Governance, access, and the trust behind your tools
On a day when one of the most prominent voices in enterprise software warned that the companies building frontier AI are not yet trustworthy enough to run inside a business, several productivity vendors shipped features that pull in the same direction. The thread is governance: the unglamorous question of who is allowed to act, whether you can trust the machine doing the acting, and how you check what happened afterwards.
The trust question sits above the tool
When you buy software with AI inside it, you are not only buying a capability. You are also buying a relationship with whoever built and runs the model behind that capability. Those are two separate things, and it is worth keeping them separate when you compare products. A feature can be genuinely useful while the vendor supplying the underlying model is still an open question for your risk team.
That separation was on display in unusually blunt terms on Monday. After reporting a quarter that produced a billion dollars in profit, Palantir's chief executive used the moment to repeat a warning about the wider AI field rather than to celebrate [1]. The point for a buyer is not the personality or the quarrel. It is the reminder that a strong commercial result and a trustworthy supply chain are not the same measurement, and that the reliability of the lab behind a tool belongs on your checklist next to price and features. This is the same discipline we have argued for in what AI should and should not do in your business: decide what you are willing to hand over before you decide who you hand it to.
Governance is becoming a product feature
For most of the past two years, the AI conversation among software vendors was about capability. Could the tool write the email, summarise the call, generate the image. The newer conversation is about control: can you set rules for what the automation is permitted to touch, and can you see what it did. That shift matters because an automation with real reach into your data and your customer records is only as safe as the limits you put around it.
Zapier gathered its AI products into a single guide on Monday, written by someone who has covered the company's automation and AI work for two years [2]. The framing is worth noting whichever tools you use: the pitch is no longer just that AI can do things, but that it can be pointed at your systems within boundaries you set. When you evaluate any automation platform, ask where those boundaries live, who can change them, and whether the vendor treats governance as a first-class part of the product or an afterthought bolted on later.
Access control is the boundary that does the work
Role-based access control, usually shortened to RBAC, is the mechanism most of that governance rests on. The idea is simple. Instead of granting each person a bespoke set of permissions, you define roles, attach permissions to those roles, and assign people to roles. A new hire in support inherits exactly what a support person should see, and nothing more. When someone changes jobs or leaves, you change one assignment rather than hunting through a dozen tools.
The alternative is the arrangement most small teams start with, and it is a familiar one. Zapier's explainer opens with the author recalling a law firm that tracked client information in a shared spreadsheet everyone could open [3]. That works until it does not: a single document where every person has full access has no notion of least privilege, no record of who changed what, and no way to narrow a view without narrowing it for everyone. RBAC exists to solve exactly that problem, and it is one of the clearest signals that a tool was built for more than one person to use safely. We covered the same instinct from the identity side in one login and why it matters: fewer doors, each one with a lock you actually control.
Agents and generators are not the same purchase
A lot of confusion in the market comes from putting two different kinds of AI in one bucket. Generative AI produces something when you ask: text, an image, a summary. Agentic AI is meant to pursue a goal across several steps, deciding and acting along the way rather than returning a single output. The distinction changes what you are buying and what can go wrong. A generator that produces a poor draft costs you a rewrite. An agent that takes a wrong action costs you the action.
Zapier drew the line plainly on Monday, comparing the habit of lumping the two together to treating a blender and an AI personal assistant as the same category because both have buttons [4]. The practical takeaway is that these need different scrutiny before you deploy them. For a generator, judge the output. For an agent, judge the guardrails, because you are delegating decisions and not just words. Where the line falls for your own team is a judgement worth making on purpose, and it is the subject of how to tell whether a task should be automated.
A clearer record of what was shown and said
Governance is not only about permissions before the fact. It is also about the record afterwards. Most decisions in a business are made in meetings and reviews, and the record of those decisions is often thinner than the decision deserves. A transcript captures the words but loses the slide that was on screen. A comment on a video says "the bit near the middle" and leaves the reader scrubbing to find it.
Two Google Workspace updates on Monday chipped away at that gap. Google Meet's automatic note-taking can now capture screenshots of presented content and place them into the notes document, so the visual context sits beside the summary rather than vanishing when the call ends [5]. Separately, Google Drive gained timestamped comments on video, letting a reviewer anchor feedback to a specific moment instead of describing it in prose [6]. Neither is a large feature on its own. Together they point at something buyers should value: a record that is precise enough to be useful weeks later, when nobody remembers what was on the screen. That is the same reasoning behind the audit trail nobody thinks about — the value of a record is felt long after the moment it was made.
What to take from the day
Read together, Monday's announcements describe a market growing up. The questions are moving from "can the tool do this" to "who is allowed to make it do this, can I trust what sits behind it, and can I see what happened." When you next compare tools, treat those as first-order questions rather than fine print. 360REV is built around keeping the conversation, the records, and the audit trail in one place precisely so those questions have answers. The tools that will still serve you in a year are the ones that took governance seriously before you had to ask.
Sources
- [1] After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’ — TechCrunch
- [2] Zapier's AI tools: Get to know our governed AI products and features — Zapier
- [3] What is role-based access control (RBAC)? — Zapier
- [4] Agentic AI vs. generative AI: Key differences and use cases — Zapier
- [5] Visual screenshots now included in Google Meet meeting notes — Google Workspace Updates
- [6] Provide more clear, contextual feedback with timestamped comments in Google Drive videos — Google Workspace Updates