Where agentic AI breaks enterprise controls and how to close the gap

hero image
  • July 2026
Andrea Acciarri

Andrea Acciarri

Cyber, Data and Tech Risk - Salesforce Lead, PwC US

Stephen Sullivan

Stephen Sullivan

Principal, Cyber, Data, and Tech Risk, PwC US

Key takeaways:

  • Agent-driven transactions cross platform boundaries, but platform controls don’t.
  • The gap is in the handoffs, where individually authorized actions can chain into risks no single system’s controls are designed to catch.
  • Organizations that close this gap now can help define what audit-ready agentic AI looks like at enterprise scale.

A global technology company deploys autonomous agents across its enterprise stack to accelerate its contact-to-cash cycle and streamline back-office operations. A Salesforce agent qualifies inbound leads, creates opportunities, and generates quotes. When a deal closes, it triggers a handoff to an Oracle agent that posts the revenue recognition entries. A Workday agent automatically onboards new sales hires, updates commission plans, recommends compensation adjustments, and surfaces workforce actions based on sales performance and organizational data. An SAP agent procures third-party services needed for fulfillment.

Each agent operates within its own platform. Permissions are reviewed and approved by the respective platform security team. No single agent has conflicting access. Every access review passes.

For nine months, no issue is flagged—until an internal audit discovers a pattern no control was designed to catch.

As deals closed in Salesforce, the agent chain set other actions in motion. Revenue recognition was posted in Oracle for contracts requiring third-party fulfillment before the related costs were fully visible. Third-party services were procured through SAP, adding fulfillment costs to the transaction. Commission tiers were updated and bonus eligibility accelerated in Workday based on the same transactions.

Each action was authorized when viewed in isolation. But viewed as a chain, the orchestration had created a cycle—deal closure, revenue posting, procurement commitment, and compensation adjustment—without human review of the end-to-end economics of the transactions. In 87 cases, commission payments exceeded deal margin after third-party costs. The company paid more in commissions than it earned.

Why platform controls aren’t enough

Segregation of duty (SoD) controls never flagged the conflict because it didn’t exist within any single system. It existed in the space between Salesforce, Oracle, SAP, and Workday—in the orchestration layer that coordinated them.

No alert fired. No exception report caught it. The pattern surfaced only when a manual margin analysis happened to look across the right data at the right time.

This isn’t a breach or a hack. It’s the normal, intended operation of an agentic architecture that no one thought to govern. The controls didn’t fail. They weren’t built for this.

Enterprise controls were built on three assumptions: Humans performed actions, systems enforced rules, and auditors reviewed logs. Agentic AI breaks all three at once. Platform controls stop at the platform boundary. The transaction doesn’t.

Closing this gap requires controls to follow the transaction, not the platform. As agentic AI scales, trust should be engineered across the full chain of agent activity, with governance that extends to handoffs, interactions, and decisions between systems. Trust AI helps frame this shift, particularly as AI regulatory frameworks worldwide raise expectations for secure and defensible AI.

What does this shift look like in practice?

Key practices for governing agentic AI across platforms

The five practices below address what no platform can see on its own: the full landscape of agents, the handoffs between them, the full transaction chain, and the orchestration layer that coordinates them.

  1. Build a complete inventory of agents. Document every autonomous agent operating across enterprise platforms, including those created by business users through low-code tools that IT may not know exist. Without full visibility, gaps are inevitable.
  2. Make transactions traceable end-to-end. Use shared identifiers and centralized logging to trace agent-executed transactions from initiation to final posting across systems. Without this, audit trails fragment: Each platform records its piece, but no system captures the full chain.
  3. Evaluate segregation of duties across the full transaction chain. Assess the combined actions of multiple agents, not just permissions within individual systems. Conflicts often emerge only when tasks are viewed collectively—across platforms and across agents—rather than within a single application.
  4. Shift from periodic testing to continuous monitoring. Move to ongoing monitoring, broader sampling, and defined thresholds for acceptable variation. Traditional controls can be tested periodically because behavior is stable and rules based. Agents can behave differently across executions when underlying inputs or context change.
  5. Treat the orchestration layer as a critical enterprise system. Apply change management, access controls, monitoring, and expanded audit scope to the orchestration layer that routes tasks, data, and decisions between agents. Govern it with the same rigor as any financially significant system.

These five practices define an approach to governing beyond individual platforms. The next step is to test where governance may need to adapt.

Questions to test cross-platform AI governance

The questions below can help your organization surface gaps between platform-level controls and cross-platform execution.

  • Do we have a complete inventory of every autonomous agent operating across our enterprise platforms, including those created by business users through low-code tools that IT may not know about?
  • Do we understand how each of our enterprise platforms constrains agent behavior differently? Agentforce flow, an SAP Joule agent, an Oracle AI agent, and a Workday Sana agent each expose different telemetry, enforce different guardrails, and create different blast radii. Cross-platform governance only works if it accounts for those differences.
  • If an auditor selected a random agent-executed transaction and asked us to reconstruct the full chain from initiation to recording across all participating systems, could we produce that evidence?
  • Are our segregation of duties controls evaluated at the transaction-chain level across platforms, or only at the individual identity level within each system? Would a composite SoD violation across multiple agents spanning Salesforce, Oracle, SAP, and Workday be detected today?
  • Has our internal audit function changed its testing methodology for controls that behave non-deterministically, or are we still applying point-in-time walkthroughs to AI-powered processes?
  • Is the agent orchestration layer—the software that coordinates agents across systems—included in both our IT general controls (ITGC) scope and Sarbanes-Oxley (SOX) assessment?

If your answer to any of these is “no” or “not sure,” the gap exists today. The question is whether your organization closes it proactively or waits for an auditor to find it.

Bottom line

The space between platforms is where agent-driven transactions cross boundaries, beyond the scope of any single system’s controls or accountability. The risk is in that space — and so is the opportunity. Organizations that govern it now can define what responsible, audit-ready agentic AI looks like at enterprise scale, while protecting the value these systems are designed to create.

Contact us

Stephen D’Arcy

Stephen D’Arcy

Principal, Cyber, Data and Tech Risk, PwC US

Scott  Osterman

Scott Osterman

Partner, Cyber, Data, and Tech Risk, PwC US

Antwon  Hardwick

Antwon Hardwick

Principal, Cyber, Data, and Tech Risk, PwC US

Nicole Pledger

Nicole Pledger

Principal, Cyber, Data, and Tech Risk, PwC US

Follow us