← The journal
Applied AI

If You Are Still the Operating System, You Do Not Have an Agent Yet

If you still supply the memory, sequence, judgment, and handoff every time, the model may be useful. The operating layer is still you.

By Lauren Mack  ·  Co-founder, Keeks


A founder opens an AI chat, asks a smart question, and gets a smart answer.

Then the real work begins.

She corrects the company context. Checks the sources. Rewrites the recommendation around a constraint the model could not know. Decides what should happen next. Moves the work to another person. Explains the whole thing again. Reviews the result. Remembers what changed.

The answer may have been useful. But the founder was still the memory, the router, the quality check, and the operating system.

That is the part I care about.

I care much less about whether a product calls something an agent than I do about who is still carrying everything the next step depends on. If you still have to supply the memory, sequence, judgment, and handoff every time, you do not have an agent yet. You have a capable model with a human operating layer around it.

A good answer is only one part of the job

Chat is often the right tool. I use it to explore an idea, pressure-test language, summarize material, or think through a decision. For one-time thinking, adding an agent can create more machinery than value.

The need changes when the work repeats, carries information from one step to another, uses company sources, takes action, or has consequences.

Take a recurring competitive research brief.

In chat, a person supplies the category, explains which competitors matter, points to the right company information, checks the sources, catches an outdated assumption, decides what qualifies as evidence, reformats the answer, and sends it to whoever needs it. The model helps with the research. The person still runs the job.

Now imagine that same work assigned to a trained agent.

When I say trained, I usually do not mean retraining the underlying model. I mean training it to do a particular job inside a particular company. It knows the category definition, approved sources, required method, claim boundaries, available tools, completion standard, and next owner. It knows what it may do, what it must verify, and where it has to stop.

A useful agent does not simply have more freedom. It has clearer responsibility and clearer limits.

The improvement is not magical intelligence. The work no longer depends on one person reassembling the operating instructions every time.

Most business work does not fail at the first answer. It fails in the space between the answer and the next responsible action.

Someone still has to notice the missing source. Someone still has to know the client changed a definition three weeks ago. Someone still has to decide whether an exception is normal or dangerous. Someone still has to know who gets the work next.

If all of that still lives inside one person, the AI may have accelerated a step. The system still is not carrying the job.

The seven-part agent contract

Before giving an agent more prompts, memory, or tools, define the contract around one real job.

Every one of these decisions exists already. The question is whether you have put it into the system or whether one person is still carrying it.

1. Job

What result should the agent help produce? What is outside its scope?

“Help with research” is vague. “Produce a source-verified competitive brief for an approved category and route it to the strategy lead” is a job.

2. Context

What must the agent know about the company, category, customer, and current decision? Which source wins when two sources disagree?

More context is not always better. Stale or conflicting context can make an agent wrong in a more company-specific way.

3. Method

What sequence should it follow? Where may it adapt? Which corrections need to become part of the repeatable process?

Without a method, the founder teaches the same lesson in a different chat every week.

4. Tools

What may the agent read, search, create, or change? What proves the action actually happened?

A draft that says a record should be updated is not an updated record. The agent needs a way to read the real result back.

5. Authority

What can it do automatically? What needs approval? What must it never do?

Tool access is not permission. Consequential actions need explicit boundaries.

6. Verification

What source, test, or artifact proves the work is acceptable?

If “done” is vague, the work will stop at something plausible. Consequential work needs evidence outside the conversation.

7. Ownership

Who accepts the result? Who decides when evidence conflicts, a tool fails, or the situation falls outside the expected path?

The agent can carry the work. A human still owns the outcome.

For the research brief, those seven decisions define the system the prompt has to operate inside. The agent can gather from approved sources, label what remains unknown, check its evidence, assemble the brief, and hand it to the named owner. The person is no longer rebuilding the sequence. Human judgment stays where it belongs: defining the question, resolving the exception, and accepting the result.

A bad agent can industrialize a bad process

Agents move the failure, too.

A badly designed agent does not eliminate a bad process. It can industrialize it.

Bad context becomes repeatable bad context. A stale rule becomes a rule followed perfectly. An unsupported assumption can travel farther because no person happens to interrupt it. Too much authority can turn a weak recommendation into an external action before anyone notices the gap.

Memory is not judgment. A saved procedure can preserve a good method, or preserve an outdated one. A successful tool call can still produce the wrong business result.

Sources change. Definitions change. Permissions change. If nobody owns the maintenance, the agent can keep following yesterday’s rules perfectly long after the business has moved on.

The goal is not to create the most autonomous agent. The goal is to remove the right work without removing the judgment, control, and accountability the company still needs.

Find the person hiding inside the workflow

Take one recurring job you currently do with AI.

After the model gives you its answer, look at what happens next. Name everything a person still has to remember, decide, check, move, explain, or approve.

That inventory tells you what you actually have.

You may discover that chat is enough. Good. Use the simpler tool.

You may discover that the model is doing useful work, but a person is still carrying the continuity, sequence, evidence, exceptions, and handoff. That is the operating layer you have not built yet.

A better model can improve the answer. A better operating system is what gives the answer somewhere to go.