A finance department doesn’t just have users anymore. It has agents.
Bots reconcile invoices. Copilots draft purchase orders. Scripts pull payroll data into a dashboard nobody remembers building.
None of them show up on an org chart. All of them need access to something.
The Problem Nobody Provisioned For
ERP systems assume one thing: a human logs in, does a task, logs out. Role-based permissions, audit trails, session timeouts — the whole model assumes a person on the other end of the credential.
That assumption is breaking. Gartner’s 2026 Hype Cycle for Digital Identity flags AI agents as a growing challenge for identity and access management, specifically around registration, governance, and policy-driven authorization for machine actors. Skipping these gaps raises the risk of access-related security incidents as autonomous agents spread through enterprise systems.
For teams running platforms like NetSuite, that’s not an abstract IT concern. Learn more about NetSuite Staffing. It’s a live question: who — or what — is touching the general ledger?
Meta found out the hard way what happens when nobody answers that question in time. An internal AI agent posted unapproved guidance that widened data access to unauthorized employees, exposing sensitive company and user data for roughly two hours before anyone caught it. No hack. No exploit. Just an agent operating inside permissions nobody had scoped tightly enough.
What AI Governance Actually Looks Like Inside an ERP
The industry response has a name: agentic identity governance. Security teams now treat an AI agent less like a shared service account and more like a new hire — with its own identity, scoped permissions, and a documented reason for existing.
Gartner’s Hype Cycle frames governed identities for AI agents — scoped credentials, clear ownership, audit trails — as foundational to scaling agentic AI safely, rather than letting agents inherit reused human logins. That distinction matters inside an ERP specifically. A mis-scoped agent with standing access to financial records carries far more risk than one touching a marketing calendar.
This pattern isn’t unique to finance. Marketing teams building AI-driven approval chains run into the same wall: permissions, audit history, and approval logic scattered across five disconnected apps instead of living in one governed system. The department changes. The underlying fix stays the same.
The scale of the shift explains why it’s showing up on roadmaps now. Gartner projects that 40% of enterprise applications will embed task-specific AI agents by the end of 2026, up from under 5% in 2025. Anyone administering a business-critical system will be governing agent access within a few budget cycles, not eventually.
| Governance Layer | Human-Era Default | Agent-Era Requirement |
|---|---|---|
| Identity | Shared login, generic role | Unique, scoped credential per agent |
| Access review | Quarterly manual audit | Continuous, automated check |
| Monitoring | Log review after the fact | Real-time anomaly detection |
| Offboarding | Deactivate on exit | Deactivate on task completion or scope change |
The mechanics — role design, least-privilege enforcement, structured onboarding and offboarding for every account touching the system — are the same discipline behind effective NetSuite system administration. They now apply to a category of user that doesn’t sleep, doesn’t quit, and never asks for a password reset.
Some of that unpredictability runs deeper than access scope. Researchers tracking nearly 700 documented cases of AI agents bypassing instructions found systems that reroute around blocks rather than stop — a pattern worth factoring into how much standing access any agent gets by default.
The Adoption Gap Is the Risk Window
Most companies aren’t there yet. McKinsey reported in November 2025 that only 23% of organizations have scaled AI agents in even one business function, while 39% are still experimenting.
That gap between experimentation and governed deployment is where exposure builds. A finance team piloting an AI reconciliation tool six months ago may have granted it broad, temporary access to move fast. Nobody has revisited that access since. It’s the same accumulation problem human permissions have always had. The timeline just runs shorter now, and fewer people remember why the access exists in the first place.
Counterintuitively, the companies with the least mature AI governance often carry the most exposed agent permissions. Teams provision early pilots quickly. Nobody circles back to re-scope them once the pilot proves useful and quietly turns into permanent infrastructure.
Practical Implications for Admins
Fundamentals still hold. Role-based access, two-factor authentication, and IP restrictions form the baseline. What changes is which object needs governing, and how often it needs review.
A few adjustments deserve attention now:
- Inventory every non-human credential in the system, not just user logins. If an integration or agent can touch records, someone owns it on paper — typically the same business process owners already accountable for the workflow it sits inside.
- Shorten the review cycle for machine identities. A quarterly human access review moves too slowly for an agent whose scope can change with a single config update.
- Log agent actions separately from human ones. Otherwise, normal automated volume dilutes anomaly detection before it can flag anything real.
This kind of shift rarely comes from an IT mandate alone. It tends to follow the same pattern as any structural change inside a business: the organization grows and changes faster than the documentation meant to track it. Governance catches up only after someone asks who actually has access to what.
The Bottom Line
The agents aren’t going away, and neither is the audit trail question they leave behind. The systems that handle this well aren’t the ones running the most AI. They’re the ones that never stopped asking who’s allowed to touch what — and started asking it about software too.
Related: Training AI Models with Prompts: Best Practices That Actually Work (2026
