AI & Automation · Resource 11 of 15
AI Orchestration Ledger
A governance framework for the agentic enterprise — the CoS's instrument for turning AI ambition into a governed operating model.
Resource 11 · Governance
The AI Orchestration Ledger
A governance framework for the agentic enterprise.
The Chief of Staff's instrument for turning AI ambition into a governed, productive operating model. Built for the reality of 2026: widespread shadow use, rising agent autonomy, and regulation catching up fast.
The AI-Pilled CoS resource covered how a Chief of Staff becomes personally AI-fluent. This resource covers the next problem: how the organization gets there, and why the operator in the room — not the CTO, not Legal, not the CEO alone — is the one who can actually run the instrument.
Before you read further
Two audiences, one instrument, applied differently
This resource was written primarily for operators inside traditional organizations — companies that grew by hiring humans into functions and now need to govern AI activity that is already happening underneath that structure. That is the majority case in 2026, and the framework below is calibrated to it.
If you are an AI-native founder or early operator, the Register still applies — but the surfaces you are registering are different. You are not inventorying what your sales team quietly pastes into ChatGPT. You are registering the agents you are already onboarding, their role definitions, their decision boundaries, the guardrails that keep them from sending the wrong ad live at 11pm on a Friday. The ledger is the same instrument. What fills it changes.
This resource fits you if
You run the operating rhythm for a team where humans are the primary actors and AI is being added underneath. You already suspect AI use in the company is wider than leadership can see, and you need to make it visible without punishing anyone for it.
You'll get value, but adapt it if
You are building AI-native from day one. Agents are on the team before humans are. The Register is still the right instrument — the columns still matter — but your population of entries is weighted toward agent specs and guardians rather than shadow discoveries. A companion resource on the Register for agent-first companies is coming next in this series.
How this resource is organized
Why → How → What → Apply
1
Why
The gap, who owns it, and which posture your org needs now.
2
How
The governance approach before any instrument — the paved road.
3
What
The Register, discovery by company stage, and a worked example.
4
Apply
Stewards, the operating rhythm, the disclosure dividend, a 30-day start.
Phase 1 · Why
The gap, the owner, the posture
Before any instrument: name the problem, claim the role, diagnose what your org actually needs.
The Problem
Four numbers that name the gap
The gap between "leadership wants AI" and "the organization is using it safely and productively" is not a technology gap. It is a coordination gap. That is the CoS's home field.
74%
of companies plan to use agentic AI at least moderately within two years.
Only 21% have a mature governance model for autonomous agents.
Deloitte, State of AI in the Enterprise 2026
98%
of organizations report some form of unsanctioned AI use by employees.
Shadow AI adds an average of $670,000 to breach costs.
CrowdStrike 2026 Global Threat Report · IBM 2025 Cost of a Data Breach
80% / 28%
of leaders say their org is mature at basic automation. Only 28% say the same for AI agents.
The gap between automation maturity and agent maturity is the operating problem.
Deloitte 2025 Tech Value Survey, n=550
Aug 2, 2026
EU AI Act enforcement begins.
Fines up to €35M or 7% of global revenue for non-compliance.
Regulation (EU) 2024/1689
Ownership
Why the Chief of Staff owns this
Three roles are already circling this problem and none of them can solve it alone:
The CTO
Sees: Infrastructure and models.
Misses: Cannot see the workflow.
Legal & Compliance
Sees: Risk and regulation.
Misses: Cannot see the productivity loss of saying no.
The CEO
Sees: Ambition and velocity.
Misses: Cannot see what the finance team is actually pasting into ChatGPT on a Tuesday.
The CoS sees across all three. The CoS is trusted by all three. The CoS already runs the operating rhythm that turns decisions into follow-through. What follows is not a new job for the CoS. It is the job, named.
Diagnosis
Which posture does your org need now?
Before any framework or instrument, the CoS answers a single diagnostic question: what kind of governance problem does this organization actually have right now? Most companies need all three postures at once, applied to different surfaces. The CoS's job is to know which belongs where — and to start with the posture that matches the most pressing reality.
01
The Velocity Posture
The org is under-using AI. Governance risks becoming a brake.
CoS move: Remove friction. Fund sandboxes. Publish sanctioned tool lists. Celebrate use cases publicly. Make the approved path fast enough that no one bothers with a workaround.
When to use it: Early-stage adoption, specific functions lagging, new acquisitions being integrated.
02
The Visibility Posture
Use is widespread but unmanaged. You are in the 98% shadow AI reality.
CoS move: Inventory without punishment. Declare amnesty. Build the ledger. Treat disclosure as learning, not enforcement. Pair every discovered shadow use with a paved-road alternative within 30 days.
When to use it: Most mid-size and scaling organizations in 2026 are here and do not know it.
