Self-Improving AI Still Needs a Change Ticket

Autoheal's Healer writes prompt diffs into Git. Meta launched an enterprise platform the same week Workplace died. Microsoft says attackers already shrank the window to minutes.

Printed change-request form on a desk beside a laptop showing a git diff of a prompt file, cool office light, no logos

James Alan Miller’s TechTarget piece, dated October 5, is not about models that rewrite themselves in production while nobody watches. Autoheal, the startup he uses as the example, runs an Evaluator that scores other agents and a Healer that proposes changes to prompts, tools, skills, or model picks. Those proposals get tested against historical benchmarks, dropped into Git, and wait for an engineer. That is a pull request with extra nouns.

The useful question is the one Miller puts on CIOs: if the change is still versioned, tested, and approved, what actually moved in IT change management? The answer in that article is not “everything.” The answer is the number of things that can alter production behavior without a compiler. We already wrote that the job is where agents are allowed to act. This week is what counts as a change after you said yes.

The prompt is now a deployable

A conventional change is code, config, or infrastructure. An agent also has a prompt, a model, a routing policy, a tool list, permissions, and a workflow. Miller’s point is blunt. Any of those can change what happens next time even if the application repo is quiet. Harness, in the same piece, still uses the old control set: testing, human gates, progressive rollout, canaries, risk scoring, rollback. It is applying them to nondeterministic agents. The controls are familiar. The inventory is not.

That is why “we didn’t ship code this week” is no longer an audit answer. If someone edited the refund prompt, you shipped. If someone added a tool that can open a ticket in the ERP, you shipped. If the router started sending HR screening to a new model, you shipped. Technical size is the wrong ranking. Miller’s examples are the right ones. A small prompt tweak that changes an internal summary is one class. A similarly small tweak that changes when a customer gets a refund is another. HR screening. ERP approval paths. Money.

Julie Irish, CIO at Alteryx, told TechTarget that supervision should match the consequence of a mistake. Drafts and internal summaries are not the same category as moving money, deleting data, contacting customers, or affecting legal rights. Miller applies the same split to changes, not only to runtime permissions. What the agent is allowed to do and what you are allowed to change about it are the same risk register.

If your change-advisory board still only sees Jira tickets with Git SHAs, the Healer’s prompt diff is going around you. Put the prompt file in the same pipeline you already trust, or admit you have a shadow deploy.

Evidence buys scope, not a forever yes

Miller’s next turn is the one vendors will hate. Historical tests help. Side-by-side comparison helps. Staged production exposure helps. Business-owner review helps. Rollback helps. None of it is certainty. The cases you tested are conditions you already know. Approval is for what happens next: different data, different regulation, different downstream system.

So the question is not “is the evidence good enough?” It is “how much change does this evidence justify?” Low-consequence, easy-to-check summary prompts can travel. ERP, refunds, hiring, finance cannot get an unrestricted pass because a benchmark suite went green. Split the change: one workflow, one user group, transactions under a threshold, a review date. Evidence buys scope.

Approval, in his framing, should name the version, the workflow, the users or transactions, the conditions that force reevaluation, and the path back. That is a bounded operating decision, not a rubber stamp. Taking the human out of the gate does not remove the judgment. It moves the judgment into whoever set the passing tests. Six months later the model, the business rule, or the downstream system can change without the agent file moving. An old yes is not a current yes.

Domo’s recent platform work, as Miller cites it, is the backward-looking half: pipeline versioning, visibility into processes agents start, an MCP trigger that flags when an agent or assistant initiates work. Reconstruction is easier than approval because the state existed. The prompt ran. The transaction posted. You can walk backward. Approval still faces a future that has not happened. Keep both. Do not confuse an audit log with a change policy.

This is the same discipline as client zero being a bill, not a demo. A green eval is a demo until it has a scope and a rollback.

Meta wants the seat. Workplace already left the building

Madeleine Streets in InformationWeek, October 1, puts a vendor in the same week. Meta Enterprise Platform, introduced the Monday before that piece, packages models, agents, and developer tools for businesses. Meta hired former MongoDB CEO Chirantan “CJ” Desai to run it. OpenAI unveiled Dots the next day, pitched as always-on systems that pursue goals across applications. Consumer AI companies want the workflow, not only the chat window.

CIOs are not empty-handed. They already have AI inside the vendors they integrated. Alex Sobol, co-founder of The Millennium Alliance, said every new player is “just another thing to evaluate, secure and govern.” Jim Piazza, chief AI officer at Ensono, wants competing platforms run against the same workflow, the same data, the same success criteria. Cost per successfully completed business task, not cost per token. A demo is a starting point. Reliable performance is the investment.

