Blog/Can an AI Agent Run Your Role? The Three-Part Test
Agentic AIMaya Workforce AIAI AgentsRole Automation

Can an AI Agent Run Your Role? The Three-Part Test

September 1, 20267 min readBy Brad McCorkle, Founder & CEO, Lesos AI

Test it against three questions. Can the procedural share of the job be written down as steps a new hire could follow. Are the systems it touches specific and named, not a vague description of "the tools I use." And is there a person who owns the sign-off on anything that moves money, grants access, or cannot be undone. Pass all three and the role is a real candidate for an agentic employee. Fail any one of them and it is not, at least not yet.

Gartner predicted in August 2025 that 40 percent of enterprise applications would ship a task-specific AI agent by the end of 2026, up from under 5 percent the year before. That number tells you the market is moving fast. It tells you nothing about whether the role on your desk right now should move first. The three-part test answers that, and it has nothing to do with department or title.

What Is the Three-Part Test for Whether a Role Can Become an Agentic Employee?

The test checks for the three things a role manifest needs: written procedures, named systems, and a sign-off line. A manifest is the file that defines an agentic employee's job: the job description, the tools it may call and the risk class of each, the procedures, the escalation rules, and the failure policy. Missing any one of the three means there is nothing to write into a manifest yet, and the honest next step is closing that gap before evaluating vendors.

  • Written procedures: the steps exist somewhere a new hire could follow cold, not only in one person's head
  • Named systems: the software the role touches is specific enough to grant, scope, and revoke a credential against
  • A sign-off line: a named person owns approval for money, access, and anything irreversible, and that approval has a real denial path

Test One: Are the Procedures Actually Written Down?

This is where most role evaluations quietly fail before they start. "We know how to do this" and "this is written down" are different claims. The first lives in a person's head and comes out differently depending on their mood. The second is a document a new hire could follow without asking a question.

A procedure that says "always verify the requester before a reset" is written down. A note that says "use judgment on vendor exceptions" is not, no matter how confident the person who wrote it feels. The fix is not automation software. It is a week of someone sitting with whoever does the job today and turning what they actually do into steps.

If the procedures are not written yet, write them first.

Test Two: Are the Systems Named and Reachable?

A role that "touches a bunch of internal tools" fails this test. A role that touches your ERP, your HRIS, or your ticketing system by name passes it, because each of those can be granted a scoped credential, logged, and revoked. Vague systems produce vague scope, and vague scope is what a security reviewer rejects on sight.

A system that is already supported is configuration. A new system of record is a scoped connector build with its own timeline and its own cost, and a vendor worth working with will tell you which one your system is before you sign anything, not after.

The constraint is almost never the department. It is whether the systems in question already have a supported connector. IT service desk work against ServiceNow and Entra ID passes this test today because that connector already exists. A role against a system nobody has built a connector for does not fail forever, but it fails this quarter.

Test Three: Is There a Real Sign-Off Line?

Every vendor claims there is a human in the loop. The test is whether the sign-off line names an actual person, and whether that person's "no" resolves cleanly instead of triggering a retry loop that quietly asks again later.

  • Access grants always route to a person, in every role, with no configuration that removes that gate
  • Anything that moves money routes to a person, whether it is a single invoice or a payment run
  • Anything irreversible, like terminating an account or sending something under the company's name, routes to a person

A role with no natural approval point is not disqualified. It usually means the sign-off has never been made explicit, because one person was doing the whole job and approving their own work by default. Naming the approver tends to surface who actually owns the role's risk, which is worth knowing on its own.

Which Roles Pass the Test Today?

IT service desk, accounts payable, HR coordination, and marketing operations deploy fastest on Maya Workforce AI today, because the connectors and procedure patterns already exist for those roles. That is a statement about which systems are already wired, not where the platform stops. Claims intake, order management, dispatch, and scheduling pass the same test on paper. Whether they pass it in your organization depends on how concrete your own procedures and systems are.

RoleWritten proceduresNamed systemsSign-off linePasses the test
IT service desk technicianYes, resets and provisioning are already scriptedYes, ServiceNow, Entra IDYes, any access grantPasses
Accounts payable clerkUsually, PO-matching rules are already documentedYes, the ERP and vendor masterYes, every paymentPasses
Claims intake coordinatorOften, intake checklists existYes, the claims systemYes, above a dollar thresholdPasses, if written down
Brand strategistNo, judgment calls without a repeatable procedurePartial, many tools looselyUnclear, no single money momentFails on procedures

The table is not a verdict on any job's value. It is a verdict on what part of that job can be handed to a manifest today.

Why the Same Test Also Satisfies the Security Reviewer

The three-part test was built for a department head deciding whether to automate a role, but it happens to answer most of what a security reviewer asks separately. Named systems turn a credential grant into something that can be scoped and audited. A real sign-off line turns "human in the loop" from a slide into a control. Gartner's November 2025 forecast projects that more than 40 percent of enterprises will have a security or compliance incident tied to unauthorized shadow AI by 2030. Roles that pass the three-part test are the ones least likely to land in that statistic, because the systems and the approvals got named before anything was deployed. If you are the one who signs off on giving an agent credentials, the questions to ask any AI agent vendor before you hand it credentials go one level deeper, into what happens when a token expires mid-task or a webhook fires twice.

How to Run the Test on Your Own Role

  • Pick the role, not the department. "IT" is not a role. "Password resets for verified requesters" is.
  • Write the procedures down as if training a new hire, this week, not after a vendor call
  • List the specific systems by name and who holds credentials into each one today
  • Name who signs off on money, access, and anything irreversible, even if it is informal today
  • Score all three tests honestly. Two out of three is not a pass

A role that fails today is a to-do list, not a permanent no.

Frequently Asked Questions

What is the three-part test for whether an AI agent can run a role?

It checks for written procedures a new hire could follow, systems specific enough to name and grant a scoped credential against, and a named person who owns sign-off on money, access, and anything irreversible in that role. All three have to be true for the role to be a real candidate for an agentic employee.

Do the four roles a vendor deploys fastest limit what can be automated?

No. IT service desk, accounts payable, HR coordination, and marketing operations deploy fastest because the connectors and procedures already exist for them, not because the platform is scoped to those departments. A different role that passes the three-part test is a scoped connector conversation, not an automatic no.

What if our procedures are not written down yet?

Write them first. Turning how a job actually gets done into a document a new hire could follow is worthwhile even if you never automate anything, and it usually takes about a week of sitting with whoever does the job today.

Does passing the test mean the entire job gets automated?

No. It means the procedural share of the job, the part with written steps, named systems, and a clear escalation point, can be authored as a role. The judgment calls and the exceptions still route to a person, by design, regardless of how much of the role passes the test.

Find Out If Your Role Passes

Tell us the job, the systems it touches, and who owns the approvals. We will tell you honestly which tests it passes today and what closes the gap.

See Maya Workforce AI

How AI-ready is your organization?

Free 2-minute assessment. Get an industry-specific score and action plan — no call required.

Get My Readiness Score