How CIOs Contain Agent Sprawl By Managing Every Deployment Like A Product
Jason Jodoin, President of 23 Advisory Group, on why an agent headcount tells CIOs nothing about the risk underneath it, and how product discipline turns a sprawling estate into a governed one.

Enterprises are spinning up AI agents faster than they can account for them. The autonomy to deploy now sits at the fingertips of the average worker, not behind a build team, and that shift has moved governance from a back-office concern to a live operational problem. Most organizations can report how many agents they run. Far fewer can say what those agents touch, what value they create, or what risk they carry. Closing that gap is becoming a discipline of its own, and it increasingly resembles product management.
Jason Jodoin is President of 23 Advisory Group, where he helps organizations turn technology spending into measurable results through management consulting, M&A integration, and technology strategy. He previously served as Chief of Staff to the CTO at Citizens, where he was part of the leadership team that transformed the company into a fully cloud-native bank, a multi-year effort spanning more than a thousand application migrations. Before that, he led global infrastructure programs at Hasbro through several acquisitions, including the $4 billion purchase of Entertainment One (eOne), the largest in the company's history. He also ran technology M&A integration at Thrasio. His view of agentic AI starts from the same question he asks of every major technology investment: what is it actually returning?
"You can't govern what you can't count," Jodoin said. He means it as a working test, not a slogan. A headcount reassures without informing: it confirms agents exist without touching the question that actually carries the risk, which is what each of them is doing.
Jodoin sees the emerging agent estate as a portfolio problem as much as a technology problem. As the numbers grow, organizations will need to manage agents much like other technology investments. That means knowing what they own, understanding the cost, assigning accountability, measuring the return, eliminating duplication, and retiring what no longer earns its place in the portfolio.
Count the estate first: Jodoin wants the demographic behind the number, how many agents are running finance workflows or transactional calculations against how many are just organizing calendars and drafting email. "180 agents is a starting point over knowing nothing," he said. "But when you have 1,800 agents and you don't even understand that you have 1,800 agents, that's a different problem." He's seen the expensive version, a large estate doing little more than tidying inboxes. "Do I have 1,800 agents that are automating email? That's a great waste of money," he said. Getting to a truer view means treating the inventory as something to be enforced through architecture, not described in a document.
Deliver value, not noise: "If it's just noise, you're not delivering value, you're delivering distraction," Jodoin said. His test for any deployment is whether it wraps into the full stack in a way the business can feel, from the PMO to the cloud, network, IAM, and security teams, and then back out to a measurable outcome. Activity that merely looks like progress doesn't clear that bar. He compares the current moment to the dashboard boom of the last software cycle, where teams mistook a busy screen for a business result. Increasingly, he argues, the check on all of it is financial discipline, since licensing costs stack up fast when every product on the market now ships an AI-enabled feature and every sales rep arrives with one. His advice there is to pick a small number of paths and go deep rather than chase the buzz across all of them.
Product-manage the lifecycle: Jodoin's answer to the sprawl is a lifecycle borrowed straight from product management. Build each agent for a stated purpose, run it long enough to gather real metrics, and hold a hard line on when to shut it down if it never reaches its potential. "It's really product management at the end of the day," he said. "We have to product-manage through agent deployment. Absent that, everyone's just spinning up their own and hoping for the best." He also builds the cost of the human doing the building into the equation, not just the agent. The failure mode he watches for is what he calls being "overly productive," an agent that runs too many cycles of something it was never meant to do. "I deploy an agent to create ServiceNow tickets, something goes bad in the process, and it creates 50,000 of them," he said. "That's a problem."
Every one of those controls still comes back to a person. The tooling makes it trivial to deploy at scale, which is why Jodoin keeps returning to the human side of the equation rather than the technical one. The question, in his view, is not whether a human belongs in the loop, since most security professionals will insist on one at every step. The harder question is when that human should be present, and when their presence starts eating the efficiency the agent was built to deliver in the first place.
Time the human's entry and exit: "There's a tasteful time and entry of the human, and a tasteful time for the exit of the human, to then reap the benefits of what you're trying to achieve autonomously." Over-govern, and the agent delivers none of the value it promised. His model keeps the person who built the deployment heavily involved at the start, watching how it behaves against parameters set early, before autonomy widens. Scale is the reward for proof, not the default. "Scale should not be introduced until it's been proven that it can't be divergent," he said. That is closer to a QA discipline than a policy one, and he frames the human's role less as a rubber stamp and more as a set of human checkpoints placed where they actually change the outcome.
Standardize the patterns: The mechanism that lets an organization move quickly without losing control, Jodoin argued, is the pattern. He brings a change-management methodology to agents, treating anything already run safely dozens of times as a low-risk template. "Patterns help us define success," he said. "I take that change-management approach and bring that methodology into agents. Something that's been done 50 or 100 times with success proves you can do it with very low risk. Take those patterns, test them, refine them, and make them more accessible." Once a pattern is trusted, oversight itself can be automated. "I'm a big fan of agents for agents, mostly at that supervisor authority level. Something to keep that watchdog, one to manage 100. It's that automated leader, if you will." None of it works, he added, without the right leaders aligned on what matters and on what the organization actually wants AI to achieve over the next several years, and without sequencing the work so the safe, repeatable parts move first.
For all his emphasis on control, Jodoin is not arguing for slowing down. Governance, in his framing, is what makes speed survivable. "Governance is real, and it can't be an afterthought," he said. "It has to be a forethought, tastefully done, so you don't over-govern and get nothing done."
Done right, the discipline compounds. Proven patterns become standard agents, standard agents get supervised by other agents, and the whole structure starts to return more than the sum of its parts. "We're building agents upon agents upon agents. But collectively, it's this packaged agent that's really now multiplying work 100x."
If this caught your attention, that’s not accidental.
The best editorial systems don’t happen by accident. Outlever builds them.









