NetSuite staffing

AI Agents Are Changing Who Counts as a User in ERP

A finance department doesn’t just have users anymore. It has agents.

Bots reconcile invoices. Copilots draft purchase orders. Scripts pull payroll data into a dashboard nobody remembers building.

None of them show up on an org chart. All of them need access to something.

The Problem Nobody Provisioned For

ERP systems were built around one assumption: a human logs in, does a task, logs out. Role-based permissions, audit trails, session timeouts — the whole model assumes a person on the other end of the credential.

That assumption is breaking. Gartner points to the rise of AI agents as a growing challenge for identity and access management, particularly around registration, governance, and policy-driven authorization for machine actors. The firm warns that skipping these gaps raises the risk of access-related security incidents as autonomous agents spread.

For teams running platforms like NetSuite, that’s not an abstract IT concern. It’s a live question: who — or what — is touching the general ledger?

What AI Governance Actually Looks Like Inside an ERP

The industry response has a name: agentic identity governance. Security teams now treat an AI agent less like a shared service account and more like a new hire — with its own identity, scoped permissions, and a documented reason for existing.

Gartner’s 2026 Hype Cycle for Digital Identity frames governed identities for AI agents — scoped credentials, clear ownership, audit trails — as foundational to scaling agentic AI safely, rather than letting agents inherit reused human logins. That distinction matters inside an ERP specifically. A mis-scoped agent with standing access to financial records carries far more risk than one touching a marketing calendar.

This pattern isn’t unique to finance. Marketing teams building AI-driven approval chains are running into the same wall: permissions, audit history, and approval logic scattered across five disconnected apps instead of living in one governed system. The department changes; the underlying fix stays the same.

The scale of the shift explains why it’s showing up on roadmaps now. Gartner projects 40% of enterprise applications will embed task-specific AI agents by the end of 2026, up from under 5% in 2025. Anyone administering a business-critical system will be governing agent access within a few budget cycles, not eventually.

Governance LayerHuman-Era DefaultAgent-Era Requirement
IdentityShared login, generic roleUnique, scoped credential per agent
Access reviewQuarterly manual auditContinuous, automated check
MonitoringLog review after the factReal-time anomaly detection
OffboardingDeactivate on exitDeactivate on task completion or scope change

The mechanics — role design, least-privilege enforcement, structured onboarding and offboarding for every account touching the system — are the same discipline behind effective NetSuite system administration. They just now apply to a category of user that doesn’t sleep, doesn’t quit, and never asks for a password reset.

The Adoption Gap Is the Risk Window

Most companies aren’t there yet. McKinsey reported in November 2025 that only 23% of organizations have scaled AI agents in even one business function, while 39% are still experimenting.

That gap between experimentation and governed deployment is where exposure builds. A finance team piloting an AI reconciliation tool six months ago may have granted it broad, temporary access to move fast. Nobody has revisited that access since. It’s the same accumulation problem human permissions have always had, just compressed into a shorter timeline with less institutional memory of why the access exists.

Counterintuitively, the companies with the least mature AI governance often carry the most exposed agent permissions. Early pilots get provisioned quickly. They rarely get re-scoped once the pilot proves useful and quietly becomes permanent infrastructure.

Practical Implications for Admins

Fundamentals still hold. Role-based access, two-factor authentication, and IP restrictions form the baseline. What changes is the object being governed, and how often it needs review.

A few adjustments worth making now:

  • Inventory every non-human credential in the system, not just user logins. If an integration or agent can touch records, someone owns it on paper.
  • Shorten the review cycle for machine identities. A quarterly human access review moves too slowly for an agent whose scope can change with a single config update.
  • Log agent actions separately from human ones. Otherwise, anomaly detection gets diluted by normal automated volume.

This kind of shift rarely comes from an IT mandate alone. It tends to follow the same pattern as any structural change inside a business, where organizations grow and change faster than the documentation meant to track them. Governance catches up only after someone asks who actually has access to what.

Closing Thoughts

The agents aren’t going away, and neither is the audit trail question they leave behind. The systems that handle this well aren’t the ones running the most AI. They’re the ones that never stopped asking who’s allowed to touch what — and started asking it about software too.

Related: ERP AI Chatbot in 2026: Architecture, ROI, Guardrails & Real Enterprise Risks

Tags: