None of the four certification outlines in this field contains the word agent in the sense used here, and none addresses what happens when one agent invokes another. The material below therefore sits beyond the published outlines, and it is marked as such wherever it appears in Fieldwork.
An agent-to-agent handoff is a routing decision rather than a grant of authority, which is why it is configured without anyone deciding that authority should change. A conversation begins with one agent and, on some condition, transfers to a second agent holding a different tool set, different instructions, and an owner who may sit in a different part of the organization. Agent platforms provide the mechanism, because splitting a large instruction set across several agents keeps each one tractable. A route is added as a configuration change rather than as a grant, so from the platform’s position nothing was given to anyone, and the change does not present as a change to any agent’s authority.
It makes the inventory wrong. Whatever was established about the first agent’s tool surface is now a subset of the truth. The effective surface is the first agent’s tools together with the second agent’s tools, and where the second can hand off to a third, the third’s as well. A register that stops at the first agent describes the entrance to a building whose floor plan has not been seen.
It moves authority outside the approval trail. The second agent was approved for its own use case, by its own stakeholders, against its own risk assessment. Placing a hold on an account is a reasonable capability for a collections agent, with a process built around it and officers trained to operate it. Reached through the first agent, that same capability becomes available inside a member-service conversation, initiated by a member, with none of the surrounding process. No forum approved the combination, because approving the second agent’s capability and configuring the route into it were separate decisions taken by separate people, and each decision was defensible on its own terms.
It breaks attribution. Logs are held per agent, so a single conversation touching three agents produces three log streams. Where those streams carry no shared correlation identifier, reconstructing what happened means joining on timestamps, and the cost of that appears at the moment an incident requires the question of which members were affected to be answered under time pressure.
A handoff configured as a routing change leaves no trace in the design documentation, because the documentation records approvals and no approval was sought. Four routes reach it, listed in descending order of how directly each evidences the deployed state.
Worth anticipating: governance, architecture, and the business owner may each state that no handoffs exist, and state it sincerely, because a route configured as a refactor never entered the record any of them maintains.
An authority register that stops at the first agent has not recorded the authority. Each entry needs the reachable agent, the condition on which the route fires, the target’s tool surface, and the approval status of the combination. The combination is the object that has been through no governance forum, and neither agent examined alone will show it.
The recommendation that follows is a control the organization does not yet hold: no route may be configured to an agent whose tool surface has not been approved for the originating agent’s use case. It is one sentence, it is enforceable at the point a route is configured, and it closes the class of condition rather than the instance.
This brief is one of ten behind Module 1, The tool surface, a free guided walkthrough of an AI agent assessment at a credit union. The same engagement can be run unassisted, with the check questions above put to you against evidence rather than against a description.
NexNith advises boards and audit committees on exactly this work. How we work