I had one of those moments recently when technology moved faster than the policies I had in place to manage it. An employee wanted to use Claude to help do her job. To do that, Claude needed access to company information through MCP. The request showed up in Microsoft Entra asking for permission to access our SharePoint environment.
And I found myself staring at the screen thinking: What exactly am I supposed to do with this?
My first question was easy. Do I trust the employee? Absolutely.
Then I realized that wasn’t really the question I needed to answer. The better question was: Do I trust the AI agent?
My answer to that was very different. Not completely. And certainly not without governance.
This Wasn’t a Problem a Few Months Ago
This is one of the strange parts about trying to manage technology in 2026. The technology is moving so quickly that the governance problem sometimes appears at your door before you’ve even had time to create a policy for it.
That is basically what happened to me. I wasn’t dealing with a theoretical discussion about AI governance. I had an actual employee trying to get work done. I had an actual AI system requesting access. I had an actual company SharePoint environment containing company information.
And Microsoft Entra was effectively asking me: Allow or deny?
That’s when AI governance becomes real.
I Called the Employee
Before approving anything, I picked up the phone. I wanted to make sure the employee had actually initiated the request.
She had. There was nothing suspicious going on. She was simply trying to use a new productivity tool to do her job.
So I approved the access. But the experience left me thinking about a much larger problem.
Because this isn’t going to be the last request. It’s probably the beginning.
I Now Have Three Different Agent Governance Problems
In my day job, I can already see at least three places where AI agents are entering the company.
The first is our ERP system. Business software vendors are adding AI capabilities and agents directly into their products. Those agents may eventually interact with customers, vendors, inventory, purchasing, accounting, production, sales orders, and other operational processes.
Those agents need governance.
The second is the AI layer we’re building around the company. As we connect AI to company information and business systems, we’ll create our own agents and automated workflows. Those agents may retrieve information, analyze it, recommend actions, and eventually take some actions themselves.
Those agents need governance too.
And now there is a third category: agents brought into the company by employees.
An employee may prefer Claude. Another may use ChatGPT. Another may find a specialized AI product that makes her dramatically better at her job.
That AI may request access to SharePoint, Microsoft 365, an ERP system, a database, or another company resource.
Suddenly the company isn’t just governing the AI it purchased or built. It also has to govern the AI that employees want to bring through the front door.
That is a very different IT environment.
And the Agents Are Becoming More Capable
This problem is going to become more important because AI systems are moving beyond simply answering questions.
ChatGPT Work is a good example. OpenAI describes Work as an agent that can work across apps, files, browsers, and other tools to complete longer tasks. Its cloud browser can operate on supported signed-in websites while the user remains in control of access and important actions.
Think about how different that is from the chatbot we were using only a short time ago.
We aren’t simply asking AI: “What should I do?”
Increasingly, we’re asking: “Can you do this for me?”
That is an enormous change. And it changes the governance problem.
The Question Isn’t Just What the AI Can See
Access is certainly part of governance. What documents can the agent read? Which SharePoint sites can it access? Can it see financial information? Can it see HR information? Can it access customer records? Can it access an ERP system?
But those are only the beginning.
The next questions are even more important. What can the agent do?
Can it create a document? Can it change a customer record? Can it send an email? Can it create a purchase order? Can it update pricing? Can it publish something publicly? Can it move money?
And then comes another question: When does it need a human to approve the action?
That is where I think AI governance is going.
It isn’t simply about access. It’s about authority.
Trusting the Employee Isn’t the Same as Trusting the Agent
This was probably the biggest lesson from my Entra experience.
I trust the employee. But granting an AI system access because I trust the employee isn’t enough.
Those are two different trust decisions.
The employee has a role. She has responsibilities. She understands the company. She has judgment. She is accountable for what she does.
An AI agent is different. It may be extremely capable, but I still need to understand what information it can access, what tools it can use, what actions it can take, and what controls surround those actions.
That doesn’t mean I should automatically deny access.
In fact, I think automatically denying these tools would create a different problem.
Saying No to AI Isn’t Much of a Strategy
Companies could respond to this new risk by blocking everything. No ChatGPT. No Claude. No external agents. No MCP. No connections to company systems.
That might feel safer. I don’t think it’s a very good long-term business strategy.
