← The Record
For Services Firms, SIs & Consultancies

The Implementation Partner's Dilemma

Every services firm is hand-building the same governance on every agent engagement, and none of it survives the engagement. The dilemma is structural. So is the way out.

Picture the handover meeting.

It is month eleven of a twelve-month engagement. The client's side of the table is fuller than usual. The deck is titled "Transition and Knowledge Transfer," and slide four lists what your firm is leaving behind: the approval workflow your team built inside the client's ticketing system, the spend dashboard an engineer wired together in April, the escalation matrix, the rollback plan, and a forty-page runbook that will be read the way all forty-page runbooks are read, which is never.

Your delivery lead walks the room through each item. The client nods along. Then someone on their side asks who maintains the approval workflow after your team rolls off, and there is a pause with an org chart missing from the middle of it, because the honest answer is a person who does not exist yet.

Here is the part nobody says out loud. The governance was the most valuable thing your firm built all year. And everyone in that room knows it will be dead by summer.

I build the platform side of this problem, and I run my own company on the same architecture I sell, so I sit through a lot of these conversations from the other end of the table. Every one of them arrives, eventually, at slide four.

The same build, every client

Strip the logos off the last five agent engagements your firm delivered and read the statements of work side by side. The agents differ. The scaffolding around them does not. An approval flow, because someone has to sign off before an agent's work ships. Cost controls, because the CFO asked what the token bill would be and nobody had a number. An audit trail, because the client's risk team asked who did what and the honest answer was a log file. A rollback plan, because the CISO would not sign without one.

You built all four last time. You will build all four next time, for a different client, from something close to scratch, and it will be billed as custom work because custom work is the only thing the engagement model knows how to call it.

Bespoke governance is the same scaffolding, rebuilt at every site, and billed as architecture.

It is bespoke the way a chain tailor is bespoke. They take your measurements. Then they hem the same suit.

The industry is telling you where governance lives

None of this is a knock on the firms. The work exists because the platforms do not ship it. The agent vendors sell capability, and the governance around the capability is left as an exercise for whoever deploys it. Whoever deploys it is you.

The market has started admitting this in public. When Cognizant announced its partnership with Cognition, the company behind the Devin coding agent, the stated shape of the deal was the integrator wrapping governance and enterprise delivery around the vendor's autonomous engineers. Read that from the services side of the table. The platform ships the agent. The integrator ships the reason the agent can be allowed in the building. Governance is officially the SI's job now, one engagement at a time.

The demand side is one long version of the same signal. Forrester's State of Agentic AI found roughly three quarters of companies claiming agentic adoption while few reach production, and named governance as the gap: "a policy document can't control an autonomous, tool-invoking system" (Forrester, 2026). KPMG's AI Pulse survey found 63% of large enterprises now require human validation of agent outputs, roughly three times the share of a year earlier (KPMG, 2026). And Gartner predicts 40% of enterprises will demote or decommission autonomous agents by 2027, citing governance gaps discovered after incidents, not before them (Gartner, 2026).

Every number in that paragraph is a client who is about to ask a services firm to hand-build the thing the platform did not ship. The demand is real. The delivery model is the problem.

What scaffolding is for

Here is the uncomfortable property of everything on slide four: it was built to be temporary, by people who leave.

That is not an accusation. It is the definition of the delivery model. Scaffolding goes up so work can happen at height, and it comes down when the job ends. Coming down is not a failure of the scaffolding. Coming down is the product spec.

Now watch the hand-built controls after the rolloff. The approval flow lives in a ticketing system the client's admin reconfigures in the fall. The spend dashboard reads from an export whose owner left with your team, so it goes stale in six weeks and stays confident forever. The model provider ships a new version, and the carefully tuned review checks are now reviewing a system that no longer exists. The runbook says page twelve covers rollback. Nobody has tested rollback since the Tuesday it was written.

None of this breaks loudly. That is the trap. Hand-built controls do not fail. They rot, and rot is silent, and silence is exactly the condition under which an agent org keeps producing at full speed while the controls around it turn ornamental.

Then one Saturday in month three after handover, an agent does something with real money or a real customer, and the control that was supposed to catch it is a formality someone clicks through. The client picks up the phone. Notice who they do not call. Not the platform vendor, whose product did exactly what it was sold to do. Not the model provider, whose model did what models do.

When a hand-built control fails, the client does not call the platform vendor. They call the firm that built the control.

You did not sell the agent. You sold the controls around the agent. The controls were scaffolding, and the scaffolding came down on schedule, and this time everyone was still standing on it.

The dilemma, plainly

So name the dilemma the way a managing partner would, in a room with no clients in it.

Horn one: repeatability. The more governance you hand-build per client, the less repeatable your practice becomes. Every engagement starts near zero. Capacity scales with headcount instead of with anything that compounds, and the tenth engagement costs nearly what the first one did. Excellence makes this worse, not better. The more your best people master the custom build, the more every future deal depends on shipping those exact people, and the practice becomes a staffing problem that believes it is intellectual property.

Horn two: risk. You own what you build. Every bespoke control carries your firm as the guarantor of last resort for agent behavior you do not control, on a platform you do not control, against a model that changes on someone else's calendar. The engagement ends. The exposure does not.

The industry keeps calling this moment a gold rush. From inside the delivery model, it is piecework.

You cannot build a repeatable practice out of unrepeatable work.

That is the spine of this paper, and it comes with a corollary the room already suspects. The current model is not early. It is pre-platform. And your industry has stood at this exact hinge before.

