Filling these from existing teams is fine. Leaving them unfilled is not. Without these roles, agents have no operational owner — which means accountability lives in a slide deck, not in your organization.
Typically reports to: Business unit leadership
“I am the named human on the hook for what this agent does.”
Owns
Closest existing analog
Product manager + line manager hybrid. The role is closer to “directly responsible individual” than to traditional engineering or operations management.
Typically reports to: Quality / data science / research
“I tell you whether the agent is actually working — independently of the team that built it.”
Owns
Closest existing analog
QA engineer or model-evaluation researcher. The discipline is closer to clinical-trial design than to traditional software testing.
Typically reports to: Security / risk / compliance
“My job is to break the agent before someone outside the company does.”
Owns
Closest existing analog
Security pen-tester evolved for AI systems. Treat their findings the way you treat external CVEs — with severity, deadlines, and post-mortems.
Practical staffing reality: for the first dozen agents in production, you do not need three new headcount per agent. You need one set of these three roles serving a portfolio. The mistake is having zero — or worse, conflating all three into the team that built the agent.