AI Agent Access Controls Become Critical as Enterprise Automation Scales
### AI Agent Access Controls Need a New Model
AI agent access controls are becoming a priority as enterprises move from experimentation to deployment. In this Techstrong.ai Leadership Insights episode, Mike Vizard and Tony Grout, Chief Product and Technology Officer at M-Files, examine why unmanaged agents can create unexpected security, data, and workflow risks.
Grout compares an AI agent to a smart new employee who has not yet learned the business. The agent may have broad intelligence, but it does not understand context, priorities, or policy boundaries unless those limits are designed into the environment. That makes access control, training, and supervision essential.
### Legacy Data Problems Surface Quickly
The conversation explores how AI agents expose hidden complexity across IT environments. Agents can discover relationships, dependencies, and backend systems that humans may overlook. That weakens older approaches that relied on security through obscurity.
AI agent access controls must also account for long-standing data management issues. Grout notes that concepts such as master data management and single sources of truth are becoming relevant again. If organizations do not address data quality and ownership first, agent deployments can reach the “trough of despair” quickly.
### Deterministic Workflows Still Matter
Grout also explains why deterministic workflows remain important. Many business processes are designed to run the same way every time. AI agents are probabilistic, so they may not repeat the same steps twice. Enterprises need to decide where creativity is useful and where standard operating procedures should remain in control.
One practical approach is to combine deterministic workflow logic with non-deterministic AI actions. The workflow can define the guardrails, while the agent performs a specific activity inside those limits. The system can then check whether the action met the required criteria.
### Accountability, Auditability, and Oversight
The episode also covers agent-to-agent conflict, arbitration layers, auditability, and rogue agent behavior. As companies deploy more agents, they will need automated permission models that can keep pace with agentic speed. They may also need anomaly detection and human escalation when risk increases.
For IT and security leaders, the message is clear. AI agent access controls should be planned before agents spread across the enterprise. Strong permissions, audit trails, orchestration, and human oversight will help organizations scale automation without losing control.
Transcript
ai Leadership Insight Series. I'm your host, Mike Bizos. Today, we're with Tony Grout, who is Chief Product and Technology Officer for M-Files, and we're having a chat about, well, AI agents.
Tony, welcome to the show. Thanks very much, Mike. Pleasure to be here.
I think one of the things that people are doing is they're deploying AI agents, and a lot of them are, shall we say, unmanaged and untrained, and then they're surprised when bad things happen. So, from your perspective, is there a smarter way of thinking about all this and what's going on? Yeah.
I think there's a lot of excitement about the art of the possible, and we're seeing a lot of people doing really cool things. I think the simplest way I think that's helpful for most people, especially in business, is to think about an agent as a really smart but not fully informed employee that's just joined. I think that's a really helpful starting point.
You've hired somebody with a lot of foundational intelligence. They don't really know your business. They know all the names of things, but they don't know what's really important to you.
They don't know where the edges are of your security policies and all those kind of things. So I just think about them as a really starter employee. To your point about that, though, those starter employees lack the scruples that a normal human might bring to an equation, and they are inclined to try to do everything and anything to accomplish a mission assigned to them, regardless of whatever red flags might've been put in place.
So do we need to rethink maybe some of the controls and safeguards we're putting in place before we roll out these AI agents because, well, they do what they do? Yeah. I think, again, I'm going to keep pulling on the analogy a bit.
I think you've got to give them access to the things that they should have access to and not give them things, the things they shouldn't have access to. And that's much harder these days because the agents can... It's so much harder to work out what they do have access to and what they don't.
With employees, it's normally done through user experience of some description. You can create much easier access controls in the applications. It's sometimes difficult to work out what the agents can and can't see, which is why you need much more thought about security around those things.
To your point about that, is this just highlighting that maybe there's too many dependencies in our IT environments, and they're too complex, and there's all these relationships on backend systems that normal humans don't see, but AI agents discover in a couple of seconds? Yeah, for sure. I think it is much easier for an agent to discover things that we've got away.
We've kind of had security through obscurity. So they've become so obscure that nobody can find them anywhere, and we've just relied on that, and now we can't do that. I think this is surfacing a lot of that concern, and I think our IT organizations are going to be forced to just put more rigor around things like APIs, are going to have to be all much more tested.
The great thing is, though, Mike, you can use AI to do that, and I think that's what we also have to be aware of. Use the system to fix the system, basically, is also helpful. In a lot of ways, are we exposing data management issues that we've kind of ignored for decades, but now they're all coming full circle to smack us in the head because the AI agents are turned loose, and they're discovering all these issues that either we've known or ignored?