03
The Veracity Posture
Autonomous agents are acting at scale. The risk is wrong actions, fast.
CoS move: Named Stewards per agent. Incident playbooks. Periodic human audits even of out-of-the-loop systems. Separation of concerns: the agent that creates is never the agent that verifies.
When to use it: Any surface with customer impact, regulatory exposure, or financial authority.
Posture tells you where to start. The next question is how — before you pick up any tool.
Phase 2 · How
The approach, before the instrument
One philosophy sits under every governance decision that follows. Get this wrong and the instrument will not save the program.
Approach
The Paved Road Principle
Every governance decision the CoS makes flows from one philosophy: build the well-lit path, do not build walls. Prohibition drives shadow use deeper. A good sanctioned option pulls it back into the light. This principle sits under every section that follows — the Register, the operating rhythm, the thirty-day starter. If the approach is wrong, the instrument will not save the program.
Borrowed from platform engineering
Build the well-lit path
Instead of building walls around forbidden behavior, build a well-lit, well-maintained path that is genuinely easier to follow than the alternative. Prohibition drives shadow use deeper; a good sanctioned option pulls it back into the light.
01
Surface what people are actually doing
Not what the AI policy says they should be doing. Interviews and declared-use amnesty beat network scans.
02
Fund the paved version
If marketing is pasting customer data into a consumer chatbot, the answer is not a memo; it is an enterprise-sanctioned tool with the same ease of use.
03
Retire the cowpath
Close off the shadow option only after the paved one exists, not before. The sequence matters.
With the approach settled, the instrument becomes straightforward. The Register is where the paved road gets drawn.
Phase 3 · What
The Register — and how to fill it
With approach settled, the instrument becomes straightforward. The Register is where the paved road gets drawn.
The Instrument
The Register
Every AI use case in the organization belongs on one ledger, with five columns the CoS is uniquely positioned to maintain. Reviewed quarterly. Owned by the CoS. Consumed by the CEO, CTO, and Legal in three different languages.
Autonomy Position · the three values defined
The autonomy spectrum that matters
Deloitte's 2026 framing is the clearest on the market. The CoS should adopt the language and stop letting teams conflate these three.
Autonomy
Human-in-the-loop
AI drafts, human reviews and approves before anything ships.
Examples: Board briefs · offer letters · customer-facing copy · financial models.
Default for anything with external audience or legal weight.
Autonomy
Human-on-the-loop
AI acts, human monitors and can intervene.
Examples: Auto-filed meeting notes · expense categorization · inbound lead qualification.
Human is not in the critical path but is watching the dashboard.
Autonomy
Human-out-of-the-loop
AI acts and the system audits.
Examples: Anomaly detection · log triage · scheduled report generation.
Continuous monitoring replaces case-by-case review.
Most organizations in 2026 are trying to operate at out-of-the-loop speed with in-the-loop assumptions, or the reverse. The Register forces the conversation.
A blank Register is not the hard part. Filling it honestly is. How the CoS does that changes with the size of the company.
Discovery
How to populate the Register by company stage
Discovery is a judgment problem, not a scanning problem
No network-monitoring tool will surface a finance analyst pasting an earnings draft into a consumer chatbot at 9pm. The data the Register needs comes from conversations, not dashboards. But the method scales differently depending on how many conversations there are to have.
Four stages below, each with the CoS-appropriate discovery method and the tooling that makes it tractable. Claude — or the AI thought partner of your choice — is part of the method itself, not a substitute for the conversations.
Stage 01 · Seed
The hallway method
Typically under 50 people · pre-Series A
Method
Direct conversation with every functional lead. At this stage the CoS can realistically know every AI use case in the company by name.
Goal: A complete Register in one week of 20-minute conversations.
Tooling: A shared doc. No platform spend required. The CoS's real work is building the muscle of disclosure before the company grows past the point where direct visibility is possible.
Stage 02 · Series A–B
The functional audit
Typically 50–250 people · post-product-market-fit
Method
Structured interviews with function leads (Eng, Product, Sales, Marketing, Finance, People, Ops), asking each to name their team's top three AI uses. Cross-reference with a short all-hands survey.
Goal: A Register that captures ~80% of real use in two to three weeks.
Tooling: A spreadsheet or Notion database, plus an AI thought partner to synthesize interview notes into Register rows. This is where Claude starts earning its place in the workflow.
Stage 03 · Series C+
The delegated discovery
Typically 250–1,000 people · scaling globally
Method
The CoS cannot personally interview every function any longer. Instead: appoint a Function AI Liaison per department, give each a simple intake template, and run a quarterly Register rollup. Pair with procurement data (any SaaS tool with 'AI,' 'Copilot,' 'GPT,' or 'Agent' in the name or latest release note) to catch embedded AI that users may not flag.
Goal: Liaison-led intake plus procurement cross-check.
Tooling: Shared Register in a governance platform or purpose-built Notion template; AI thought partner for rollup synthesis; procurement/SaaS management data as a cross-check.
Stage 04 · Public or PE-owned
The governance platform
Typically 1,000+ people · regulated or sponsor-scrutinized
Method
At this scale, the Register becomes a governed asset with auditable history, role-based access, and integration to existing risk and procurement systems. Discovery combines Liaison-led intake, automated AI-tool discovery (CASB, SaaS management platforms), and periodic third-party assessments.
Goal: The CoS's role shifts from discovery to orchestration across named deputies.
Tooling: Dedicated AI governance platform (Credo AI, Enzai, Holistic AI, or equivalent); integration with existing GRC stack; quarterly attestation from each Function AI Liaison.
AI-Assisted Discovery
Two prompts that make Claude a real discovery partner
At Stages 2 through 4, the CoS is synthesizing more interview notes than any human should process manually. A dedicated AI thought partner — set up as a Claude Project, ChatGPT custom GPT, or equivalent — turns raw notes into Register rows in minutes. Below are two prompts the CoS can use immediately. Adapt freely.
Prompt
You are acting as my Chief of Staff thought partner for AI governance. I am going to paste notes from an interview with [FUNCTION LEAD NAME, ROLE]. Extract every distinct AI use case mentioned or implied, and for each one produce a draft Register row with these five columns: Surface, Sanction State, Autonomy Position, Blast Radius, Steward. Where information is missing, flag it as "needs follow-up" rather than guessing. Keep each row under 40 words per cell. Here are the notes: [PASTE].Prompt
Here is our current Register of AI use cases across the company [paste the table]. Act as a governance analyst and tell me: (1) which rows are most likely to expose us to the EU AI Act as high-risk, (2) which rows have a mismatched Autonomy Position given their Blast Radius, (3) which rows are missing a named Steward and should not stay that way. Rank each finding by how urgent it is to resolve this quarter, and explain your reasoning in one sentence per row.These prompts assume the CoS has set up a dedicated Claude Project with organizational context loaded — org chart, function names, known AI vendors. Without that context, the quality of the synthesis drops materially. Resource 9 in this series covers the setup.
An instrument and a discovery method are still abstract until they meet a real company. The rest is applied.
Phase 4 · Apply
Working example, accountability, rhythm, starter
An instrument and a method are still abstract until they meet a real company. The rest of this resource is applied.
Worked Example
TrackFlow — the Register on a real company
Worked Example · TrackFlow
What the Register looks like on a real company
Returning to TrackFlow, the fictional B2B SaaS company from the P&L Field Guide. ARR sits at $19M with growth decelerating for eight consecutive quarters. Gross margin has dropped from 71% to 63%. Equity remaining is $2.1M, down from $11.4M. A funding conversation is coming, and it will not be the easy kind.
This is the environment in which AI governance stops being theoretical. Every use case below either helps the next board meeting go better, or makes it worse. The Register is how the CoS makes that distinction legible.
Surface
Board narrative drafting
Sanction
Approved
Autonomy
Human-in-the-loop
Blast Radius
Brand & investors
Steward
CoS
Surface
Sales forecast modeling
Sanction
Shadow
Autonomy
Human-on-the-loop
Blast Radius
Regulators (revenue recognition)
Steward
CRO (proposed)
Surface
Customer support triage
Sanction
Sandboxed
Autonomy
Human-out-of-the-loop
Blast Radius
Customers
Steward
VP Customer Success
Surface
Candidate screening in ATS
Sanction
Shadow
Autonomy
Human-on-the-loop
Blast Radius
Regulators (EU AI Act, high-risk)
Steward
Head of People (proposed)
Surface
Investor update copy
Sanction
Shadow
Autonomy
Human-in-the-loop
Blast Radius
Investors & brand
Steward
CEO (via CoS)
Reading the Register
What five rows tell the CoS in under a minute
Three of five rows are Shadow.
This is not a TrackFlow failing. It is the 2026 baseline. The Register's job is not to shame the company into existence; it is to name reality so the next decision is informed. At 82% equity collapse, the CoS does not have the option of pretending the finance team is not already using AI to stretch the runway.
The ATS row is the most dangerous on the page.
Candidate screening is explicitly classified as high-risk under the EU AI Act. Shadow use on this surface with a funding round approaching means a diligence finding waiting to happen. This row moves to Sandboxed this week, Approved within the quarter, or it disappears.
The sales forecast row is the most consequential for the next board meeting.
If revenue recognition is being influenced by an ungoverned model, the CFO needs to know before the auditors do. The CoS brings this to the CFO before the QOR, not during it.
The investor update row is the most quietly damaging.
