The Cage Was the Screen
Software relies on human friction to enforce rules, but AI doesn't. Discover why automated authority is failing—and how to fix it before it breaks.
Yasmeen Ahmad
SVP and General Manager, Workday Data Cloud
Workday
Software relies on human friction to enforce rules, but AI doesn't. Discover why automated authority is failing—and how to fix it before it breaks.
Yasmeen Ahmad
SVP and General Manager, Workday Data Cloud
Workday
For 30 years, the enterprise software industry enforced its most important rules in the least durable place available: the user interface.
Think about what actually stopped a bad transaction in 2015: a grayed-out button, a dropdown with only the legally approved options, a form that required a second approver, a field that turned red in one country and stayed white in another.
We told ourselves compliance lived in the system, but it mostly lived in the screen. And, the screen worked because a human being had to look at it.
Agents don't look at screens.
That's the whole problem. And it explains why so many architectures are snapping right now.
When an agent operates behind the interface, it bypasses more than a cosmetic layer. It bypasses the place where a great deal of business context and operational logic have quietly been living.
Agents don’t look at screens.
Report
This is why I'm skeptical of the current trend for context layers.
A layer that describes your rules to a model is not the same as a system that enforces them. A definition tells an agent what a retention bonus is. It does not stop one from being paid out of the wrong budget.
The shift I'm arguing for isn't better documentation—it's putting the enforcement back in the path, so an agent has to adhere to the rule rather than read about it.
This is solvable. It takes work, but it's engineering, and the industry is already moving on it. From governed tool boundaries and protocol access into live systems, to permissions evaluated at the moment of action rather than looked up in advance—I'm confident we'll get there.
What I'm less confident about is the second thing the screen was doing, which almost nobody is talking about.
The screen didn't just enforce rules. It put a person in the room.
Every consequential action in the old model had a human who loaded the page, read the number, and clicked. That process was slow and imperfect, but it demanded human presence. And, that presence carried an enormous amount of governance we never wrote down.
The screen didn’t just enforce the rules. It put a person in the room.
Consider how delegated authority has actually been maintained inside companies. Not well. Managers grant approval rights and forget. Scopes drift. People end up able to sign off on things nobody consciously decided they should own. But, it mostly worked anyway, because human delegation cleans itself up.
People leave, and leaving triggers a review. People get promoted, and someone rewrites the job description. People delegate poorly, and, in the handover,somebody finally asks why certain approval rights exist. People notice when a policy changes. They get uneasy. They escalate because something feels wrong, even when they can't explain why.
None of that is a true guardrail. It's turnover, friction, and mild anxiety. It has been doing the work of governance for decades and we never gave it credit.
Agents have none of this accidental governance
An agent doesn't leave. It never gets promoted out of the role. It doesn't delegate, so it’s never forced to explain what it does. It doesn't notice the policy changed. It doesn't feel uneasy. It never escalates because something seems off. It does exactly what it was authorized to do, at three o’clock in the morning, for as long as we let it.
We've removed the enforcement layer and the self-cleaning mechanism. What we've put in its place is a log.
Agents have none of this accidental governance.
Every governance framework I've read this year treats authorization as an event. Was the agent approved? Is it monitored? Is there an audit trail? All necessary, all shaped around a single moment in time.
But an agent's behavior doesn’t last a moment. It's ongoing.
Authority that was correct the day it was granted decays over the months that follow, as policies shift, as the business reorganizes, as the person who granted it moves on. Nothing registers that decay, because from the system's point of view nothing has changed. The approval is still there. It's still valid. It just no longer means what it meant.
Which brings me to the question I can't get past: When an agent gets a big decision wrong, who is to blame?
Approval means something is allowed, whereas accountability is about who is on the hook to explain why. We keep building the first and calling it the second.
And here's what makes that dangerous rather than merely sloppy: accountability that isn't assigned doesn't disappear. It settles on whoever is standing closest when the failure surfaces. Usually that's the operator who ran the process, not the executive who authorized the agent or the vendor who built it. We are quietly constructing a world where the person with the least say carries the most exposure, and calling it automation.
A single approval is easy, and we solved it decades ago with a name, a date and a limit. The hard case is permission that never ends. Someone signs off on an agent to run reconciliation continuously, but 18 months later it acts under conditions nobody imagined, on a policy that's changed twice since, approved by a manager who left the company. The authorization is still valid. The accountability evaporated somewhere along the way, and nobody noticed until something broke.
We are quietly constructing a world where the person with the least say carries the most exposure, and calling it automation.
Authorizations for agents should expire on their own.
Give every standing delegation a hard end date—90 days for anything touching money or people, a year for lower stakes work. When it lapses, the agent stops taking on new work and finishes what it has in flight.
Renewal shouldn't be a click. It should take a named person confirming that they still understand what the agent is allowed to do, that the policies underneath it haven't shifted in ways that matter, and that they're willing to put their name on the next 90 days. If nobody wants to be accountable, you've learned something worth knowing.
I know the objection because I've made it myself. A reconciliation agent that halts on a Friday because a credential lapsed is its own kind of incident. That's fair. But an agent running for two years on nobody's authority is a problem you find in a deposition.
We already accept this trade-off in security, where certificates expire and access reviews force recertification and occasionally something breaks because somebody didn't renew in time. We accept it because the alternative is credentials nobody can account for piling up for years.
An agent deserves the same treatment and for a stronger reason: an agent doesn't just hold access, it acts on it.
A permission expiration date isn't really the point, though—renewal is. The value is in manufacturing the moment that used to happen by accident, when somebody left a company and somebody else had to ask why they are the decision maker. We are going to have to build that moment deliberately now, because nobody is going to stumble into it.
None of this is fully solved, and I'd rather say that plainly than pretend otherwise. It's worth answering a hard question before the end of the year: for every agent you have running, can you name the person whose authority it's acting on and whether that person would still say yes today?
Most companies can't answer the first part. Almost nobody can answer the second.
Report