Meta’s enterprise history is the trust problem Streets does not dodge. Workplace, the collaboration product, shut down this year. Different product, same company. Sobol’s line: CIOs value novelty, but they value staying power more. Ask whether enterprise is core or a side project. Ask whether security is baked in. Ask for exit rights and portability before the workflow is trapped. Piazza: an exit plan belongs in the buying decision, not in a clause you find after the agents are in the ERP.

Agentic access raises the bar again. Piazza: “Giving an agent access is a decision about delegated authority.” An agent that investigates an incident does not automatically remediate. An agent that recommends a transaction does not automatically approve. Sobol said successful CIOs treat agents like a new employee. Named accounts, granular permissions, a business owner, approval points for high-impact actions. That is change management for people, applied to software that can act.

If you are comparing Meta’s new platform to whatever is already in Microsoft 365 or the CRM, do not start with the model card. Start with whether you can fire the vendor without rebuilding the process. Gartner’s spend number already showed how easy it is to relabel a budget as transformation. A second agent platform is the same trick unless it clears Piazza’s task-level test.

Attackers already use the shorter clock

MSSP Alert’s October 5 summary of Microsoft’s Digital Defense Report 2026, itself dated October 1, is the ugly twin of Miller’s change ticket. Attackers are using agentic models to compress the lifecycle from days to minutes: initial access, vulnerability discovery, social engineering, malware. After compromise, exfiltration, credential discovery, and lateral movement shrink the same way. The methods are not new. The speed is. The report flags autonomous campaigns such as JadePuffer.

Phishing as an initial vector rose from 7 percent to 23 percent of incidents, on AI-personalized messages. Public-facing app exploits also rose. Government was the most targeted sector at 27 percent, then IT at 17 percent, research and academia at 14 percent, with the United States taking the highest volume. Microsoft’s advice in that summary is not glamorous: phishing-resistant MFA, identity, AI-speed defense.

Connect it to the Healer anyway. If your production agent can change a prompt overnight with a weak gate, you built an attacker-speed deploy path and called it improvement. If identity is still passwords plus SMS, the minutes Microsoft is describing are not theoretical. Change control on agents and identity on humans are the same week.

CIO.com’s savings piece from October 1 did not load here. The extract still had numbers worth parking, with that caveat. LaunchDarkly, about $50,000 annualized, agentic tier-1 IT support. West Monroe, 40 percent off yearly MSP cost and about 2,700 hours a year. Atera’s Gil Pekelman pointing at a Forrester ROI study on an IT incident agent. KamiwazaAI’s Matthew Wallace using agents in engineering and cloud optimization. Those are support and cloud tickets, reversible relative to refunds and hiring. They fit Irish’s low-consequence bucket. They do not license an unsupervised Healer on the ledger.

Put the ticket on the prompt file

Self-improving AI, in Miller’s reporting, is not an argument for throwing out CAB. Versioning, tests, staged rollout, review, rollback still do the job. What moved is the definition of the artifact. Prompt, model, tool, permission, workflow. Meta is asking to be a new platform in that inventory while its last enterprise product is already gone. Microsoft is telling you the other side already ships on a minutes-scale loop.

Write the inventory in the same system you already use for servers. Prompt files get owners. Model IDs get versions. Tool allowlists get a ticket when they grow. MCP triggers, in the Domo example, exist so you can see that an agent started a process. If you cannot answer “what ran at 14:03,” reconstruction is a slide.

Microsoft’s sector split is a procurement hint, not a vibes chart. Government at 27 percent, IT at 17, research and academia at 14. Universities that just stood up agent platforms for “student services” are in the academia bucket and the identity bucket at the same time. Phishing-resistant MFA is cheaper than a second Healer.

Piazza’s cost-per-completed-task test belongs next to Irish’s consequence test. A $50,000 LaunchDarkly support save, if the extract holds, is a completed-task number. A Healer that rewrites the refund prompt is not. Sobol’s new-employee metaphor is the hiring process you already have: limited access, a manager, a probation period, a way to disable the account. Agents skip probation when they ship as a platform feature.

The practical page for this week is boring on purpose. Inventory the agent-editable surfaces. Decide which ones are summaries and which ones are money. Tie the first class to a lightweight Git review. Tie the second to the same change process you use for payroll config. Write the scope into the approval: version, workflow, users, expiry, rollback. If a vendor cannot tell you how an agent is identified and how you leave, you are not buying a platform. You are renting a demo that can act.