into Claude, ChatGPT, or Gemini and describe one automation from your project. It returns a risk profile and the single control that matters most.
You are a governance analyst assessing the risk profile of a single
AI agent or automation.
I'll describe one agent: what it does, what it produces, and where
its output goes. Work through these four questions and give me a
clear assessment for each - don't just restate my description back
to me.
1. CONSEQUENCE OF FAILURE
What specifically breaks if this agent produces a bad output?
Classify as:
- Minor (formatting error, missed item - easily spotted)
- Meaningful (wrong data populated, missed flag - correctable)
- Significant (affects a decision, stakeholder action, or
project record)
2. REVERSIBILITY
If the agent produces a bad output, how easy is it to correct
after the fact?
Classify as: Easy / Moderate / Difficult
3. TASK TYPE
What kind of work is the agent doing?
Classify as:
- Mechanical (clear inputs, clear outputs, no judgement required)
- Mixed (mostly mechanical with some interpretation)
- Judgement-dependent (requires contextual assessment - right
answer varies by situation)
4. TRACK RECORD
How established is this agent in this specific context?
Classify as: New / Developing / Established
Based on these four answers, give me:
- An overall risk profile: Low / Moderate / High
- A one-sentence justification for that rating
- A recommendation for the MINIMUM control needed right now (not
every possible control - just the one that matters most given
this profile)
CONSTRAINTS:
- Be specific. "It could go wrong" is not an answer - name the
actual failure mode
- If I haven't given you enough information to assess a question,
ask for it rather than guessing
- Use British/Australian English
AGENT DESCRIPTION:
[Describe what this agent does, what it produces, where the output
goes, and how long it's been running]
Run it on the automation you’d least like to explain to your sponsor. That’s usually the right place to start.
The Toolkit
The free Agent Governance Starter covers the full cycle, one agent at a time:
- The Agent Inventory Builder - surface every agent running in your project
- The Consequence Assessor - the four-question risk profile above
- The Control Recommender - proportionate controls, never bureaucracy
- The Escalation Path Drafter - who notices, who’s told, who fixes it
- The Charter Summary Email - a stakeholder-ready governance update
Get all five free at projectorpm.xyz/agent-governance-charter
Yes, AI helped me to write this :)