← Back to articlesGoverned agents

Governed attention, not more notifications

A governed attention system routes the few decisions, proof gaps, exceptions, and risks that need a person back to the exact work context, while optional updates can be watched, muted, or delivered through configured channels.

Operations contrast between noisy bot notification spam and ScrumDo governed attention funnel delivering only high-leverage decision slabs in card context

The goal is a decision, not a badge count

Agent systems can generate a stream of plans, completions, failures, review comments, connector events, and proof artifacts. Treating every event as an interruption trains people to ignore the system. Governed attention begins by asking what the recipient must decide, what context they need, how urgent the decision is, and what happens if nobody responds.

Four attention classes

ClassExamplesExpected action
DecisionSpec ready, plan ready, final review readyOpen the target, review the current version, approve, request changes, or decline
ExceptionProof insufficient, target changed, revision limit reached, run failedInvestigate the recorded reason and choose recovery or stop
Required acknowledgmentAccepted risk, consequential policy change, overdue control decisionA named person must acknowledge after reviewing the context
InformationalWatched card completed, optional activity, successful deliveryRead, digest, mute, or stop watching

What the Action Center should preserve

  • Plain-language title, why the recipient is seeing it, and what decision is expected.
  • Deep link to the exact card, accepted spec, run, proof item, or portfolio decision.
  • Current state and target version so an old alert cannot authorize changed work.
  • Available actions based on the person’s authority, not merely on receipt of the message.
  • Required acknowledgment state, due time, escalation path, and audit record where policy requires it.
  • Preferences and watches for optional updates, with mandatory items protected from mute.

Use external channels as delivery, not authority

Where an account has configured Slack or Microsoft Teams delivery, the external message should carry a safe summary and a link back to the governed record. It should not leak sensitive story content, turn a chat reaction into an approval, or bypass application permissions. Delivery attempts, suppression, failures, retries, and acknowledgment should remain auditable in the application.

Optional items can be watched, routed to a digest, or muted. Required acknowledgments stay visible because they protect policy, risk, and accountability. Alert-thread snooze can defer attention where enabled, but it should have an expiry and must not erase the underlying obligation.

Events worth routing from governed agent work

  • A proposed specification is ready for review or has blocking comments.
  • A plan is ready for approval, changed after approval, or became stale.
  • A run failed, exceeded a limit, lost connector access, or requires a recovery choice.
  • QA found insufficient proof, contested a result, or reached the revision limit.
  • Final review is ready, or an authorized person accepted a disclosed risk.
  • A pull request, deployment, or other proof target changed after the recorded review.

Key terms

Governed attention
Routing a person to a specific decision, exception, or acknowledgment with the context and authority needed to act.
Watch
An opt-in rule for receiving selected updates about a card, epic, release, room, portfolio object, or decision.
Required acknowledgment
A policy-protected item that remains visible until an authorized recipient records that it was reviewed.

Sources and standards context

  • NIST AI Risk Management Framework CoreNIST describes governance as a continuous, cross-cutting function and calls for documented human oversight, roles, testing, and accountability across the AI lifecycle.