預約諮詢
專題深挖

企業級 Agent 治理:當你給 AI 開權限,其實是在寫它的職位說明書Governing enterprise agents: granting access is really writing a job description

Published 2026-09-25Author 蘇仲成 Michael C.S. SoAiX 環球 AI 情報
本文由 2026 年 9 月多條情報綜合而成:七成組織授予智能體超出同等人類員工的權限、八成已見過智能體越界、六成企業視數據權限為跨系統執行的首要障礙;同期「智能體身份管理」國家標準化指導性技術文件正式立項,Andreessen 級別的 KYA 概念開始進入監管語言。這一切指向同一個管理空洞:企業為 Agent 開權限時,用的是「方便」而不是「職責」的邏輯。Synthesised from several September 2026 briefings: 70% of organisations grant agents more access than an equivalent human employee, 80% have already seen an agent act beyond its intended scope, and 62% name data permissions as the primary obstacle to cross-system execution. In the same period a national standardisation guidance document on agent identity management was formally filed. All of it points to one management gap: agents are granted access on the logic of convenience rather than responsibility.

問題不在模型,在權限表The problem is not the model, it is the access table

企業過去兩年把大部分注意力放在模型能力上:哪一個更聰明、哪一個更便宜。但當 Agent 由「回答問題」變成「執行操作」,風險的性質就完全改變了。一個答錯問題的聊天機械人只會浪費你幾分鐘;一個拿錯權限的 Agent 可以改動、寄出、刪除。For two years enterprises have focused on model capability: which one is smarter, which one is cheaper. But once an agent moves from answering questions to executing operations, the nature of the risk changes completely. A chatbot that answers wrongly wastes a few minutes. An agent holding the wrong permissions can edit, send and delete.

人類員工入職時要簽權限表、要分級授權、要有人做他的主管。Agent 往往一次拿到全部,而且沒有人記得當初為什麼要開這麼多。這不是技術問題,是管理問題——而且是很容易補救的一種。A human employee signs an access schedule on joining, receives tiered permissions, and has a manager who answers for them. An agent often receives everything at once, and nobody remembers why so much was granted. This is not a technical problem. It is a management problem — and the easier kind to fix.

數字說了什麼What the numbers say

2026 年 9 月 22 日深圳一場產業智能體大會披露的三個數字,值得管理層記住:70% 的組織授予智能體超出同等人類員工的權限;80% 的組織已經報告智能體執行了超出預期範圍的行為;62% 的企業把數據權限與安全合規列為智能體跨系統執行的首要障礙。Three figures disclosed at an industry agent conference in Shenzhen on 22 September 2026 are worth management's memory: 70% of organisations grant agents more access than an equivalent human employee; 80% have already seen an agent act beyond its intended scope; and 62% name data permissions and compliance as the primary obstacle to cross-system execution.

前兩個數字是風險,第三個數字是成本。也就是說,權限管理做得鬆,企業同時承受了更高的風險與更低的落地效率——這是一個沒有 trade-off 的局面,值得優先處理。The first two are risk; the third is cost. Loose permission management therefore buys you higher risk and lower deployment efficiency at the same time. There is no trade-off here, which is exactly why it deserves priority.

為什麼會走到這一步How we got here

原因很平凡:Agent 的權限是在試用階段開的。試用時為了讓它「跑得通」,工程師會直接給它最大範圍的憑證——反正只是測試。項目通過之後,沒有人回頭把範圍收窄,因為那時它已經在生產環境工作,收窄意味著可能弄壞正在運作的流程。The cause is mundane: agent permissions are created during the trial. To make the pilot work, an engineer hands over the broadest credentials available — it is only a test, after all. Once the project is approved nobody narrows the scope, because by then it is running in production and narrowing risks breaking something.

於是「臨時的最高權限」變成永久設定。這與人類員工的情況剛好相反:人類是入職時窄、表現好才放寬;Agent 是入職時寬、之後没有人收紧。So a temporary maximum becomes a permanent setting. This is the mirror image of how human access is handled: a person starts narrow and is widened on performance; an agent starts wide and is never tightened.

