Test it against three questions. Can the procedural share of the job be written down as steps a new hire could follow. Are the systems it touches specific and named, not a vague description of "the tools I use." And is there a person who owns the sign-off on anything that moves money, grants access, or cannot be undone. Pass all three and the role is a real candidate for an agentic employee. Fail any one of them and it is not, at least not yet.
Gartner predicted in August 2025 that 40 percent of enterprise applications would ship a task-specific AI agent by the end of 2026, up from under 5 percent the year before. That number tells you the market is moving fast. It tells you nothing about whether the role on your desk right now should move first. The three-part test answers that, and it has nothing to do with department or title.
The test checks for the three things a role manifest needs: written procedures, named systems, and a sign-off line. A manifest is the file that defines an agentic employee's job: the job description, the tools it may call and the risk class of each, the procedures, the escalation rules, and the failure policy. Missing any one of the three means there is nothing to write into a manifest yet, and the honest next step is closing that gap before evaluating vendors.
This is where most role evaluations quietly fail before they start. "We know how to do this" and "this is written down" are different claims. The first lives in a person's head and comes out differently depending on their mood. The second is a document a new hire could follow without asking a question.
A procedure that says "always verify the requester before a reset" is written down. A note that says "use judgment on vendor exceptions" is not, no matter how confident the person who wrote it feels. The fix is not automation software. It is a week of someone sitting with whoever does the job today and turning what they actually do into steps.
If the procedures are not written yet, write them first.
A role that "touches a bunch of internal tools" fails this test. A role that touches your ERP, your HRIS, or your ticketing system by name passes it, because each of those can be granted a scoped credential, logged, and revoked. Vague systems produce vague scope, and vague scope is what a security reviewer rejects on sight.
A system that is already supported is configuration. A new system of record is a scoped connector build with its own timeline and its own cost, and a vendor worth working with will tell you which one your system is before you sign anything, not after.
The constraint is almost never the department. It is whether the systems in question already have a supported connector. IT service desk work against ServiceNow and Entra ID passes this test today because that connector already exists. A role against a system nobody has built a connector for does not fail forever, but it fails this quarter.
Every vendor claims there is a human in the loop. The test is whether the sign-off line names an actual person, and whether that person's "no" resolves cleanly instead of triggering a retry loop that quietly asks again later.
A role with no natural approval point is not disqualified. It usually means the sign-off has never been made explicit, because one person was doing the whole job and approving their own work by default. Naming the approver tends to surface who actually owns the role's risk, which is worth knowing on its own.
IT service desk, accounts payable, HR coordination, and marketing operations deploy fastest on Maya Workforce AI today, because the connectors and procedure patterns already exist for those roles. That is a statement about which systems are already wired, not where the platform stops. Claims intake, order management, dispatch, and scheduling pass the same test on paper. Whether they pass it in your organization depends on how concrete your own procedures and systems are.
| Role | Written procedures | Named systems | Sign-off line | Passes the test |
|---|---|---|---|---|
| IT service desk technician | Yes, resets and provisioning are already scripted | Yes, ServiceNow, Entra ID | Yes, any access grant | Passes |
| Accounts payable clerk | Usually, PO-matching rules are already documented | Yes, the ERP and vendor master | Yes, every payment | Passes |
| Claims intake coordinator | Often, intake checklists exist | Yes, the claims system | Yes, above a dollar threshold | Passes, if written down |
| Brand strategist | No, judgment calls without a repeatable procedure | Partial, many tools loosely | Unclear, no single money moment | Fails on procedures |
The table is not a verdict on any job's value. It is a verdict on what part of that job can be handed to a manifest today.
The three-part test was built for a department head deciding whether to automate a role, but it happens to answer most of what a security reviewer asks separately. Named systems turn a credential grant into something that can be scoped and audited. A real sign-off line turns "human in the loop" from a slide into a control. Gartner's November 2025 forecast projects that more than 40 percent of enterprises will have a security or compliance incident tied to unauthorized shadow AI by 2030. Roles that pass the three-part test are the ones least likely to land in that statistic, because the systems and the approvals got named before anything was deployed. If you are the one who signs off on giving an agent credentials, the questions to ask any AI agent vendor before you hand it credentials go one level deeper, into what happens when a token expires mid-task or a webhook fires twice.
A role that fails today is a to-do list, not a permanent no.
It checks for written procedures a new hire could follow, systems specific enough to name and grant a scoped credential against, and a named person who owns sign-off on money, access, and anything irreversible in that role. All three have to be true for the role to be a real candidate for an agentic employee.
No. IT service desk, accounts payable, HR coordination, and marketing operations deploy fastest because the connectors and procedures already exist for them, not because the platform is scoped to those departments. A different role that passes the three-part test is a scoped connector conversation, not an automatic no.
Write them first. Turning how a job actually gets done into a document a new hire could follow is worthwhile even if you never automate anything, and it usually takes about a week of sitting with whoever does the job today.
No. It means the procedural share of the job, the part with written steps, named systems, and a clear escalation point, can be authored as a role. The judgment calls and the exceptions still route to a person, by design, regardless of how much of the role passes the test.
Tell us the job, the systems it touches, and who owns the approvals. We will tell you honestly which tests it passes today and what closes the gap.
See Maya Workforce AIFree 2-minute assessment. Get an industry-specific score and action plan — no call required.