Back to insights
21 September 20266 min readMelverick Ng

AI Agent Identity Is Not Enough: SMEs Need Runtime Authorization

AI agent governance is moving from static access lists to per-action authorization. SMEs need identity, declared intent, scope, approval gates, telemetry, and rollback before digital coworkers act.

Visual concept: AI Agent Identity Is Not Enough: SMEs Need Runtime Authorization within a human-controlled agentic operating model.

ANSWER-FIRST SUMMARY

Key takeaways

Knowing an AI agent's identity is useful. It is not enough to decide whether the agent should be allowed to act.

That distinction is becoming visible in the market. Broadcom's AgentMinder announcement describes checking agent identity, declared mission, intent, context, and current risk before an action reaches an enterprise resource. Genesys has released an AI Control Plane while developing routing and orchestration that use customer intent and context to choose between an agent, workflow, or human. SAS argues that enterprise governance is moving from models and predictions toward decisions, actions, and whole workflows.

The shared signal is clear: governance is moving closer to execution. A register of agents and a static permission list are no longer enough when digital coworkers can interpret a goal, choose a tool, and act across CRM, finance, service, or operations systems.

For SMEs, the answer is not to buy every new control-plane product. It is to adopt the operating principle underneath them: authorize the action, not just the agent.

Identity Answers “Who?”—Not “Should This Happen?”

Traditional access control asks who the user is and which application they may enter. That model assumes a human sits behind the account, understands the current situation, and is accountable for each choice.

An AI agent behaves differently. It can receive a broad objective, assemble context, select tools, and initiate several steps without a person making each intermediate decision. An agent that is legitimately allowed to read customer records for a renewal brief should not automatically be allowed to change prices, send the proposal, or expose the same data to another tool.

Identity is necessary. Runtime authorization adds the missing question: given this agent, this declared purpose, this resource, and this moment, should this exact action proceed?

A Practical Runtime Authorization Stack for SMEs

You do not need enterprise-scale infrastructure to apply the discipline. Start with six layers.

1. Named agent identity and owner

Every production agent needs a unique name, version, business owner, technical owner, and approved environment. “The finance bot” is not an operational identity. “Receivables Follow-up Agent v3, owned by the finance manager” is.

The owner is accountable for the agent's scope, review cadence, exceptions, and retirement. This is the beginning of the Agent Boss role: humans own outcomes and boundaries while digital coworkers execute.

2. Declared intent

Require the workflow to state the intended business outcome before a consequential tool call. Examples include preparing a renewal brief, drafting an overdue-payment reminder, reconciling an invoice exception, or classifying a service request.

Intent is not decorative metadata. It lets the system compare the requested action with the job the agent was commissioned to do. If a renewal agent suddenly attempts to export an entire account database, the identity may be valid while the action is not.

3. Scope-bound permissions

Write permissions as a bounded sentence, not a vague application entitlement:

  • Action: read, recommend, prepare, update, send, approve, or pay.
  • Resource: which records, folders, systems, or accounts.
  • Purpose: which approved business outcome.
  • Limit: value, volume, data sensitivity, customer class, or confidence threshold.
  • Duration: persistent, task-bound, or time-limited.

“Can use the CRM” is not a safe permission. “May read open renewal records for assigned accounts for 30 minutes and prepare a draft brief; may not change commercial terms or send externally” is much closer.

4. Consequence-based approval gates

Autonomy should rise or fall with consequence. Reading an approved knowledge base is different from sending a customer message. Preparing a payment is different from releasing it.

A useful action ladder is:

  • Read: access approved context.
  • Recommend: produce a decision with supporting evidence.
  • Prepare: create a draft message, transaction, or system change.
  • Execute: act only inside explicit thresholds.
  • Escalate: stop when context, policy, or confidence is insufficient.

For an SME, the most valuable control is often simple: let the agent prepare the work, then require a human to approve the irreversible step.

5. Evidence before and after action

Before execution, the agent should present enough evidence for the authorization decision: relevant records, applied rule, detected exception, requested action, and expected outcome.

After execution, record the agent and version, declared intent, data consulted, tool called, permission decision, approver where required, result, error state, and rollback status. A long transcript is not automatically an audit trail. The record must help another person reconstruct what happened.

6. Stop and rollback rules

Define conditions that remove authority: missing mandatory data, conflicting records, an unfamiliar customer type, a value above threshold, a policy mismatch, repeated tool failure, or an unavailable reviewer.

Then define rollback. Can the draft be discarded? Can the CRM field be restored? Can the message be held before release? Can a payment instruction be cancelled? Governance is incomplete when it can say “no” but cannot recover from “already happened.”

Use Telemetry to Improve the Boundary

Runtime authorization should not become bureaucracy that blocks every useful action. Measure it as an operating system.

  • Which actions were allowed, denied, or escalated?
  • How many human approvals changed the proposed action?
  • Which stop condition appears most often?
  • Where are reviewers creating a queue?
  • How many executed outcomes were accepted without correction?
  • How quickly can the team reconstruct and reverse a bad action?

These metrics show whether the boundary is too loose, too rigid, or poorly defined. The goal is not maximum autonomy. It is the highest level of useful autonomy the business can supervise and defend.

A 30-Minute SME Starting Exercise

Choose one agent-assisted action already being considered—sending a follow-up, changing a CRM stage, approving a discount, updating an invoice, or publishing a report. Complete this authorization card:

  • Agent identity and owner: named role, version, accountable person.
  • Declared intent: specific business outcome.
  • Allowed action and resource: verb plus bounded system records.
  • Limits: value, volume, sensitivity, duration, or confidence.
  • Human gate: when approval is mandatory and who provides it.
  • Stop conditions: missing context, conflict, risk, or uncertainty.
  • Audit evidence: what must be captured before and after action.
  • Rollback: how the change is contained or reversed.

If the team cannot complete the card, the agent is not ready for production execution. Keep it in recommendation or preparation mode.

Orchestrate, Don't Operate

The next phase of agentic AI will not be won by the company with the most agents. It will be won by operators who can give digital coworkers useful authority without giving them undefined authority.

That requires more than identity. It requires intent, scope, consequence-aware approval, evidence, telemetry, and rollback—evaluated where the work happens.

The practical rule for SMEs is simple: trust the agent enough to prepare the work; authorize each consequential action before it reaches the business.

Sources

RELATED NEXIUS FIELD GUIDES

Take the concept
into practice.

Continue with implementation-focused guidance from Nexius co-founder Darryl Wong.

AGENTIC SYSTEMS / 9 min read

How to Agentify ERP and CRM Systems Safely

A governed path from read access to approval-gated execution for businesses introducing AI agents into ERP, CRM, and operational systems.

Read field guide
OPERATING MODEL / 8 min read

How to Design Non-Technical Work Loops with AI Agents

A practical method for turning recurring business work into bounded, evidence-driven human-agent loops without giving away human authority.

Read field guide

CONTINUE THE JOURNEY

Related insights

TURN THE IDEA INTO AN OPERATING CAPABILITY

Ready to build your
agentic operating model?

Get the readiness checklist + your recommended next step