Investor communications drafted by AI without a named Steward is how a well-meaning CEO ends up defending a claim they never actually made. The Register forces the name.
Accountability
The Steward model
Every AI use case on the Register has a named human Steward. The Steward is not the engineer who built it or the vendor who sells it. The Steward is the business owner of the outcome.
This is governance as role clarity, which is why it slots directly into the Decision Frameworks resource. In DACI terms, the Steward is the Approver. In RAPID terms, the Steward Decides. The engineer Recommends. The CTO is Consulted on technical risk. The CEO is Informed on strategic exposure. Legal is Consulted on regulatory exposure.
When an agent misfires, the question is not "whose system broke?" It is "whose judgment was this supposed to extend?" The Steward answers.
Operating Rhythm
The Quarterly Orchestration Review
An operating ritual the CoS runs alongside the QBR. Not a separate meeting — a standing section of the existing executive operating rhythm.
One page per Surface
Four questions
- 1.What is running today? (Sanctioned, Sandboxed, and known Shadow uses.)
- 2.What changed this quarter? (New uses, retired uses, autonomy shifts.)
- 3.What broke? (Near-misses count. Silence is a finding, not an absence of one.)
- 4.What is next? (Proposed changes to autonomy position, stewards, or sanction state.)
Read three ways
Classic CoS translation work
CEO
Strategic velocity and leverage
"Where is AI actually producing output we couldn't get before?"
CTO
Technical risk and architecture debt
"Where are we accumulating agent sprawl we'll regret?"
Legal / Compliance
Regulatory exposure
"What on this ledger would we struggle to defend to an EU AI Act auditor?"
The Soft Skills Are the Mechanism
The Disclosure Dividend
You cannot orchestrate what you cannot see
Why honesty is the governance instrument
The hardest part of the Register is not building it. It is filling it honestly.
Employees disclose AI use when disclosure is treated as learning. They hide it when disclosure is treated as enforcement. The governance literature is consistent: prohibition-first approaches produce less visibility and more risk, not less risk. A paved-road approach with transparent declaration reveals far more than any network scan.
This is where the soft skills of a Chief of Staff become the actual governance mechanism, not adjacent to it. Trust, discretion, follow-through, the ability to surface uncomfortable information without punishing the messenger — these are not nice-to-haves that make the Register easier to build. They are what make the Register possible at all.
You cannot orchestrate what you cannot see. You cannot see what people are afraid to show you.
Get Started
The thirty-day starter
If you are reading this as a sitting CoS without an AI governance program, here is the minimum viable version. It does not require budget or headcount. It requires a calendar and a willingness to ask.
01
Week 1
Declare amnesty
A short CEO-signed note: "We want to know what AI tools you are using. No tool will be banned in the next 30 days as a result of disclosure. We are building a better version." Open a simple intake form.
02
Week 2
Interview the heaviest users
The marketing ops person, the sales engineer, the FP&A analyst, one engineer, one recruiter. Ask what they use, why, and what a sanctioned version would need to do to be worth switching.
03
Week 3
Build the first Register
Five columns, one row per discovered use case. Assign a proposed Steward for each. Leave the Autonomy Position blank for now if you need to.
04
Week 4
Present to the Triad
CEO, CTO, and you. One decision per row: Approve, Sandbox, or Retire-with-replacement. Assign the replacement work. Schedule the first QOR.
Why no agent replaces this role
The AI-Pilled CoS resource made the case that no AI agent can replace a human Chief of Staff. The Orchestration Ledger is the sharpest proof.
An agent cannot hold an amnesty conversation with a nervous team lead. An agent cannot read the room when the CTO and Legal disagree on autonomy position. An agent cannot decide that this quarter, the org needs velocity more than visibility, or the reverse. An agent cannot be the named Steward — by definition.
The governance of AI is a deeply human problem dressed in technical clothing. That is exactly the kind of problem a Chief of Staff is built to hold.
Key research cited
- Deloitte 2026 State of AI in the Enterprise — 74% planning agentic AI, 21% with mature governance; in/on/out-of-the-loop framing.
- Deloitte 2025 Tech Value Survey — 80% automation maturity vs 28% agent maturity across 550 US leaders.
- CrowdStrike 2026 Global Threat Report — 98% of organizations report unsanctioned AI use.
- IBM 2025 Cost of a Data Breach Report — shadow AI adds avg $670,000 to breach costs; 63% of breached orgs had no AI governance policy.
- McKinsey State of AI 2025 — 88% of organizations use AI in at least one business function; redesigning workflows is the top success factor.
- Gartner / Forrester 2026 — >40% of agentic AI initiatives at risk of abandonment by 2027 due to governance and ROI fundamentals.
- EU AI Act (Regulation 2024/1689) — enforcement begins 2 August 2026.