How to Write a Job Description for an AI Agent: 6 Essential Elements for Governance
Learn how to write an AI agent job description that defines roles, permissions, decision authority, guardrails, and escalation paths for better AI governance.
- AI Agents
- AI Governance
- Agent Operations
- Agent Design

An AI agent job description defines an agent's role, responsibilities, permissions, decision authority, success criteria, escalation paths, and guardrails. Like a job description for a human employee, it establishes what the agent owns, what it can access, which decisions it can make, and when it must involve a human.
For businesses deploying AI agents, that clarity is a foundation for effective AI agent governance.
A prompt alone isn't enough. A simple prompt tells an agent what to do right now. It doesn't define the full scope of what it's responsible for, where its authority lies, or what success looks like.
AI agents only know what they're told. That's why organizations need to start thinking of agents as newly hired employees instead of just smart software.
And every new hire starts with a job description.
The six elements every AI agent job description needs
Without clearly defined responsibilities and boundaries, an AI agent has no reliable way to know where its job begins or where it ends. So here are the six things you need to outline in its job description:
1. Scope: What is the AI agent responsible for?
Start by briefly defining the agent's primary responsibility. Describe what it's supposed to accomplish and, just as importantly, what falls outside its role.
Example: "Your job is to handle Tier 1 customer support inquiries, answering common product questions and creating support tickets when necessary. Do not process refunds or provide legal or financial advice."
Clearly delineating scope prevents the agent from drifting into doing work that belongs to others in the organization, whether they're human or non-human.
2. Tools and access: What systems can the AI agent access?
Document exactly which systems, accounts, datasets, and tools the agent is allowed to interact with.
For example, your job description might specify that the agent can access:
- Your CRM to look up customer records
- A knowledge base to answer product questions
- A ticketing system to create and update support cases
- Internal documentation on company policies
If a tool or dataset isn't on the list, the agent shouldn't touch it.
Tip: Follow the principle of least privilege, which states that a user should be restricted to the bare minimum permissions necessary to execute their job and nothing more.
3. Decision authority: What can the AI agent decide independently?
Every human employee has decisions they can make independently at their own discretion, while others require manager sign-off first. AI agents need the same clarity around their own authority.
Define these boundaries explicitly so the agent knows exactly when to bring a human or a higher-tier agent into the loop.
For example, you might stipulate that the agent can:
- Answer common customer questions
- Share order status updates
- Create support tickets
- Schedule appointments
But it must escalate things like:
- All refund requests, or only those above a certain threshold
- Requests involving sensitive customer data
- Legal, financial, or compliance questions
- Security incidents
Defining decision authority is the most important part of the job description, yet it's often neglected -- and security depends upon it.
4. Success criteria: How should you measure AI agent performance?
Agents need objectives just like employees do. But instead of vague expectations like "provide excellent customer service," it's best to establish specific outcomes for your agent.
Think in terms of key performance indicators (KPIs). These are measurable values that show how well an employee is executing tasks, including metrics like resolution percentage, response time, escalation accuracy, customer satisfaction, and error rate.
KPIs should be goal-focused and tracked over time. Remember: If you can't measure whether your agent is succeeding, it'll be difficult to improve its performance or to know when something's gone wrong.
5. Escalation path: When should the AI agent involve a human?
Even the best agent won't have the answer to every situation. That's to be expected. The important part is what happens next.
In some scenarios, a task might have to be escalated to a domain-specific expert agent with broader capabilities. In others, a human might need to get involved.
Your job description should specify things like:
- When the agent should stop and ask for help
- Who it should notify
- What information it should include in the agent-to-human or agent-to-agent handoff
- Whether it should wait for approval before taking any additional action
An effective agent knows its limits -- so make sure it doesn't have to guess what they are.
6. Non-negotiable boundaries: What should an AI agent never do?
AI agents don't have common sense. You can't rely on them to recognize that "this isn't a good idea" unless you've told them so. (Well, sometimes that's true of humans, too, but we digress.)
Every agent should have a short list of non-negotiable rules that apply regardless of the task at hand. It goes deeper than scope, access permissions, or decision authority. These are specific actions it should never take under any circumstance.
For example, you might include guardrails such as:
- Never bypass required approval workflows.
- Never make financial or legal commitments on the organization's behalf.
- Never override security or compliance controls.
- Never impersonate a human employee.
- Never claim to have completed work that hasn't actually been completed.
Of course, this list won't cover every possible scenario, but the ones it does cover should never be left open to interpretation.
The bottom line: Treat agent design like org design
AI agent governance starts with clear roles and responsibilities
Most organizations won't have just one AI agent on their team. As they deploy multiple agents -- perhaps dozens or even eventually hundreds -- it becomes even more important to have clear roles, clear authority, and clear accountability for each one.
This is an organizational design problem. Essentially, agents should be treated the same way human employees are treated: with specific roles, measurable expectations, well-defined boundaries, and governance built in from the start.
Before deploying your next AI agent, ask yourself: Could you hand its job description to a newly hired employee and expect them to understand the role?
If not, you probably haven't defined the role clearly enough for the agent, either.
Still figuring out what your agent's job should look like? We can help.
See your agents, govern what they do, and prove it to anyone who asks.