→ Back to Home
Enterprise AI

Enterprise AI Agents Stall on Permissions, Not Model Performance

While the capabilities of AI models continue to advance rapidly, the real-world deployment of enterprise AI agents is hitting a wall, not due to limitations in model performance, but because of intricate permissioning challenges. According to Gerrit Kazmaier, President for Product and Technology at Workday, the fundamental issue lies in clearly defining what an AI agent is authorized to access and act upon, and how the system reliably enforces these boundaries. This problem is particularly acute in sensitive areas like HR and finance, where "almost right is not acceptable" due to the critical nature of tasks such as payroll and financial closing. Kazmaier explained that the accuracy of AI agents in these domains is far more difficult to evaluate than in typical AI contexts. Policy configurations, role-based security, and complex organizational hierarchies are deeply interconnected, meaning even minor errors can have significant, compounding consequences. Furthermore, unlike many generative AI outputs that can be easily corrected, errors in HR and finance workflows often lack a straightforward correction loop, making robust governance an absolute necessity from the outset. Workday's solution involves leveraging its existing system of record as the primary governance layer for agents. This approach ensures that the integrity of established approval processes and security models is consistently maintained. Kazmaier noted that customers often struggle when attempting to construct ad-hoc permissioning solutions for their AI agents, leading to a loss of the rich security model inherent in their enterprise systems and resulting in overly broad or insecure agent actions. Workday's expanded partnership with Google to bring its Sana agent system to Gemini Enterprise further underscores the importance of integrating agent governance directly into established enterprise platforms.
#ai agents#enterprise ai#permissions#governance#workday#security
Read original source