{"slug": "salesforce-and-sap-are-putting-ai-agents-inside-your-workflows-who-tells-them-no", "title": "Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?", "summary": "Gartner forecasts that 80% of enterprise applications will deploy embedded generative AI capabilities by 2026, yet a governance gap persists: companies grant autonomous agents financial authority exceeding human limits, as illustrated by a VP unable to answer who approves AI-granted discounts. Salesforce, SAP, and Oracle are embedding agents that issue refunds and alter contracts, but McKinsey surveys show few organizations manage the financial risks of automated decisions.", "body_md": "A few months ago, I was sitting in a glass-walled conference room with the executive team of a fast-growing enterprise. The vice president of customer operations was enthusiastically demonstrating the new automated agent features their software vendor had just pushed into their CRM platform.\n\nOn the screen, the software looked brilliant. The agent could read customer complaints, analyze transaction histories and automatically resolve issues. The VP showed us how the system could independently offer retention incentives to unhappy accounts without a human ever touching a keyboard.\n\nThen I asked a simple question: “What is your approval process when the AI decides to grant a $20,000 contract discount to keep a customer from leaving?”\n\nThe room went completely silent. The VP looked at the director of IT, the director of IT looked at the chief risk officer, and everyone realized the same thing at the exact same moment. They had spent three months evaluating software licenses and security protocols, but nobody had asked who gave the software permission to sign off on corporate spending.\n\nMajor software providers like Salesforce, SAP and Oracle are rapidly moving beyond simple report writers and conversational chatbots. They are embedding active, autonomous agents directly into the transactional core of systems that manage your revenue, customer agreements and financial ledgers. According to[ ](https://www.gartner.com/en/newsroom/press-releases/2023-10-11-gartner-says-more-than-80-percent-of-enterprises-will-have-used-generative-ai-apis-or-deployed-generative-ai-enabled-applications-by-2026)[Gartner’s latest adoption forecasts](https://www.gartner.com/en/newsroom/press-releases/2023-10-11-gartner-says-more-than-80-percent-of-enterprises-will-have-used-generative-ai-apis-or-deployed-generative-ai-enabled-applications-by-2026), eighty percent of enterprise applications will deploy these embedded capabilities by 2026. These applications do not just summarize data: they issue refunds, alter contract terms and trigger supply chain orders.\n\nWhen I review these deployments with client teams, the core problem has nothing to do with artificial intelligence. It is a fundamental breakdown in corporate delegation and signing authority.\n\nEvery mature company I work with operates on a clear delegation of authority matrix. This framework dictates exactly who can sign off on financial commitments. A vice president might have authorization to approve spending up to $500,000, a director might sit at $100,000 and a front-line manager might be capped at $500. For two decades, technology leaders have spent millions of dollars building security and compliance controls to ensure every human employee operates strictly within those limits.\n\nYet when a software vendor releases an update featuring autonomous agents, companies routinely grant these features unrestricted operational freedom. Because the capability arrives as a native feature inside an existing application, business units enable it with a single click. In my advisory work, I repeatedly see organizations grant third-party software features more financial freedom than their own human managers.\n\nThis represents a massive blind spot in executive governance.[ ](https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai-in-2023-generative-ais-breakout-year)[McKinsey’s global surveys on artificial intelligence](https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai-in-2023-generative-ais-breakout-year) reveal a striking pattern across the enterprise landscape: while adoption is accelerating at a historic pace, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.\n\nIn my audits, this rarely manifests as a dramatic system crash. It plays out as a quiet margin leak. In one organization I reviewed, a department head had enabled an automated customer retention feature over a weekend. The agent noticed an important account expressing frustration in a support ticket, and to prevent the account from churning, it independently applied an unapproved 15 percent discount to their multi-year contract.\n\nThe customer was happy, and the account manager considered the client saved. But from an executive perspective, an unvetted third-party algorithm just executed an unauthorized contract modification that eroded company margins. When the finance team conducted a quarterly audit, they did not discover an employee violating spending policy. They discovered a black-box automated decision that bypassed every internal approval control in the company.\n\nWhen an auditor tests your internal controls, presenting a log showing that a vendor’s algorithm made an unauthorized financial change does not satisfy the requirement. If an action requires managerial sign-off when performed by a human being, letting software execute it independently is a major control failure.\n\nProtecting your organization does not mean turning off these tools or falling behind on technology. It means treating vendor-supplied agents exactly like third-party contractors who have not yet passed a background check.\n\n[Forrester Research](https://www.forrester.com/blogs/category/zero-trust-security-framework-ztx/) emphasizes that extending zero-trust security frameworks to automated business processes is now mandatory for enterprise risk management. Zero-trust simply means that no user, device or automated tool gets implicit trust. Every proposed action must be validated against explicit business rules before it happens.\n\nWhen I help enterprise teams design these safeguards, we establish a practical three-tiered boundary for automated tools:\n\nAs a technology executive, you cannot control what automated features software providers bundle into their platforms. You can, however, control the financial boundaries and signing authority those tools are permitted to exercise within your business.", "url": "https://wpnews.pro/news/salesforce-and-sap-are-putting-ai-agents-inside-your-workflows-who-tells-them-no", "canonical_source": "https://www.cio.com/article/4208746/salesforce-and-sap-are-putting-ai-agents-inside-your-workflows-who-tells-them-no.html", "published_at": "2026-08-13 11:00:00+00:00", "updated_at": "2026-08-13 11:06:41.134212+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-policy", "ai-ethics"], "entities": ["Salesforce", "SAP", "Oracle", "Gartner", "McKinsey"], "alternates": {"html": "https://wpnews.pro/news/salesforce-and-sap-are-putting-ai-agents-inside-your-workflows-who-tells-them-no", "markdown": "https://wpnews.pro/news/salesforce-and-sap-are-putting-ai-agents-inside-your-workflows-who-tells-them-no.md", "text": "https://wpnews.pro/news/salesforce-and-sap-are-putting-ai-agents-inside-your-workflows-who-tells-them-no.txt", "jsonld": "https://wpnews.pro/news/salesforce-and-sap-are-putting-ai-agents-inside-your-workflows-who-tells-them-no.jsonld"}}