Yeah. I think many of us who have circled around, I've been around a while in technology, and many of us will smile when we hear the concept master data management, for example. How many organizations have been smashing their head against the wall on that for 20 years?
" You can also start thinking about how I can help you do that, but you've got to sequence it in the right order. You can't throw out AI everywhere and then fix the problem. " is going to be important.
And I think the organizations are experimenting. I think a lot of them reach the trough of despair just because they've sequenced it in the wrong order. To your point about that, a lot of the workflows that businesses have are deterministic in the sense that they're supposed to be done the same way every time.
And an AI agent, being based on an LLM, is probabilistic and never does the same thing the same way twice. So- Yeah ... is this kind of creating some sort of mismatch between what the technology does and the workflows that we're trying to use it in?
I think that's a great point. I think we have to be much more thoughtful about when deterministic is still the right answer. In many occasions, in my organization, we deal with a lot of companies who are doing highly regulated activities, and you create standard operating procedures because it's the proven way of getting the job done, and you don't want somebody making it up.
So you've got to work out where you want innovation and creativity and where you want just standard ways of working. So I think standard operating procedures and putting guardrails around the AI is going to be important. So for example, what we use at the moment is, we have the ability to do workflows, but the workflows themselves are deterministic, so it's if this, then do that.
But the activities inside of the workflows are non-deterministic, so we can go and make some action, but then they come back to a deterministic workflow that can then check, did what just happened actually meet the criteria we set to validate it's just happened? So I think we're going to have to decide when do we want creativity? When do we want determinism?
And when do we want a mixture of the two that we can check one versus the other? Also, a lot of these AI agents are being deployed within the context of a particular business unit. But- Yeah ...
if you've worked in any kind of large organization, you realize that there is tension between business units, and sometimes they have competing agendas. And we're starting to see now when I deploy an AI agent in one department and it encounters an AI agent in another department, the two don't always play nice. Sometimes they try and undermine each other, just like humans.
So, do we need to kind of think through that relationship between those AI agents as well? Yeah, and I think it's interesting, actually. I think in some ways, I think we are going to step back to having some form of, in the old world, we'd have had enterprise systems, the ESPs, enterprise systems bus.
I think we need an enterprise agent arbitration layer that literally can be an escalation path when two agents can't agree that either another agent, a judgment agent, is helping them work it out because it has a high visibility and policies that will help it do that, and/or it might need to bring in play a human if the risk profile of the reason they can't agree is so great that there's material risk that needs a human pulled in. Because ultimately, a human is still going to be accountable. So I think we're going to have this, some form of arbitration layer above just the individual agents, and then we're likely to have a human in the loop somewhere for the things that are material.
I suspect there's going to be something like that increasingly true. When you put all that together, are we kind of in danger, or maybe we're already past that point, but it feels like the cart's before the horse. We've deployed the AI agents, but we don't have the orchestration layer and the negotiation layer in place that you described.
And so is there just going to be chaos ensuing until we figure all this out? Or how do I manage this workflow and this, shall we say, irrational AI agent exuberance? So what I'm currently seeing when I talk to our customers, and it's interesting, I think in the last six months has been so much more- serious thought coming into our customer sets about how they want to do things.
" So I think some of them have played the experiment, Mike, and they're swinging back to locking it all down. And now I'll have to go back around and work out what I am going to allow them to do. And that unfortunately can take a lot of the energy out of the room at the same time of what the creativity could be.
So I think we need to rely on some of the organizations that are doing some more interesting things, like the likes of Microsoft with some of the work they're doing, where they're able to go back around and harvest all the agents. " And that's when they started to build this layer of orchestration and monitoring of agents, so they could actually monitor them. So I think we're going to go from, I think you can see us swinging back to organizations wanting more control as they get further down that continuum.
There's a lot of talk about the ROI benefits of the investments in AI agents and the cost and everything that goes with that. And while I believe that that is a legitimate concern, I also have to wonder if it's kind of maybe besides the point, and I say that from this regard. It's like AI agents at some point real soon are just going to be table stakes.
You kind of have to have them, and you might not be able to create a sustainable competitive advantage because you deploy them, but if you don't deploy them, you will certainly fall behind. Is that kind of where we are? Yes, I think so.
