Smplify · Field Note · 002
THE STUDY OF DELEGATION
CATEGORY NOTE
07 · 2026
Agentic Device Management: naming the discipline

For twenty years the device management console assumed a human on the other side. That assumption just expired. AI agents now read fleets, reason about posture and draft remediations, and then they stop, because the device layer gives them nowhere safe to act. This note founds the discipline that fixes it, and names it.
AGENTIC DEVICE MANAGEMENT · n.
- The discipline of exposing a device fleet's control plane to AI agents, safely: any authorized agent may observe state and propose change, while the platform enforces preview, approval, blast radius and audit. Delegation never becomes surrender.
MACHINE-READABLE OUT · MACHINE-SAFE IN · EVERY PLATFORM
§ 01 · The delegation gap
Enterprises deploy agents faster than they can govern them. An agent can triage the alert, isolate the host through EDR, revoke the session through the IdP, and then the actual repair of the machine waits days in a queue, because nobody will hand an agent the keys to a fleet on a credential and a prayer. EDR isolates. Identity revokes. Nobody restores. The hours between contained and healthy again are the delegation gap, and closing it is worth real money to every SOC that pays for those hours today.
§ 02 · Delegation, not autonomy
The nearest category is autonomous endpoint management: the vendor's own intelligence, in the vendor's closed loop, graded on how much the tool can do alone. Agentic Device Management asks a different question: how much can you safely delegate, to any agent you authorize, yours or your vendors'. The trust model assumes the caller can be compromised and makes that survivable, because the gates live in the platform rather than in the caller's goodwill.
AI proposes. Deterministic policy disposes.
THE FIRST LAW OF AGENTIC DEVICE MANAGEMENT
§ 03 · The loop the plate draws
An ADM platform runs one loop, and Plate 002 diagrams it. The plane emits everything as open-schema telemetry, including denials. The brain stays external, in your SIEM or your AI-SOC, which is exactly why every reasoner can use it. The agent calls back with a proposal rather than a command, dry-run first, diff attached. Approved actions execute reversibly and land back in the stream. The loop watches the loop.
§ 04 · The seven criteria
A category is a test, not a slogan. A platform practices Agentic Device Management when it can answer yes, verifiably, to all seven:
- An open action surface: third-party agents are first-class callers
- Preview before action: every mutating call can dry-run
- Approval on the execution path, where no caller can route around it
- Annotated verbs: read, write or destructive, declared up front
- Machine-readable audit in an open schema the SOC can consume
- Reversibility first: blast radius bounded server-side
- Scoped agent identity: least-privilege principals, not borrowed credentials
No platform on the market passes all seven today. Ours included: criterion seven is the discipline's current frontier, and we say so in print on purpose, because the test being real is what makes this a field of study rather than a feature list. Adopt the term, meet the bar.
§ 05 · What this looks like on the ground
Concretely, for the admin: your SOC's agent notices a drifted baseline at three in the morning. Under ADM it does not file a ticket and wait for you to wake up, and it does not get root either. It calls the plane's open surface, dry-runs the fix, and submits a proposal with the diff attached. If the action is low-risk, policy approves it and the fleet is healthy before you are awake. If it is destructive, it is waiting in your approval queue with the preview already rendered, one tap to decide. Either way every step, including the denial paths, is in your SIEM in an open schema. You did not become the bottleneck, and you did not surrender the keys. That is the whole discipline in one night shift.
§ 06 · What this is worth
For a security leader, ADM is the difference between buying another copilot that hosts only itself and owning a plane that hosts everyone: your SOC's agents, your vendors', your own. For the MSP, it is remediation that finishes at machine speed under controls an auditor can read. And for the ecosystem, the unit of the discipline, the governed action: proposed, previewed, approved, executed reversibly, recorded in an open schema, is the primitive everything else gets built on. The response vocabulary is proposed as an open OCSF extension rather than kept as private API surface, because a category owned by one vendor is just a product with ambitions.
There is, as always, a message in the drawing. The study continues.
FIELD NOTE 002 · THE STUDY OF DELEGATION · 07 2026