AI is rapidly becoming a productivity tool.
I think about Excel. There was a time when spreadsheets were a major change in how office work got done. Employees who learned to use spreadsheets could perform work differently and much faster than employees who relied entirely on older methods.
AI is likely to have an even larger effect.
If an employee can use AI to research faster, analyze information better, prepare documents faster, find company knowledge, automate repetitive work, or make better decisions, I want that employee to have access to those capabilities.
The challenge is not figuring out how to stop employees from using AI.
The challenge is figuring out how to let them use it safely.
Governance Has to Catch Up With Capability
This is where I find myself today.
I’m not pretending I have all of this figured out. Frankly, I’m rushing to keep up.
Almost every day seems to bring another meaningful change in AI. New models. New agents. New tools. New connections. New MCP servers. New ways for AI to interact with business systems.
And every new capability can create another governance question.
Technology companies are moving incredibly quickly because they’re competing to build the next generation of computing. Businesses don’t get the luxury of standing still while they do it.
We have to learn while the technology is being created.
I Think Companies Need an Agent Registry
One thing is becoming clear to me.
Companies are going to need to know which agents are operating inside their environment.
That sounds obvious, but consider how quickly this could become complicated. An ERP vendor provides several agents. The internal AI team builds five more. Finance connects an AI tool. Marketing connects another. An employee requests Claude access through Entra. Another employee connects ChatGPT to an approved system.
Pretty soon, somebody needs to be able to answer: What agents have access to our company?
For each one, I want to know: What is the agent? Who owns it? Why does it exist? Which systems can it access? What data can it read? What can it write? What actions can it take? Who approved it? When does it require human approval? Where are its actions logged? How do we shut it off?
That starts to look a lot like an AI Agent Registry.
And I suspect that will become a normal part of enterprise governance.
We May Need to Govern Authority, Not Just Identity
Microsoft Entra and similar identity systems already give companies powerful ways to control access. That’s essential.
But agents introduce another layer.
Identity answers: Who are you?
Permissions answer: What can you access?
Agent governance increasingly needs to answer: What are you authorized to do?
Those are not exactly the same thing.
An agent might be allowed to read customer information but not change it. It might be allowed to prepare a purchase order but not release it. It might draft an email but require a person to send it.
It might identify an accounting exception but not post a correcting journal entry.
That separation between access and authority is going to matter.
Human-in-the-Loop Isn’t the Whole Answer
It’s tempting to solve every agent governance problem by saying: We’ll keep a human in the loop.
That’s useful, but I don’t think it’s enough.
Which human? At what point? Approving what? Based on what information? What happens if the employee simply clicks “Approve” every time because the agent is usually right?
What gets logged? Who reviews exceptions? Who is accountable when something goes wrong?
“Human-in-the-loop” describes part of a workflow. It doesn’t automatically create governance.
Governance requires clearly defined authority, controls, accountability, monitoring, and the ability to intervene.
We’re Building the Rules While the Game Is Starting
That’s probably what struck me most when the Entra request appeared.
There wasn’t anything dramatic about it. An employee found a tool that could help her work. The tool needed access. She requested it. I verified the request and approved it.
But behind that simple interaction was a much bigger change.
An outside AI agent had just asked permission to enter the company’s technology environment and work with company information.
That is going to happen more often.
ERP agents will be inside our systems. Internally developed agents will operate across systems. Employee-selected agents will ask to connect from outside.
And increasingly capable AI systems will be able not only to retrieve information, but to act on it.
The answer cannot be to panic. And the answer cannot be to blindly approve everything either.
We need to learn how to govern this new workforce of digital agents.
The Goal Is Safe Productivity
I keep coming back to the same conclusion.
AI isn’t valuable because it’s fashionable. It’s valuable when it makes people and businesses more capable.
Employees should be able to use good tools. Companies should want them to.
But productivity without governance can create risk, and governance that prevents productivity can destroy much of the value we’re trying to create.
The goal has to be both.
Enable the employee. Govern the agent. Protect the company.
A few months ago, I wasn’t thinking much about an employee’s outside AI agent requesting access to my company’s systems.
Now I’ve already approved one.
That’s how fast this is moving.
And I suspect a lot of companies are about to discover the same problem.
