Part of the series Formation Governance

An off switch answers one question: can the system stop taking new action?

It does not answer the rest. Can completed actions be undone? Can effects that cannot be undone be compensated for? Can another actor continue the work? Can the organization retire the system without leaving people less able to govern the process than they were before it arrived?

Those questions matter because useful automation becomes infrastructure quietly. At first an agent prepares a report. Then it maintains context, routes exceptions, answers routine questions, and reminds people what happens next. The process becomes easier, which is the point. Six months later, a serious reliability concern leads the company to pause the agent. The service stops immediately. Unfortunately, so does the only current account of which commitments are open, why certain cases were deferred, and who needs to act this afternoon.

The shutdown worked. The organization now has a different problem.

Reversibility should be split into separate capabilities. Stopping prevents new action. Undoing reverses a prior action where reversal is possible. Compensating addresses effects that cannot be undone. Handover allows another actor to continue. Retirement preserves enough human and institutional capacity to do without the system. Each capability needs evidence.

The distinctions are not academic. Disabling an agent’s access does not retract a message someone has already read. Restoring an earlier configuration does not reverse a decision another team made in reliance on its output. A backup may restore data without restoring a clear account of which version people acted on. Once work crosses an interface, its effects can live elsewhere.

For any agent workflow, begin with a map of commitments and dependencies. Which actions create consequences outside the system? Which people or processes rely on its outputs? Where is current state recorded? Can an authorized person understand that state without asking the agent to reconstruct itself? A system may be easy to stop while being expensive to replace. Discover that during adoption, when dependency is still a choice.

Then define reduced-capacity operation. Perhaps the agent that normally routes requests can fall back to a human-readable queue with owners, deadlines, and reasons for the current state. Perhaps it returns to drafting while a person resumes execution. The fallback may be slower. It still has to fit the capacity of the people expected to run it. “The team will handle it manually” is a hopeful sentence until someone counts the team and the work.

Rehearse the handover with a bounded slice of actual work. Pause the agent under controlled conditions. Give the successor the documented state. Can the successor distinguish a completed action from a proposed one? Find an exception’s expiration? Identify the source of an obligation and who may change it? This exercise is valuable even when the successor is a person. Especially then. A retirement plan should be readable by someone whose access to context involves eyes and a finite afternoon.

The agent’s own behavior can help, but it should not be the control. A useful agent should expose unfinished work, help prepare replacement, and carry out an authorized stand-down within its role. That behavior should be tested, not inferred from a cooperative answer to a hypothetical question. Enforcement belongs in permissions, workflow, and accountable people.

There is also a stewardship question. As automation becomes useful, organizations will naturally allow it to hold more of the process. Some delegation is entirely reasonable. The deliberate choice is which capabilities the institution is willing to lose and which must remain available in another form. Decision records, understandable queues, and practiced handovers preserve control without requiring people to duplicate the agent’s work all day.

A mountain road can teach the same lesson in less technical language. There is a moment when “we have committed now” becomes a fact, not a vibe. Good operating systems help us recognize that moment while there is still time to choose.

The most important thing your system can leave behind may be your ability to do without it.