
Kurt FischmanFounder, Marshal
Kurt is the CEO of Marshal, the Managed Agent Operations company.

An assistant helps a person work. An agent does the work itself, inside limits you set. A managed service isn't a third kind of software: it answers who runs the agent day to day. Compare the first two on capability, then decide the harder question, which is who owns the job when it breaks.
Type the question into a search box and you get forty pages explaining that assistants are reactive and agents are proactive. Fine. Accurate, even. It's also the least useful thing anyone can tell a founder, because it answers a taxonomy question when you're trying to make a staffing decision.
Here's the reframe. Assistant and agent are answers to "what can this software do." Managed service answers "who is responsible for it on an ordinary Tuesday." Those are different axes, and vendors love that you conflate them, because a capability pitch never has to mention the operating burden that arrives with the capability.
So take the two questions in order. What does the software do? Then, and this is where the money actually goes, who owns the job it now sits inside?
An assistant waits for you. You open it, you ask, it answers, and you decide what to do with the answer. IBM's explainer makes a distinction worth keeping: a chatbot is a modality, while agency is a technological framework. Nonagentic chatbots, in IBM's description, have no tools, no memory and no reasoning, reach only short-term goals, can't plan ahead, and need continuous user input to respond.
That's not a criticism. Most business software is a tool you hold, and a good assistant is a very fast tool. It drafts the proposal, summarizes the thread, rewrites the job posting, explains the contract clause. Your judgment stays in every loop because the software has no way to act without you.
The cost profile is what founders miss. An assistant is cheap to buy and expensive in attention. Nothing gets done unless a person opens the tab. Twenty assistant subscriptions across a fifteen-person company can produce genuine speed and zero change in who does the work. If a job only happens when somebody remembers to do it, an assistant hasn't touched your actual constraint.
An agent gets a goal and some access, then takes steps toward the goal without being walked through each one. IBM defines an AI agent as a system that autonomously performs tasks by designing workflows with available tools, extending past language into decision-making, interacting with external systems and performing actions.
Two details from the same source deserve a founder's attention more than any capability claim.
First, autonomy doesn't mean self-direction. IBM notes that agents still require goals and predefined rules defined by humans, shaped by whoever builds the system, whoever deploys it, and the user who sets the goal and decides which tools are available. Somebody writes the rules. If that somebody isn't you or someone accountable to you, you've outsourced policy by accident.
Second, agents have failure modes with an operational shape. IBM's own risk list includes agents that repeatedly call the same tools in a loop when they can't form a workable plan, noting that some real-time human monitoring might be used to avoid it, alongside multi-agent setups that can fail together and privacy exposure when agents get wired into business and customer systems without oversight or guardrails. The suggested best practice is unglamorous and correct: give people access to a log of what the agent did.
Read those together and the trade becomes clear. An agent moves execution off your desk and moves supervision onto it. That's usually a good trade. It isn't a free one, and the volume of supervision is the number nobody puts on a pricing page.
A managed service is the answer to the supervision question. A provider runs the workload: monitoring, exception triage, workflow changes when your policy shifts, integration upkeep when an upstream system changes under you, and incident response when something goes wrong. You keep the approval limits, the policy calls, and the definition of a good outcome. We've written the full split in what managed agent operations actually includes.
Note that a managed service can sit on top of either capability. Somebody can run an assistant deployment for you, though there's usually little to run. Agents are where the arrangement earns its keep, because agents generate a standing operational job and assistants mostly generate a subscription.
Watch for the counterfeit version. "Managed" on a pricing page frequently means hosted: the vendor runs the servers, and everything above the servers is yours. Hosting is a real service and a useful one. It just doesn't answer the question you asked.
The cleanest way to test a vendor is to describe a specific bad afternoon and listen. An integration credential expires at 2pm and forty jobs queue up behind it. Who finds out, how, and how quickly? Who fixes it? What do you hear from them, and when? A provider who operates workloads answers in minutes and names people. A provider who sells software answers in features and sends you a status page.
Compare the rows rather than the feature lists. Each row is work that has to land on somebody.
| The job | AI assistant | AI agent | Managed service |
|---|---|---|---|
| Deciding what needs doing | You, every time | You, once, as rules and goals | You, once, with the provider drafting the rules for your approval |
| Doing the steps | You, with faster drafting | The agent, inside its limits | The agent, inside limits the provider maintains |
| Noticing that it broke | Not applicable, nothing runs unattended | You, if you built the monitoring | The provider, as a standing duty |
| Fixing a broken integration | Not applicable | You or your developer | The provider |
| Handling an unusual case | You, since you are already in the loop | You, once the agent stalls or guesses | The provider triages, you rule on policy |
| Setting approval limits | Not needed, you are the approval | You | You |
| Answering for the outcome | You | You | You, with the provider accountable for operating it |
| What it costs your attention | High and permanent, one tab at a time | Low per task, plus an unbudgeted supervision job | Low per task, plus approvals and policy calls |
| What you are actually buying | A faster hour for a person | Execution capacity plus an obligation | Execution capacity with the obligation staffed |
Marshal operates, agents work, clients approve. If the noticing and fixing rows have no name against them, they belong to you by default.
