Accountability should sit with one named owner for the agent class, supported by security, IT, and platform teams. Fragmented responsibility leads to inconsistent policies, weak audit evidence, and unclear exception handling. The right model is a single accountable chain for identity, access, logging, and lifecycle decisions.