WorkThe story, in brief

Why CIOs must redesign how SAP, Salesforce and ServiceNow grant authority

40% of enterprise apps will run agents by end of 2026. Your permission model was built for humans clicking buttons. It breaks all four control assumptions at once — and auditors are already finding it.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

Agents operating inside SAP, Salesforce, and ServiceNow are inheriting permission models designed for human users, creating segregation-of-duty failures, authorization bypasses, and audit-trail breakdowns that show as control deficiencies, not security incidents. CIOs must redesign identity governance, approval enforcement, and evidence recording before agent autonomy scales.

The key facts

13 to know
  1. Gartner: 40% of enterprise applications expected to carry task-specific AI agents by end of 2026, up from under 5% in 2025

  2. Okta: only 10% of organizations have a strategy for managing agents already running

  3. Deloitte: 21% of leaders report mature agentic governance; 74% expect to use agents within two years

  4. Cloud Security Alliance: 68% of organizations cannot clearly distinguish between human and AI agent activity

  5. Gartner forecast: 40%+ of agentic projects expected to be canceled by end of 2027 due to escalating cost, unclear value, and inadequate risk controls

  6. Four control planes break simultaneously: Intent (unbounded goals vs. least privilege), Authority (standing entitlements + API bypasses), Logic (rules drift across three homes with no unified change control), Evidence (logs name borrowed credentials, not sponsors)

  7. Real cases: Fortune 500 insurer's agent cleared exceptions under controller's ID (segregation of duties failure); retail agent wrote Salesforce quotes via API bypassing approval process; payer's authorization threshold drifted silently across three system homes

  8. Microsoft: agent identity now requires named business owner sponsor; SAP: agent lifecycle governance (proposed → evaluated → approved → active → retired) with verification badge; Google Cloud: agent identities not shared, cannot be impersonated, no long-lived keys (GA this month)

  9. Rubrik (Black Hat, 4 August): service mints short-lived tokens per tool call, eliminating standing permissions

  10. NIST National Cybersecurity Center of Excellence: concept paper on agent identity and authorization opened February, closed April (gap officially acknowledged, standard not yet written)

  11. EU AI Act: Article 50 transparency duties (disclosing AI system interaction) took effect 2 August 2026; high-risk obligations deferred to 2027–2028

  12. BCG guidance: define clear approaches to agent identity, authority, and accountability across regulated industries

  13. Booz Allen survey of 105 federal IT/cybersecurity leaders (spring 2026): 22% have not determined who bears responsibility when an agent causes an incident

Go to the source

CIOcio.com

Publisher excerpt: At a Fortune 500 insurer, I watched an AI agent inside the month-end close do exactly what we asked. It posted the recurring accruals. It worked the intercompany exception queue, the reconciliation that normally falls to a staff accountant. And when items would not match, it cleared them to a…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work