CapabilitiesAgent Surfaces
34VERTICAL CONTROLS
SaaS & ERP Agent Security
The platform becomes valuable when an agent’s authority is understandable across the entire business workflow, not just the model API.
- Priority
- P1
- Phase
- Phase 2
- Primary owner
- Integrations / Solutions
- Status
- Blueprint
Objective
Enterprise value depends on controlling agents where business actions happen: Microsoft 365, Google Workspace, Salesforce, ServiceNow, SAP, Oracle, Workday and financial systems. Build reusable action models instead of isolated point integrations.
What to build
- Microsoft/Google: email, files, calendars, directory and sharing actions.
- Salesforce/CRM: customer export, record mutation, bulk communications and permission changes.
- ServiceNow: ticket/action automation, admin changes and workflow execution.
- ERP: vendor changes, purchase orders, journal/payment-related workflows and master-data updates.
- HRIS: employee data access, role changes and exports.
Implementation decisions
- Start read-only discovery, then introduce selected write/action controls.
- Map vendor permissions to Agent Trust Cloud canonical actions.
- Use business-object metadata so policies can reason about amount, customer, vendor or employee sensitivity.
- Respect vendor rate limits and audit semantics.
Definition of done
- At least one end-to-end protected workflow exists in each priority SaaS category.
- The same policy vocabulary spans multiple vendors.
- Connector outages degrade safely and visibly.
Success metrics
- Protected SaaS actions
- Connector health
- High-risk vendor events
- Cross-vendor policy reuse
VALUE
The platform becomes valuable when an agent’s authority is understandable across the entire business workflow, not just the model API.
This control is specified on page 34 of the blueprint.