I think the age of deciding are we or are we not is gone. It's just how do you make them more effective more quickly for your organization, mostly. I think customers who, and certainly in the industries we deal with, where they, again, they deal with enormous pieces of machinery that make the world move.
They are deploying agents. " The time's gone, Mike. I think if you're not there already, you need to get on that bus pretty quickly.
" I think it comes back to some of the things you mentioned at the start, Mike. One is, it's rolling out technology and hoping it just works. And so the thing that makes me smile the most is this is not a technology problem.
It's a human change problem as most of the time these things are. And so I think what I see a lot of organizations doing is there's still a lot just throwing AI out there and not quite understanding how to prioritize where AI can add value at first and where it's going to just create chaos. And there's other organizations who are just with their heads in the sand, doing so little, but trying to check a box to say they've got AI, that actually they're getting nowhere.
And I think both of those are going to cause chaos, and I think you need a structured plan. Like where is the value add going to come in soonest? For example, that's what we're doing at M-Files.
Every single function has looked at where our AI can add most value, and we can manage the risk profile. And which sequence do we build those things in, and how do they connect together? There is a lot of these AI agents are showing up in what I might describe as highly regulated industries, although I'm hard-pressed these days to find an industry that's not regulated.
But the point being is, will it not be a matter of time before auditors, armed with their own AI agents, show up and start scanning these environments for things that AI agents are doing and start handing out fines left and right? I think you've got to be prepared for that as soon as possible. It's one of the things that I think the auditability of what agents are doing is going to be a fundamental step in us trusting AI for the first point, and secondly, us keeping ourselves personally out of prison because we've told an AI agent to go do something it shouldn't have done.
So I think you're right, Mike. I think auditability now of what agents are doing and the impact they're having with the decisions they're making is going to be key. I think the irony, though, Mike, I would say there's a little bit of an irony here that I always smile when I think about decision-making and auditability.
So many decisions, really important decisions, are made in a lot of organizations are never written down as actually a formalized decision with an audit trail behind them. It's tacit information made in a boardroom or in a corridor somewhere, and then we go and execute it. The interesting thing now we have agents is, now there's the ability to hold agents accountable, and we should just do that.
But I also think we need to look at how we as humans are also thinking about that. Because one of the reasons for that is if we're not recording the decisions we are making and how they are changing things and the outcomes of those, how does the AI agent learn to do what we would like it to do based on how we think about how those problems should operate? So I think we are also going to be expected to also record our decisions in a more structured way, so the agents can learn.
Aren't we assuming a level of risk then? Because you've already seen stories about how certain AI agents went rogue, and rogue is an interpretation, but basically, they moved beyond the scope of the original mission. That seems likely to happen.
So how do I prepare for that as a business? Because at some point, some percentage of my AI agent projects are going to go rogue. Again, I think there's a lot we can learn from a rogue employee.
However, you've got thousands of them who are unintentionally going rogue, and so I think it's as much a scale challenge as a new challenge, honestly. In most organizations, there's been some purposely rogue or accidentally rogue individual who's overstepped. And the way you typically do that is you have management oversight, or you may, again, have security policies and access controls in place to do that.
And I think the key thing for me right now is to make sure you've got at agentic speed, your access controls, security policies, and permissions are automated enough to be able to keep up with the agents. So you are really going to have, for example, we've fortunately got a very dynamic access control system in our product that literally can keep track of, given the state of a particular piece of information, the access control can change based on the state of the piece of work. Because you may want an agent to see something in this, like when it's going through a particular procurement process.
You want the agent that can check the legal contract to see it all the way through, but you don't want every agent to see that contract all the way through its workflow. And so you need to have these dynamic permissioning models ultimately that will keep pace at agent pace and be, again, highlighting up to some sort of layer above when that agent is going rogue. So I think we're going to have agentic quality police, if you like, sitting across the top, but monitoring the system and highlighting anomalies, basically.
There'll be anomaly detection, Mike, with agentic over time. Seems a bit wild, but I can imagine a world where that's the only way we're going to solve it, in my mind, is having AI help us solve it. All right.
Folks, you heard it here. AI agents, they're here to stay, but any HR executive you talk to will tell you that the more intelligent an employee is, the more difficult they are to manage. Now, think about this when you start deploying thousands of AI agents that are really super smart and work backwards from there.
Hey, Tony, thanks for being on the show. No worries. Thanks so much, Mike.
Thank you. All right. AI Leadership Insight Series.
You can find this episode and others on our website. By all means, check those out. Until then, we'll see you next time.