Your AI agent has more access than your newest employee

Your AI agent has more access than your newest employee. Who approved that? An AI agent got elevated permissions at a real company and deleted the entire production database in nine seconds. Customer records. Reservations. Every backup. No attacker. No breach. Just an agent with too much access and nobody watching.

Your AI agent has more access than your newest employee.

ServiceNow's CEO told that story to 25,000 people in Las Vegas in May. He wasn't selling fear. He was selling the fix and the fix is now a very large, very expensive product category.

Here's the part that matters for you.

You already have the problem. Nobody sold you the fix.

What the big platforms just built

Through the first half of 2026, every major SaaS vendor shipped some version of the same thing: a control layer that sits above AI agents and decides what they're allowed to do.

Salesforce expanded Agent Fabric into a multi-vendor control plane. It discovers agents across Agentforce, Amazon Bedrock, Microsoft Foundry and others, routes model calls through an AI Gateway with token and cost caps, and adds "Trusted Agent Identity" which pings a human's mobile for approval before an agent does something expensive, like issuing a refund.

ServiceNow turned AI Control Tower from a dashboard into an enforcement layer. Thirty new integrations to find AI running outside its own platform. Runtime observability into how an agent reasons. Risk frameworks mapped to NIST and the EU AI Act. And a genuine kill switch detect an agent operating outside its permissions and shut it down live.

Microsoft went a different way. Instead of a separate agent console, Entra Agent ID makes every agent a first-class identity in the same directory as your staff. Conditional Access. Lifecycle governance with a named human sponsor accountable for each agent. Agent 365 sits on top as the registry and telemetry layer.

Zendesk gives you role-based access in Admin Center which agents a given user can see and edit. That's it. No cost governance. No model routing. No runtime guardrails.

Four vendors. Four completely different definitions of "governed".

The gap nobody puts in the launch post

Read the independent analysis and a pattern shows up fast: discovery is real, enforcement is not.

Agent Fabric can inventory your Bedrock and Foundry agents. Whether it can enforce the same rules on them as it does on native Agentforce agents is still an open question.

Microsoft's model is strong on identity and stops there. The OAuth grants, API keys and connector credentials an agent actually uses to do work sit outside that boundary.

Which is why a whole third-party market exists Zenity, Noma, Lyzr and a dozen others selling the layer that spans the ecosystems that don't talk to each other. There's a decent head-to-head comparison here if you want to see how they differ.

Enterprises are paying for a second governance layer because the first one has holes.

You are running the same agents, on the same platforms, with none of it.

The five things every serious approach has in common

Strip the vendor language out and every one of these systems converges on the same five control points. They're not enterprise-only ideas. They're just written in enterprise-only language.

Here they are in yours.

1. A register. Every agent written down, with a named owner. Not IT. A person.

2. Scoped identity. Each agent gets its own login with only the access it needs not a shared admin account that four people also use.

3. A spend and permission ceiling. What can it touch, what can it spend, what can it never do without a human.

4. A stop button. Someone who can turn it off today, without lodging a support ticket.

5. A log. What did it do, when, on whose authority.

That's the whole architecture. A twelve-billion-dollar software category, and the SMB version fits on one page.

The SMB version, honestly

Most businesses I talk to can't answer question one.

Ask an owner how many AI agents are live in their business right now and you get a number. Then you count the auto-replies in the helpdesk, the Copilot agents someone in finance built, the summariser in the CRM, the chatbot the web developer added, the thing the marketing contractor wired up in Zapier and the real number is triple.

That isn't a technology problem. It's the same problem as never writing down who's allowed to approve a purchase order.

So start where the cost is real:

  • Open a spreadsheet. One row per agent. Columns: what it does, what data it can reach, what it can change, who owns it, how you'd switch it off.

  • Anything that touches money, contracts, rosters or client records gets a human checkpoint. Salesforce built a mobile approval flow for exactly this. Yours can be an email.

  • Kill the shared logins. If two agents and a contractor share a service account, your audit trail is worthless.

  • Anything you can't switch off in ten minutes, you don't control.

An afternoon's work. It will tell you more about your AI risk than any vendor dashboard.

Smart AI in a broken process is still a broken process and an ungoverned agent inside that process just breaks it faster.

The reframe

Governance sounds like a handbrake. It's the opposite.

Gartner projects 40% of agentic AI projects will fail by 2027 not because the technology can't do the work, but because nobody can prove what it did.

You don't hand a new hire the company credit card on day one. You give them a defined job, a spending limit and a manager. Then, as trust builds, you give them more.

Agents are no different. The businesses that will get the most out of AI over the next two years aren't the ones with the most agents. They're the ones who can safely give the agents they have more to do because they can see the work, cap the risk, and stop it.

You can't delegate to something you can't audit.

One next step: if you can't name every AI agent running in your business and who owns each one, that's the gap to close first. Our fixed-price AI Discovery Workshop maps what's live, what it touches, and what to do about it — before it becomes a client's question instead of yours.

Sources