The questions to ask before you deploy an AI agent
The productivity-software news on 9 September shared one thread. The agents that vendors spent the past year building are now arriving in real workplaces, and the conversation has moved from what they can do to whether people trust them, how they are secured, and who answers when they act.
For a business choosing tools this year, that shift matters more than any feature list. An agent that can draft a reply, reconcile an invoice, or update a record is only useful if the people around it will let it, if it cannot reach data it should not touch, and if there is a record of what it did. The five items below all circle that idea from different directions.
Trust is the thing that decides whether an agent gets used
The most useful piece of the day is a survey, not a product. Intercom asked more than a thousand end users how they feel about dealing with AI agents, how capable they think those agents are, and how much they trust them [1]. That framing is worth sitting with, because it names the real barrier to adoption.
Most buying decisions treat capability as the question. Can the tool do the task? But a capable agent that customers refuse to talk to, or that staff quietly route around, delivers nothing. Trust is the gate. And trust is earned by ordinary, unglamorous things: the agent tells you it is an agent, it shows the reasoning or the source behind an answer, and it hands off to a person the moment it is out of its depth.
When you evaluate a tool that puts an agent in front of customers, ask how it behaves when it does not know. A tool that admits the limit and escalates will keep the relationship. One that guesses confidently will spend trust it cannot easily earn back. We have written before about drawing that line clearly in what AI should and should not do in your business.
Your tools now have users that are not people
For years, access control assumed every actor was a person with a login. That assumption is breaking. An agent holds credentials, reaches into systems, and reads or changes data on its own schedule. It is a user, but not a human one.
The clearest signal on this front came from the funding side. Sequoia increased its backing of Cymphony, a company whose product gives security teams a single view of employees, AI agents, and other nonhuman identities, including the systems and sensitive data they can access [2]. The phrase to notice is nonhuman identities. Once an agent can act, it needs the same treatment any account gets: a scope, a limit, and a trail.
This is not a new discipline so much as an old one under new load. The rules that keep a growing team safe — least privilege, per-person access, the ability to revoke without breaking everything — now have to cover software actors too. If you are weighing a tool that ships an agent, ask what that agent can reach, whether you can narrow it, and whether you can see what it touched. The same questions we raised in why permissions matter as a team grows apply, with the added wrinkle that the new user never sleeps.
Governance is another word for knowing who is accountable
Zapier published a piece on AI governance, and its framing is the practical one. When something goes wrong — a corrupted record, an unauthorised action, a decision made on your behalf that you never approved — someone has to be accountable [3]. Governance is the set of rules and records that make that accountability possible before the incident, not after.
It is easy to hear governance and picture a committee. The working version is smaller and more concrete. Who approved this agent to act in this system? What was it allowed to do? What did it actually do, and can you reconstruct that later? Those are answerable questions if the tool keeps a record, and unanswerable if it does not.
This is where the audit trail stops being a compliance chore and becomes the thing that lets you sleep. If an agent takes an action you did not expect, the trail is how you find out what happened and stop it repeating. We covered why that record matters, and why so few teams check for it before buying, in the audit trail nobody thinks about. A tool that cannot tell you who did what, human or machine, cannot be governed, whatever its policy page says.
Being able to choose the model is a form of control
Notion shipped a feature that points at a larger principle: you can now control which AI models your agents use [4]. On the surface that reads as an administrator preference. Underneath, it is about control over cost, capability, and where your data goes.
Not every model is equal, and they are not equal in ways that matter to a business. They differ in price per unit of work, in how well they handle a given task, and in how they treat the data you send them. Being able to pin an agent to a specific model, or to keep it off certain ones, means those trade-offs are yours to make rather than the vendor's to make for you. When you assess a tool with AI inside it, ask whether the model is visible and whether you can constrain it. A fixed, invisible model is one you have to trust on faith.
Finance is the next function to get agents
Salesforce released a CFO Priorities Report, based on a double-blind survey of 865 finance leaders across three continents, which finds the role in the middle of a shift [5]. Finance has been slower to hand work to software than sales or support, for good reason: the cost of an error is measured in money and in regulators. That it is now the subject of an agent story tells you how far the pattern has spread.
The trade-off here is the same one that runs through the whole day. An agent can take on the repetitive parts of revenue work and free a finance team to judge rather than tally. But oversight remains the job. The value is not in removing the human from the decision. It is in removing the human from the parts that never needed a human, while keeping a clear record of what the software did on their behalf.
The through-line for a buyer
Read together, the day says something simple. Agents are no longer the hard part. The hard part is the surrounding structure: the trust that gets them used, the access controls that keep them safe, the governance that assigns accountability, the model choices that keep costs and data in hand, and the oversight that keeps a person answerable for the outcome.
None of that is exotic. It is the same discipline that a well-run business already applies to its people and its data, extended to a new kind of user. A tool that treats an agent as a first-class identity — scoped, logged, and answerable — is one you can adopt without crossing your fingers. That is the standard worth holding every product to this year, and it is the one we hold ourselves to.
Sources
- [1] Announcing 'The 2026 AI Sentiment Report': How end users feel about AI Agents — Intercom
- [2] Sequoia doubles down on Cymphony as AI agents create new enterprise security risks — TechCrunch
- [3] AI governance: What it is and why it's crucial for every business — Zapier
- [4] Control which AI models your agents can use — Notion
- [5] New Research: CFOs Turn to AI and Agents to Tame Growing Revenue Complexity — Salesforce