Skip to content
CapabilitiesAgent Surfaces
34VERTICAL CONTROLS

SaaS & ERP Agent Security

The platform becomes valuable when an agent’s authority is understandable across the entire business workflow, not just the model API.

Priority
P1
Phase
Phase 2
Primary owner
Integrations / Solutions
Status
Blueprint

Objective

Enterprise value depends on controlling agents where business actions happen: Microsoft 365, Google Workspace, Salesforce, ServiceNow, SAP, Oracle, Workday and financial systems. Build reusable action models instead of isolated point integrations.

What to build

  • Microsoft/Google: email, files, calendars, directory and sharing actions.
  • Salesforce/CRM: customer export, record mutation, bulk communications and permission changes.
  • ServiceNow: ticket/action automation, admin changes and workflow execution.
  • ERP: vendor changes, purchase orders, journal/payment-related workflows and master-data updates.
  • HRIS: employee data access, role changes and exports.

Implementation decisions

  • Start read-only discovery, then introduce selected write/action controls.
  • Map vendor permissions to Agent Trust Cloud canonical actions.
  • Use business-object metadata so policies can reason about amount, customer, vendor or employee sensitivity.
  • Respect vendor rate limits and audit semantics.

Definition of done

  • At least one end-to-end protected workflow exists in each priority SaaS category.
  • The same policy vocabulary spans multiple vendors.
  • Connector outages degrade safely and visibly.

Success metrics

  • Protected SaaS actions
  • Connector health
  • High-risk vendor events
  • Cross-vendor policy reuse

VALUE

The platform becomes valuable when an agent’s authority is understandable across the entire business workflow, not just the model API.

This control is specified on page 34 of the blueprint.