Operations
If the Agent Can't Reach the Work, Training Is Theater
Workshops do not fix an agent that cannot see the inbox, the folder, or the system where the work actually lives.
Most companies still treat AI adoption as a people problem. They buy a workshop. They circulate prompt templates. They ask the staff to “get more comfortable with the tools.” Then they wonder why nothing moves except the calendar.
The first failure is usually not aptitude. It is access.
If the agent cannot reach the files, mail, calendar, ticket queue, or line-of-business system the job lives in, no amount of training will produce a better week. The operator will keep copying and pasting. The model will keep answering from a corner of the work. The company will keep calling that “AI strategy.”
That is theater.
Access is a job design question, not a personality trait
A useful agent is not a smarter intern sitting next to someone who already knows the business. It is a worker that can get to the same material a competent human would open to finish the job.
Ask the blunt questions:
- What is the named job?
- Where does that job actually live?
- Can the agent reach that place under a permission the business already understands?
- Who can halt it when it reaches the wrong window?
If those answers are fuzzy, training is premature. You are teaching people to talk to a system that cannot see the work.
This is why some roles appear to “take off” with AI while neighboring roles stall. It is rarely because one group is more technical. Coding moved first because the work already lived in local, inspectable files. Legal moved when the documents were actually in reach. Finance moved later, when connectors and computer-use finally made the ledgers, portals, and exception piles reachable at usable speed. The tipping point was context availability, not IQ.
If your team cannot point to the system the job lives in, you do not have an adoption gap. You have an unfinished job map.
Whose computer is it?
Access has a second face, and it is easy to miss because it looks like progress.
An unattended cursor moving across windows the operator is no longer tracking is not a productivity win. It is a transfer of the machine. Voice in one ear, a live desktop in the other, and no named job, allowed surface, or halt owner means the vendor already has the computer. The human is narrating from the hallway.
Small businesses feel this faster than enterprises, because there is often one laptop, one inbox, and one person who “just knows where things are.” Hand that machine to an agent without a fence and you have not automated the company. You have rented the office.
The test is simple. If you cannot say which windows the agent may touch, which records it may read, and who stops it, you are not running a worker. You are hoping the software stays polite.
Hope is not an access policy.
A silent switch from connector to clicking is a control failure
The modern stack makes this worse by hiding the moment control is lost.
A connector that can read a mailbox, a folder, or a record system is usually the right tool: bounded, inspectable, cheaper in tokens, easier to permission. Computer-use — the agent looking at a screen and clicking — is the escape hatch for work that will never get a clean interface. Government forms. Vendor portals. The one screen nobody will API.
Both can be legitimate. The failure is the silent failover.
If the connector misses, and the agent starts clicking without anyone seeing the change, you no longer know whose computer it is. You also no longer know what was read, what was submitted, or whether the job is still the job you named. Calling that “interesting” is how control dies in public.
For a shop that actually has to live with the outcome, the rule is operational:
- Named job.
- Named system.
- Preferred path: a permissioned connector when one exists.
- Clicking only when the work has no other door, on an allowed surface, with a halt owner in the room or on the hook.
- A visible log when the path changes.
If the path can change and nobody can see it, you do not have an agent. You have an unsupervised intern with your mouse.
Team lift is a shared artifact, not a workshop
The other half of the theater is how companies try to spread the win.
They schedule training. They record a lunch-and-learn. They tell power users to “show the rest of the team.” Then they are surprised when the room nods and Monday looks the same.
People do not learn a new way of working from a slide. They learn it when a repeated team job becomes an inspectable artifact someone else can use: a packed brief, a checked exception list, a status that already names what is done and what is blocked. The power user did not become a trainer. They turned one real job into something the team can pick up.
That is the company version of access. Not “everyone got the same prompt class.” One job, reachable, visible, reusable.
If the only person who can run the agent is the person who sat through the demo, you did not adopt AI. You added a hobby to one laptop.
Do the access audit before you buy the class
Before the next workshop, run a one-page audit on a single job. Keep it boring.
- Name the job in one sentence, including what “done” looks like.
- Name the systems it must touch. Inbox, folder, calendar, line-of-business screen — write them down.
- Mark each system: reachable with a current permission, reachable only by copying, or not reachable at all.
- Name the halt owner. If nobody can stop it, it does not run unattended.
- Decide the path: connector, human, or supervised clicking on an allowed surface. No silent third option.
- Require one shared artifact the rest of the team can inspect. If the output cannot be handed across the counter, the job is still private.
Until that page exists, training spend is a costume. It makes the company look serious while the work remains out of reach.
The market will keep selling aptitude: better prompts, better models, better classes. Those things matter after the agent can get to the job. They do not create access. They do not decide whose computer it is. They do not turn a silent click-failover into a controlled path.
If the agent cannot reach the work, stop teaching the staff to perform around it. Fix the door. Then train.