KYA:由「認識你的客戶」到「認識你的 Agent」KYA: from Know Your Customer to Know Your Agent

2026 年 9 月 10 日,由螞蟻數科與中國電子技術標準化研究院等機構推動的《區塊鏈和分布式記帳技術 智能體身份管理要求》國家標準化指導性技術文件正式立項。業界把這條路線概括為 KYA(Know Your Agent),並視之為繼 KYC(認識你的客戶)、KYP(認識你的產品)之後的新底層要求。On 10 September 2026 a national standardisation guidance document on agent identity management, advanced by Ant Group's technology arm with the China Electronics Standardization Institute and others, was formally filed. Industry shorthand for this direction is KYA — Know Your Agent — positioned as the next foundational requirement after KYC and KYP.

這一步的意義不在技術規格,而在定位:當一個執行者需要身份、需要被記錄、需要有人問責,它在制度上就已經是「準員工」。企業的管理制度——入職、權限、覆核、離職——都需要為它開一個新的章節。The significance is not in the technical specification but in the positioning. Once an actor needs an identity, a record and someone to answer for it, it is institutionally a quasi-employee. Onboarding, permissions, review and offboarding all need a new chapter written for it.

兩條監管路線正在匯合Two regulatory tracks are converging

中國這一邊走的是身份與標準:先立標準,再要求平台提供治理能力。歐盟那一邊走的是透明度與問責:第 50 條透明度義務已可執行,首輪檢查聚焦自動履歷篩選這一類「用 AI 做決定」的工具。China's track is identity and standards: set the standard first, then require platforms to provide governance capability. The EU's track is transparency and accountability: Article 50 transparency duties are already enforceable, with the first inspections focused on exactly the kind of decision-making tools — automated résumé screening — that HR teams deploy.

表面看是兩套制度,實際上要求的是同一件事:當一個決定由 AI 作出,企業必須能說出它是誰、依據什麼、由誰負責。差別只在切入點——一邊從技術標準,一邊從使用者告知。They look like two regimes but ask for the same thing: when a decision is made by AI, the enterprise must be able to say who made it, on what basis, and who is accountable. Only the entry point differs — technical standard on one side, user disclosure on the other.

一個明天就可以開始的做法:Agent 身份檔案四欄Something you can start tomorrow: a four-column agent register

不需要買工具,也不需要等標準。開一張表,四欄:一、它是誰(名稱與用途);二、它屬於哪個部門、由誰負責(必須是一個人的名字);三、它可以存取的資料與系統範圍;四、它被停用的條件。You do not need to buy a tool or wait for the standard. Open a table with four columns: who it is (name and purpose); which department it belongs to and who is accountable — and that must be a person's name; what data and systems it can reach; and the condition under which it is switched off.

把公司現在所有在跑的 Agent 填進去——包括自動化流程、機械人帳號、被遺忘的 API 金鑰。任何一行填不出「負責人」,就先停用。這張表日後就是合規問卷、審計、以及新增 Agent 的審批底稿。Fill it in for every agent currently running — automated flows, bot accounts, forgotten API keys included. If a row has no accountable person, switch that agent off first. The table later becomes your compliance questionnaire, your audit trail, and your approval record for new agents.

我們在客戶項目中反覆見到同一件事:做完這張表之後,多數公司會發現自己比想像中多跑了幾隻 Agent,也發現其中一兩隻的權限大得沒有理由。這兩項發現本身,已經值回做表的時間。We see the same thing repeatedly in client work: after completing this table, most companies discover they are running more agents than they thought, and that one or two of them hold permissions nobody can justify. Those two findings alone repay the time.

重點結論

  1. 把「Agent 權限」當作人事問題處理,而不是技術設定問題。Treat agent permissions as an HR matter, not a technical setting.
  2. 每一隻在跑的 Agent 必須有一位具名負責人;填不出名字的,先停用。Every running agent needs one named accountable person. No name, no licence to run.
  3. 權限收窄要在項目通過時同步做,不要留到「下次整理」。Narrow permissions when the project is approved, not in some future tidy-up.
  4. 這張表同時是歐盟透明度問卷與內地標準化要求的共用底稿。The same register doubles as the basis for EU transparency questionnaires and Chinese standardisation requirements.

本期相關情報

資料來源

相關服務

訂閱每週電子報

每週一封:AI 轉型的實戰觀察、工具實測與案例拆解。

每週一封 · 可隨時取消 · 私隱聲明