Field note 02

A useful virtual employee still needs a job description

A human hand stamps a red approval check beside a defined charcoal role card and connected inputs
A role is useful when responsibility, access and approval are explicit.

Calling something an agent does not tell a team what it owns. A useful Virtual Employee needs the same operational clarity expected of any role: purpose, outcomes, inputs, tools, authority, escalation and a manager. NIST warns that unclear responsibilities and chains of command limit effective risk management.[1]

Begin with purpose and outputs

Write one sentence that explains why the role exists. Then name the outputs another person can inspect. “Help with operations” is too broad. “Prepare the daily delivery-exception list for the logistics manager by 9:00” is concrete enough to test.

Do not describe the role by model features. Describe the work:

Define knowledge and access

List every source the role may read and every system it may touch. Access should be no broader than the job requires. Separate reference knowledge from live operational data, and separate reading from writing. OWASP’s agent-security guidance likewise recommends granting only the minimum tools required for the specific task.[2]

Separate preparation from authority

Use four verbs to make authority visible: prepare, recommend, execute and approve. A role may prepare a customer response without being allowed to send it. It may recommend a credit adjustment without changing the account. It may execute a reversible filing step while a manager retains approval over a commitment.

A human must approve consequential actions. The role may never approve its own legal, financial, safety, access, publication or customer-commitment action. OWASP recommends explicit approval for high-impact or irreversible actions.[2]

Write escalation as part of the job

Escalation is not a fallback sentence. Define observable triggers:

Name the person or role that receives each handover. Require the handover to include the trigger, relevant records, checks already completed, unresolved question and requested decision so the person does not restart the investigation.

Assign management and review

Every Virtual Employee needs an accountable manager. That person reviews quality, resolves exceptions, approves changes to the role and decides when authority may expand. Review a small scorecard rather than one vague accuracy number:

A reusable job-description template

A filled example: supplier-invoice exception reviewer

Test the description with real cases

Run normal work, edge cases and deliberately incomplete inputs through the role description before deployment. If two people interpret its authority differently, the job is not defined yet. Fix the role before adding more automation.

A Virtual Employee becomes useful when the team knows what it owns, what it cannot do and exactly when a person takes over. NIST’s playbook also calls for organizations to establish the frequency and detail of monitoring, auditing and review.[1]

Sources

  1. NIST AI RMF Playbook — Govern
  2. OWASP AI Agent Security Cheat Sheet

Discuss a role for your team ↗