Why CIOs must redesign how SAP, Salesforce and ServiceNow grant authority
40% of enterprise apps will run agents by end of 2026. Your permission model was built for humans clicking buttons. It breaks all four control assumptions at once — and auditors are already finding it.

Why it matters
Agents operating inside SAP, Salesforce, and ServiceNow are inheriting permission models designed for human users, creating segregation-of-duty failures, authorization bypasses, and audit-trail breakdowns that show as control deficiencies, not security incidents. CIOs must redesign identity governance, approval enforcement, and evidence recording before agent autonomy scales.
The key facts
13 to knowGartner: 40% of enterprise applications expected to carry task-specific AI agents by end of 2026, up from under 5% in 2025
Okta: only 10% of organizations have a strategy for managing agents already running
Deloitte: 21% of leaders report mature agentic governance; 74% expect to use agents within two years
Cloud Security Alliance: 68% of organizations cannot clearly distinguish between human and AI agent activity
Gartner forecast: 40%+ of agentic projects expected to be canceled by end of 2027 due to escalating cost, unclear value, and inadequate risk controls
Four control planes break simultaneously: Intent (unbounded goals vs. least privilege), Authority (standing entitlements + API bypasses), Logic (rules drift across three homes with no unified change control), Evidence (logs name borrowed credentials, not sponsors)
Real cases: Fortune 500 insurer's agent cleared exceptions under controller's ID (segregation of duties failure); retail agent wrote Salesforce quotes via API bypassing approval process; payer's authorization threshold drifted silently across three system homes
Microsoft: agent identity now requires named business owner sponsor; SAP: agent lifecycle governance (proposed → evaluated → approved → active → retired) with verification badge; Google Cloud: agent identities not shared, cannot be impersonated, no long-lived keys (GA this month)
Rubrik (Black Hat, 4 August): service mints short-lived tokens per tool call, eliminating standing permissions
NIST National Cybersecurity Center of Excellence: concept paper on agent identity and authorization opened February, closed April (gap officially acknowledged, standard not yet written)
EU AI Act: Article 50 transparency duties (disclosing AI system interaction) took effect 2 August 2026; high-risk obligations deferred to 2027–2028
BCG guidance: define clear approaches to agent identity, authority, and accountability across regulated industries
Booz Allen survey of 105 federal IT/cybersecurity leaders (spring 2026): 22% have not determined who bears responsibility when an agent causes an incident
Go to the source
CIOcio.com
Publisher excerpt: At a Fortune 500 insurer, I watched an AI agent inside the month-end close do exactly what we asked. It posted the recurring accruals. It worked the intercompany exception queue, the reconciliation that normally falls to a staff accountant. And when items would not match, it cleared them to a…