← Field Notes

An Agent Directory Needs an Owner, Not Just a Listing

A reusable agent deserves more than a searchable name. Five visible signals can help people judge whether it is current, appropriately scoped and worth considering for reuse.

Field Notesagent-governanceworkflow-lifecyclemarket-watch

A directory makes reuse look simple. Search for an agent, read a short description, choose it and get on with the work. That convenience is useful, but it can hide the questions that matter most: Who maintains this? Who is meant to use it? What information can it use? Has anyone reviewed it recently? What happens when it no longer fits?

Those are not paperwork questions. A reusable agent can carry instructions, connections, access to organisational knowledge and a reputation earned from prior work. Once it is easy to discover, people may assume it is also current, suitable and authorised for their situation. A listing does not establish any of those things.

Recent product changes from Notion, Microsoft and Atlassian point to a more useful model. They treat agents not only as prompt endpoints, but as organisational objects with an audience, management surface, review state and a route to change or withdraw them. Their products differ, and their documentation is not evidence that every organisation administers agents well. Still, the pattern gives teams a practical way to make reuse more legible.

A directory is a decision surface

A directory changes an agent from something a creator remembers into something another person may choose. That makes the directory part of the decision, not a passive inventory.

Notion documentation distinguishes what a Custom Agent can access from who can access the agent. It says an agent has its own permissions, and warns that sharing an agent can let its users retrieve information from resources they could not otherwise open. It also gives enterprise administrators an Agent Directory that shows the creator and last-active time, and lets them disable editing, chatting and triggers. Notion sharing and permissions guidance is a useful reminder that an agent scope and its audience are separate controls.

Microsoft makes a related separation between a privately shared agent and an organisation-catalogued version. The maker can continue to iterate on the shared version, while changes to the catalogued version require resubmission and administrator approval. Its documented review includes capabilities, knowledge sources, sensitivity labels and developer metadata. Microsoft catalog guidance does not make an approved agent correct. It does show that broad distribution can have a different lifecycle from a pilot.

Atlassian August release notes describe a central view for governing Rovo agents, default access policies for new agents, granular permissions and an administrator-assigned verified status that can be removed. The release is marked as rolling out, so availability may vary. Atlassian release notes show a similar shift: discovery is being connected to administration rather than left as a collection of isolated agent cards.

The inference is modest but important. If people can discover and reuse an agent, they need enough visible context to decide whether that reuse is sensible.

Five signals worth showing before reuse

A useful directory does not need to expose every prompt or every internal trace. It should show the smallest set of facts that lets a person ask a better question before choosing an agent or workflow.

1. A named accountable owner

Show the person or team responsible for maintaining the listing, not merely the original creator. Creation and stewardship can diverge. An owner can answer whether the agent is still supported, receive a report when it misbehaves and arrange replacement when an underlying source or rule changes.

Ownership also needs continuity. Notion documents an ownership-transfer flow for agents left behind by departing users and says an agent without an owner stops running after seven days. That is a product-specific behaviour, not a universal rule. The general lesson is safer: an agent with no accountable steward should not quietly look like a dependable shared tool.

2. An intended audience and permitted context

A listing should say who the workflow is intended to help and what context it is allowed to use. That can be a role, a project boundary, a set of approved sources or a clear statement that it should not receive sensitive participant information.

This is especially important where an agent access exceeds the user's own direct access. The audience label tells people who may use the agent. The context label tells them what the agent is designed to see and do. Neither label grants a new permission. Together, they make an accidental mismatch easier to spot.

3. A lifecycle state that means something

A single active label conceals too much. A small, plain lifecycle vocabulary is more useful: draft, pilot, approved, paused, superseded or retired. The key is that each state changes the reader expectation. A pilot may be appropriate for a named test group. An approved workflow may be available to its stated audience. A paused or retired one should be difficult to select by mistake.

Microsoft separation between shared and catalogued versions illustrates why this matters. Private iteration and broad organisational availability are different conditions. A directory should not blur them into one reassuring-looking card.

4. A review date and review scope

A last-updated date is useful, but it is not proof that someone examined the right risks. Pair a visible review date with a short statement of what was reviewed: purpose, audience, sources, permissions, instructions or operational changes. If no review has occurred, say so.

This is not an argument for perpetual approval. Review can be proportionate to the agent reach and consequences. A read-only drafting assistant may need a lighter check than a workflow with access to shared records or the ability to trigger a downstream process. The point is to make the basis for trust inspectable rather than implied.

5. A withdrawal and replacement path

Every reusable object eventually becomes wrong for some context. A source can change, an owner can leave, a policy can be revised or a newer workflow can replace it. The directory should say what happens next: pause the agent, point to its replacement, notify the owner or return work to a human decision-maker.

Atlassian ability to unverify an agent and Notion ability to disable agent editing, chatting and triggers are examples of reversible controls. They do not prove a particular agent is safe or suitable. They do show that withdrawal needs to be a first-class part of management, not an improvised response after someone has already relied on outdated guidance.

Keep discovery separate from authority

A clear directory can reduce confusion, but it cannot turn a recommendation into consent or an output into an authorised action. An owner label is not a booking authority. A verified mark is not a guarantee of accuracy. An approved catalogue entry is not confirmation from an external provider, permission to make a payment or agreement from the people affected by a decision.

That boundary matters for any planning workflow. A reusable agent might help frame options, gather stated constraints or prepare a decision record. The human responsible for a consequential choice still needs to judge the current facts, the affected people and the authority required to proceed. The directory should make that handoff visible rather than implying that reuse completes the work.

A small test for a more trustworthy directory

For PatOS, a sensible starting point is a reusable workflow card that shows purpose, intended audience, accountable owner, permitted sources or participant context, lifecycle state, last review and the human decision owner. When it is paused, replaced or retired, the card should explain what to use instead or where to ask for help.

This is a product hypothesis, not a claim about current capability or user demand. It can be tested with a small set of workflows and a concrete question: can a participant identify what they are selecting, who maintains it, what it can use and whether it is current before they rely on it? Measure comprehension and the quality of routing, not just clicks or search success.

The useful outcome is not a more impressive catalogue. It is a clearer moment of choice. An agent directory earns trust when it helps people see the limits of an agent as clearly as its promise.

Sources