Enterprise AI agent adoption is constrained by permissioning and governance
Most discussions about enterprise AI focus on model performance. That is becoming the wrong question. Today’s leading models are already capable of understanding language, reasoning through tasks, and generating useful responses. The real constraint is whether an AI agent has the authority to act inside an organization.
Every enterprise eventually reaches the same point. An AI agent can answer a question, but can it approve a purchase? Can it access payroll information? Can it update a customer record? Can it do those things only for the people it is authorized to represent? Without reliable answers, the technology stops at the pilot stage instead of becoming part of daily operations.
This is where Workday is focusing its strategy. Instead of treating AI agents as separate applications, the company is positioning its existing system of record as the governance layer. That means identity, permissions, approvals, and security remain connected to the same business data that employees already trust. Rather than creating another security model, Workday extends the one enterprises have already built.
This approach also addresses a common mistake. Many organizations assemble AI solutions by connecting foundation models directly to enterprise data. The model may generate impressive responses, but if it ignores detailed approval rules, role-based permissions, or organizational hierarchies, it can expose information or perform actions beyond what users should be allowed to do. Strong AI capabilities cannot compensate for weak governance.
For executives, this shifts the investment decision. Competitive advantage will increasingly come from operational trust rather than incremental improvements in model quality. Organizations that can verify identity, enforce permissions, and maintain complete auditability will be able to deploy AI agents across finance, HR, procurement, and other sensitive functions with much greater confidence. Governance becomes an enabler of scale.
Gerrit Kazmaier, President of Product and Technology at Workday, described this challenge directly. He said, “Sana makes sure the integrity of the approvals and security model is always adhered to.” He also noted that organizations building do-it-yourself AI by simply accessing raw data often lose the richness of their security model, causing AI outputs to become “overly broad.” His point reflects a broader enterprise reality: AI systems must inherit business controls instead of bypassing them.
High accuracy in AI for HR and finance requires a multi-layered approach
Accuracy becomes much more demanding when AI moves from generating information to executing business processes. In HR and finance, a small error is not simply an incorrect answer. It can result in an incorrect payroll payment, an inaccurate financial close, or a scheduling mistake that disrupts operations.
Traditional AI benchmarks do not fully measure this challenge. Enterprise decisions depend on policies, reporting structures, compliance requirements, historical records, and constantly changing organizational relationships. A model may produce a response that appears reasonable while still violating an internal approval process or company policy. For business-critical workflows, that level of error is unacceptable.
Workday addresses this by combining multiple layers instead of relying only on a large language model. Google Gemini provides the reasoning capability, while Workday adds business context, workflow logic, verification systems, and classification models that review outputs before actions are taken. This creates an additional control layer designed to validate whether an action should happen.
This reflects an important shift in enterprise AI architecture. Success is no longer determined only by the intelligence of the underlying model. It depends on how effectively that intelligence is constrained by verified business rules, organizational context, and operational safeguards. Companies that invest in these supporting layers are likely to achieve higher reliability and lower operational risk as AI adoption expands.
Executives should also recognize that accuracy is closely connected to trust. Employees will only delegate meaningful work to AI agents if they consistently produce correct outcomes. Confidence builds gradually but can be lost after only a few high-impact mistakes. Organizations therefore need governance, verification, and monitoring to evolve alongside model capabilities rather than treating deployment as a one-time project.
Gerrit Kazmaier, President of Product and Technology at Workday, summarized this expectation clearly: “Almost right is not acceptable.” He specifically pointed to processes such as paying employees correctly, closing financial books, and managing work schedules, where even small errors can create significant operational and financial consequences.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Identity and permissions are central to trustworthy AI agent behavior
Enterprise AI becomes significantly more valuable when it can take action instead of simply providing information. That transition depends on one fundamental capability: the system must know exactly who is making the request and what authority that person has. Without verified identity and permissions, every action introduces unnecessary risk.
Workday argues that identity and accuracy are closely connected. An AI agent cannot determine the correct action unless it understands the user’s role, reporting relationships, approval authority, and current permissions. These details change over time as employees move between teams, receive promotions, or take on new responsibilities. AI systems must continuously operate with the latest organizational context rather than relying on static access rules.
This is where a system of record provides a significant advantage. Workday already stores organizational structures, employee roles, and business relationships for many enterprises. According to the company, the Sana Self-Service Agent uses Google Gemini as the conversational interface, while authentication and authorization are handled through Workday’s existing identity and security model. The agent only performs actions that the authenticated user is already permitted to perform under current company policies.
This design also strengthens accountability. The conversational interaction takes place through Gemini, while the primary audit trail remains inside Workday and under the customer’s control. That distinction is important for organizations operating under strict compliance requirements. Every action can be traced back to an authenticated user and verified against established governance policies.
For executives, this highlights a broader strategic issue. AI governance should not be treated as a separate security project after deployment. Identity management, authorization, auditability, and business context should be integrated into the AI architecture from the beginning. Organizations that make these capabilities foundational will be better positioned to expand AI into increasingly sensitive business processes while maintaining operational control.
