Agent Authority · The WTF Index
How WTF is your AI rollout, really?
Ten questions, two minutes. One point for every yes.
Question 1: You can’t list every AI agent running in your environment today.
Question 2: Some agents run on shared service accounts or long-lived API keys.
Question 3: At least one agent has admin rights “just for now.”
Question 4: Developers can install MCP servers or AI tools without a review.
Question 5: Agent credentials outlive the agents that used them.
Question 6: You can’t say which person authorized a specific agent action.
Question 7: Your controls for agents are MFA and session timeouts.
Question 8: Access is reviewed quarterly, but agents act every second.
Question 9: Nobody can tie AI or inference spend back to who approved it.
Question 10: If the board asked what your agents did last quarter, you’d answer with logs, not evidence.
Your score
Answer the questions to get your score.
- 0 to 2Mildly Concerned
- 3 to 5Raised Eyebrow
- 6 to 8Visible Sweating
- 9 to 10Full WTF