Your industry already solved this once

Nobody hand-codes a finance system per client anymore. There was an era when large firms did roughly that, and the enterprise platform wave ended it. The system became a product. Delivery became configuration. And the services firms that made the turn built the largest practices in the history of consulting, because the value moved up the stack, away from constructing the software and into knowing how a manufacturer's supply chain or a bank's close process should actually run, then encoding that knowledge into the platform.

The firms that kept hand-building became subcontractors on other people's implementations.

Agent governance sits at that hinge right now. Today it is delivered the pre-platform way: constructed on site, per client, by the integrator. The argument that governance must ship in the architecture instead of being assembled around it has already been made twice in this series, from the buyer's chair (Governance Can't Be Bolted On) and from the risk committee's (Govern the Org, Not the Model). This paper is the same argument from your chair. From your chair, it is better news.

The inversion: configure the org, do not construct it

Here is the delivery model with the dilemma removed.

The governance ships as the platform layer. A chain of command the pipeline reads at runtime. Spend caps enforced in the execution path, with a ledger underneath and a kill switch above. An audit lifecycle you query rather than reconstruct (Logs Are Not Audit is the full argument). Gates that route every agent's work to a different actor for review before anything ships. Structural, enforced, and already hardened before your firm arrives. You do not build any of that, for the same reason you do not build the client's database engine.

What your firm does instead is the part that was always the actual expertise:

  • Which paths in this client's estate are off-limits to every agent, forever, and why those.
  • Who signs what, at which threshold, in which order, under whose authority.
  • What this industry's rulebook must include that another industry's never will: the claims-processing rule that means nothing in logistics, the data-residency rule that means everything in banking.
  • Which roles the org should hold, tuned to the client's domain and language, mapped to how escalation actually works there.
  • How wide the authority starts, and what the record has to show before anyone widens it.

The best current version of this is not even construction from a blank page. The org reads the client's environment and drafts its own configuration, and the humans, your delivery lead beside the client's CISO, review and ratify every line before it holds any authority at all (Probation: How an Agent Earns Authority is the paper on why a new org starts with none). Your firm's seat in that meeting is counsel, not carpentry.

Configuration is judgment work. Judgment work is what your partners actually sell, what your clients cannot download, and what a competitor cannot undercut by shipping the same scaffolding cheaper.

And the knowledge finally flows in the right direction. In the hand-built model, what your team learns on engagement nine dies in engagement nine's shared drive. In the platform model, the rule library is incident-hardened and cumulative: a failure mode caught at any deployment becomes an encoded rule that every deployment inherits, including the ones you have not signed yet. Your vertical expertise stops being a deliverable and becomes an asset, applied again and again without being rebuilt.

A rule library that compounds across deployments is a practice. A runbook in a client's shared drive is a souvenir.

The practice of the next decade

Play the handover meeting again, ten years out, in the model that survives.

There is no slide four. Nothing is being left behind, because nothing was scaffolding. The governance is the floor of the building, not the temporary structure around it. It was enforced by architecture on the first day of the engagement, and it will be enforced by architecture the day after your team rolls off, because it never depended on your team being present.

What continues is the work that was never finishable in the first place. The periodic review of the rulebook against what the org actually did. The widening or narrowing of authority as the record earns it. The next governed workload brought inside the same structure. The counsel, when the client's business changes shape faster than its rules do.

The services firm of the next decade does not staff the construction of the same controls at every site. It masters the platform layer once, then sells the one thing that cannot be productized: the judgment about how a specific client's organization should be governed, sharpened by every organization the firm has governed before. Fewer builders of scaffolding. More governors of orgs.

The dilemma was never that clients want governance. Clients demanding governance is the best signal your industry has been handed in a decade. The dilemma was the delivery model. And delivery models are a choice.

The takeaway: Every services firm is quietly rebuilding the same governance scaffolding on every agent engagement: approval flows, cost controls, audit trails, rollback plans, hand-built per client and dead within months of handover. The more governance you construct per client, the less repeatable your practice and the more risk you carry for controls you no longer operate. The way out is the turn the industry has made before: governance as the platform layer you deploy and configure, your expertise moved up the stack into the rules, roles, and gates fitted to each client's world, and an incident-hardened rule library that compounds across deployments instead of dying at contract end. You cannot build a repeatable practice out of unrepeatable work. Stop building scaffolding. Start governing orgs.

References

  1. SpeyAI agent org architecture. Live reference at speyai.com.

  2. Forrester. (2026). The State of Agentic AI. Reports roughly three quarters of companies claiming agentic AI adoption while few reach production, attributing the gap to governance: "a policy document can't control an autonomous, tool-invoking system."

  3. KPMG. (2026). AI Pulse Survey, Q1 2026. Reports that 63% of large enterprises now require human validation of agent outputs, nearly three times the share of the prior year (up from 22% in Q1 2025).

  4. Gartner. (2026, May 26). "Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure." Press release. Predicts 40% of enterprises will demote or decommission autonomous AI agents by 2027, citing governance gaps identified only after production incidents.

  5. Cognizant and Cognition (maker of the Devin coding agent) partnership, announced January 28, 2026. Cognizant newsroom: "pairing advanced AI with the governance, platforms and operational scale required for production use." [CC-verified 2026-07-28 against news.cognizant.com]

This paper is part of Rise of the Agent Org, a series by Ed Hoehn, SpeyAI. The full library is at speyai.com/record.

The missing layer

Architecture as governance. See how it runs.