Gerrit Kazmaier, President of Product and Technology at Workday, explained that the Sana Self-Service Agent uses Gemini as the conversational layer, while Workday authenticates users and enforces permissions through its existing identity and security framework. As a result, Sana agents act only on behalf of authenticated users and remain within their authorized permissions.
Embedded governance within the system of record is essential in regulated environments
As AI agents become capable of completing business tasks independently, governance becomes a core operational requirement rather than a compliance exercise. Organizations in regulated industries cannot rely on AI systems that operate outside established security controls. Every action must be transparent, authorized, and traceable.
Permissions should remain inside the system that manages the organization’s authoritative business data. Separating governance from the system of record creates gaps between business policies and AI behavior. Those gaps increase the likelihood of unauthorized access, inconsistent decisions, and compliance failures.
This challenge becomes more significant as enterprises deploy multiple AI agents across different business functions. Each agent may interact with sensitive employee records, financial information, procurement systems, or customer data. Without centralized governance, organizations face increasing difficulty in monitoring what agents are doing, who authorized those actions, and whether those actions comply with internal policies and external regulations.
Strong governance also improves scalability. Enterprises that establish clear ownership, standardized permission models, and comprehensive audit trails can expand AI deployments with greater confidence. Instead of evaluating every new AI use case from the beginning, they can extend an existing governance framework across departments while maintaining consistent security and oversight.
Business leaders should view governance as a competitive capability rather than an operational burden. Regulatory expectations continue to evolve, and customers increasingly expect organizations to demonstrate responsible AI practices. Companies that embed governance directly into their core business systems will be better prepared to meet both business and regulatory demands as AI adoption accelerates.
Dan Obendorfer, Director of Product at Würk, reinforced this position, stating, “It has to live in the system of record, that’s not a preference, that’s the only way it works.” He added that if permissions are defined outside the system where the data resides, organizations have already lost control of the security model.
Kadan Stadelmann, Chief Technology Officer and Co-founder of Compance.AI, reached a similar conclusion. He warned that without clear ownership of AI agents and visibility into their performance, costs, and actions, organizations risk operational chaos. His comments emphasize that governance must extend beyond access control to include accountability, monitoring, and lifecycle management for enterprise AI agents.
Workday expands its AI ecosystem through enhanced integration with Google Gemini
Enterprise AI is moving beyond isolated applications. Organizations increasingly expect AI systems to operate across multiple business functions while maintaining consistent security, governance, and user experiences. That requires technology providers to build platforms that integrate with established enterprise ecosystems rather than operating independently.
Workday’s expanded partnership with Google reflects this direction. After launching its Sana agent system of record in March, the company announced that Sana will integrate with Gemini Enterprise, making Sana-based AI agents discoverable within Google’s enterprise AI environment. The objective is to combine Gemini’s reasoning and conversational capabilities with Workday’s governance, identity management, and workflow controls.
This integration reflects an important architectural principle. Foundation models provide broad reasoning capabilities, but enterprise value comes from combining those models with trusted business systems that understand organizational structures, permissions, business processes, and compliance requirements. By connecting these capabilities, organizations can deploy AI agents that are both intelligent and aligned with existing operational controls.
For business leaders, partnerships of this kind reduce the need to choose between innovation and governance. Organizations can adopt advances in foundation models without rebuilding identity systems, security policies, approval workflows, or audit processes. Existing enterprise controls remain in place while AI capabilities continue to improve as newer models become available.
The broader implication is that enterprise AI platforms are becoming increasingly interconnected. Companies are unlikely to standardize on a single AI provider or application. Instead, they will build environments where multiple AI services work together while relying on a common governance framework. Vendors that can integrate effectively into these ecosystems are likely to become more valuable partners as enterprise AI adoption expands.
Key takeaways for leaders
- Prioritize governance before model upgrades: Enterprise AI is increasingly limited by identity, permissions, and approval controls rather than model performance. Leaders should strengthen governance within existing systems of record to enable AI agents to act securely at scale.
- Treat accuracy as a business requirement: In HR and finance, even minor AI errors can create significant operational and compliance risks. Combine foundation models with business context, verification, and workflow controls before allowing agents to execute critical tasks.
- Build AI on trusted identity and access controls: AI agents should inherit existing user permissions and organizational context instead of operating with separate access rules. This improves security, accountability, and auditability while reducing the risk of unauthorized actions.
- Embed governance into enterprise architecture: Permission management, audit trails, and agent oversight should reside within the system of record, particularly in regulated industries. Leaders should establish clear ownership and monitoring for AI agents before expanding autonomous workflows.
- Favor AI platforms that integrate with enterprise systems: Partnerships such as Workday’s integration with Google Gemini demonstrate that long-term value comes from combining advanced AI models with trusted enterprise governance. Invest in platforms that can evolve with new AI capabilities without weakening security or compliance.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