The rows below are the work, not the features. Compare across and the honest answer to "which should I buy" usually falls out.
The pattern behind the table is a division of labour worth stating plainly: Marshal operates, agents work, clients approve. Software does the task. Somebody competent runs the software. You hold the judgment calls. Any arrangement that leaves the middle column empty has quietly assigned it to you.
Gartner published a prediction in April 2026 that reads like a warning to anyone building a stack out of assistant subscriptions: most enterprises will abandon assistive AI in favour of outcome-focused workflow by 2028, with over half of enterprises expected to stop paying for copilots, assistants and smart advisors that help people perform manual tasks. Gartner VP Analyst Alastair Woolcock framed the shift as software moving from a tool people use to get work done toward people supervising intelligent systems that execute on their behalf, as No Jitter reported in April 2026.
Treat that as a forecast, because it is one, and analyst forecasts miss. Two things about it still matter for a purchase you intend to keep for three years. The disruption is expected to land first in repeatable, rule-based work: service management, legal and compliance, procurement, CRM and revenue operations. And the word in Woolcock's framing that should stick is supervising. Even the optimistic version of this future has a person watching, which is a role, which needs an owner.
Meanwhile the reported Gartner forecast that 40% of enterprise applications would embed task-specific agents by the end of 2026, up from under 5%, points at something you'll feel as a buyer whether or not you buy an agent on purpose: the software you already pay for is growing the ability to act. Every one of those embedded features is a small agent nobody assigned an owner to.
Which suggests a boring piece of hygiene worth doing this quarter. List the software your business already pays for, and mark anything that can now send a message, change a record, or move money on its own. That list is your existing agent estate, assembled by accident through product updates you never approved. Deciding who owns it is the same question this article asks about a deliberate purchase, only harder, because nobody chose it.
Three questions, answered honestly, settle it.
Is the output advice or an action? If what you need is a better draft, a faster summary, or a second opinion, buy an assistant and stop reading. If what you need is for something to happen without you, you're shopping for an agent.
Does the work repeat enough to be worth the setup? An agent is a fixed cost of configuration, rules and supervision against a variable saving. Forty invoices a week clears that bar. Four doesn't. Volume is also what makes the rules improve, because every exception you rule on is a rule the workflow didn't have last month.
What does a mistake cost, and can you reverse it? Cheap and reversible means loose limits and light monitoring. Expensive or irreversible, anything touching money, customers or compliance, means an approval boundary in front of the action and a log behind it.
Then the ownership question, which is the one this article exists to force. Once the agent runs, someone has to watch it, fix it, and answer for it. Name that person. If the honest answer is "me, after dinner" or "our developer, when there's time," you're choosing between a managed service and an agent that degrades quietly until it embarrasses you in front of a customer.
Assistants are the safe default and a legitimate answer. Agents are the higher return and the higher obligation. A managed service is how you take the return without the obligation, and it's the only one of the three that's priced honestly, because it's the only one that names the ongoing work out loud.
ChatGPT is usually an assistant in the way most businesses use it: you ask, it answers, you act. It becomes agent-like when configured with tools and permission to take steps on its own, which is a configuration choice rather than a property of the product name. The distinction that matters is whether the thing can act on your systems without a person clicking the final button.
Siri sits at the assistant end for most tasks, because it responds to a request and completes a narrow, predefined action. Under the definition of an agent as a system that plans multi-step work and selects tools to reach a goal, a voice helper that sets a timer or sends a text doesn't clear the bar. The label matters less than the capability in front of you.
Starting with an assistant is often the right sequence, because it teaches you where the repeated work actually is. Be aware that little carries over. Moving to an agent means new access, new rules, an approval boundary and a supervision arrangement, so treat it as a fresh decision rather than an upgrade path.
A developer can build an agent. Whether they can run it depends on what else they own and whether they're on call. The operational work is monitoring, exception triage, integration upkeep and incident response, and it doesn't respect sprint boundaries or holidays. One person is also a single point of failure for a workload your business now depends on.
Look for repeated volume, a clear definition of a correct result, and a cheap mistake. Invoice matching, appointment reminders, inbound enquiry routing and document intake tend to fit. Avoid anything where the first error reaches a customer or a regulator, at least until the boundaries and the logs are proven on work that forgives you.