Saltar al contenido principal

There are four paths AI takes into your organisation. Most teams monitor one.

Cover of The Agent Workforce Lifecycle, a discovery and governance workbook by Sharon Hunneybell, VP of Product at FirstWave

The Agent Workforce Lifecycle

A discovery and governance workbook for enterprise AI assistants and agents. 24 pages, PDF.

We will email you about FirstWave products and events. Unsubscribe whenever you like. Read our privacy policy.

That is the finding the discovery section of this workbook opens with, and it is the reason the rest of it exists. The agents and assistants are already running inside your business. The question is whether you can name them, own them, and prove what they did.

By Sharon Hunneybell, VP of Product at FirstWave. Free, and vendor-neutral until the clearly marked last part.

Four paths to watch

Discovery is not a numbered first step you tick off. It sits outside the sequence because it never finishes. These are the four paths worth monitoring, and most organisations monitor one of them, at most.

  1. 1

    Installed tooling on endpoints and servers

    Found through software inventory and change detection.

  2. 2

    Browser and API traffic to AI services

    Found through web gateway, DNS, and egress logs.

  3. 3

    Procurement and expense data

    Found through card statements and subscription reconciliation.

  4. 4

    Vendor feature releases inside software you already licence

    Found only by reading release notes.

    This is the path with no technical detection. Nothing is installed, no new destination appears, and new features are often on by default. The only control that works is asking someone to read the release notes for your top twenty vendors, once a quarter.

How much of this do you owe?

Three questions, asked of any AI tool you have found. They set how much of the lifecycle that tool needs. Answer them here and the stages you owe are marked in the ledger below.

  1. Can it read data that belongs to your organisation?

  2. Can it take an action in one of your systems?

  3. Can it take that action without a person approving it?

Tier one
Give it a data boundary and leave it alone.
Tier two
Run point zero, stage one, stage two and stage six.
Tier three
Run point zero and all six stages, with a named owner.

The lifecycle, and the requirement each stage already answers

Six stages in a loop, plus point zero, which runs in the background and never ends. This is the crosswalk from Part Three of the workbook. It is here because none of this is new obligation: every stage but the last maps onto a requirement somebody has already written down.

  1. Point zero. Discover

    Find what exists, and keep finding it. Point zero sits outside the numbered sequence because it is never done.

    Closest existing requirement
    Inventory or register of AI systems in use
    Source
    ISO/IEC 42001, NAIC Guidance for AI Adoption register template. APRA expects an inventory of AI tooling and use cases.
  2. Stage 1. Onboard

    Assign a named human owner and a unique identity, so accountability and access are clear from day one.

    Closest existing requirement
    Accountability process, governance and ownership
    Source
    Voluntary AI Safety Standard guardrail on regulatory compliance, ISO/IEC 42001.
  3. Stage 2. Authorise

    Give each agent only the access it needs for its specific task, for only as long as it needs it, with human approval for anything that cannot be undone.

    Closest existing requirement
    Least agency, task scoped and time limited permissions
    Source
    OWASP Top 10 for Agentic Applications 2026.
  4. Stage 3. Monitor

    Watch what the agent is doing, so you can detect unusual behaviour, investigate incidents, and verify what happened.

    Closest existing requirement
    Post deployment monitoring and performance evaluation
    Source
    Voluntary AI Safety Standard guardrail on testing, NIST AI RMF measure and manage.
  5. Stage 4. Audit

    Independently verify the agent’s work, so you have evidence you can trust rather than the agent’s own account of what it did.

    Closest existing requirement
    Records enabling third party assessment of compliance
    Source
    Voluntary AI Safety Standard guardrail on records, ISO/IEC 42001 certification audit.
  6. Stage 5. Remediate

    Be able to stop the agent, contain the damage, and recover safely when something goes wrong or its behaviour changes.

    Closest existing requirement
    Human control and meaningful oversight across the lifecycle
    Source
    Voluntary AI Safety Standard guardrail on control, OWASP goal hijack and tool misuse.
  7. Stage 6. Offboard

    Remove the agent completely when it is no longer needed, including its access, integrations, data and dependencies, and keep evidence that it is gone.

    Closest existing requirement
    Named as a gap by a regulator, not yet a standard
    Source
    APRA Letter to Industry on Artificial Intelligence, 30 April 2026.

Offboarding is the one with no standard behind it. A regulator has named it as a gap and nobody has written the control yet, which is exactly why it is the stage most organisations skip. Worksheet 8 is the part of this workbook to do first.

Eight worksheets you write in

A realistic first pass takes about ninety minutes with two or three people in a room. You will not finish it, and that is the point. The gaps you cannot fill in are the findings.

Parts One to Three carry the framework, the worksheets and the standards crosswalk, with no product mentions in them, so they apply whatever software you run. Part Four is marked as vendor content, where FirstWave capability is mapped against the same stages.

  1. 1Inventory and tiering
  2. 2Discovery register
  3. 3Agent record card
  4. 4Permission scope
  5. 5Logging coverage
  6. 6Audit plan
  7. 7Remediation readiness
  8. 8Offboarding checklist

Run discovery as an amnesty, not an audit.

If people expect consequences they will hide what they are using, and you will end up governing the small honest fraction while the rest carries on unchanged. If you take one thing from this workbook, take that.

Get the workbook