Intelligence

Enterprise Adoption

How organisations are actually deploying agents, and what breaks once the deployment leaves the pilot. Procurement, review capacity, on call, audit and the operational cost of oversight.

Foundational reading

24 pieces
14 August 2026

Your AI Agent's Permissions Did Not Change. Its Authority Still Did.

Google announced Gemini 3.7 Flash on 13 August 2026 and said Gemini Spark would start using it the same day. Google describes better multi step planning, better tool calls, better recovery from roadblocks, fewer retries and less manual oversight. Spark's permission surface, the connected apps, the local and remote browser, the confirmation prompts, is unchanged. That is the part worth thinking about. Effective authority can move without a single permission being edited.

Agent Authority22 min read·Moona Intelligence

More in this topic

28 August 2026

CEOs Own the AI Budget. Who Owns the Agent's Actions?

A LinkedIn post citing a 72% figure and an unverifiable 14% figure sent me looking for the research behind it. BCG's AI Radar 2026, a survey of 640 CEOs among 2,360 executives across 16 markets and nine industries, is the real source of the 72% figure. The same survey shows CEOs committing over 30% of 2026 AI investment to agents, and its most aggressive adopters already running agents end to end. Nowhere in it does anyone ask who authorizes what one of those agents is actually allowed to do.

Agent Authority6 min read
28 August 2026

Drata Used to Help You Prove the Control Existed. Now It Wants to Enforce It Before the Agent Acts.

On 4 August 2026, Drata opened Limited Availability for AI Agent Governance, a product built on three components it calls Sensor, Mission Control and Chain of Custody. Drata's own material states that Mission Control evaluates every agent action against approved policy in real time and blocks violations inline, before they execute, using policies a team writes in plain English and Drata compiles into enforceable rules. The release covers agents running on Anthropic today, with OpenAI, Google Vertex AI and AWS Bedrock described as in active development. Drata is a compliance evidence company. What it just tried to ship is not another audit report. It is a claim to sit at the moment an agent is about to act and decide whether it may.

Agent Authority12 min read
28 August 2026

The Employee Can Open the File. Somansa Says the Agent Still Might Not Be Allowed To.

Korean trade press reported on 26 August 2026 that Somansa had launched Privacy-i AIDR, an addition of AI agent detection and response to its existing endpoint detection and response product, built to find so called shadow AI agents installed on employee machines without company approval. The reported core claim is that an administrator can restrict, by business purpose, which files, programs and system permissions an AI agent may use, distinct from the human account it runs under. Somansa says the product is being validated through proof of concept work in large enterprise environments and plans a next generation version in the fourth quarter of 2026. Moona Intelligence verifies the launch chronology, states exactly what is and is not documented about agent identification, permission scope, enforcement order and audit evidence, and narrows every claim this record could not independently confirm.

Agent Authority19 min read
26 August 2026

Ask DataHub Requires Human Approval. One Setting Decides Whether It Still Does.

DataHub Cloud v2.1 made Ask DataHub generally available on the strength of one claim: the chat agent pauses for human in the loop approval before applying a metadata edit on the web. DataHub's own release notes document the control underneath that claim directly, an environment variable called DATAHUB_AI_TOOL_APPROVAL_ENABLED, default true, re read per chat turn, that switches every mutating tool from paused to auto applied. Moona Intelligence reads that as two separate authority questions stacked on top of each other. The first is whether one write gets a human's yes. DataHub answers that one. The second is who is allowed to decide that future writes stop needing a yes at all, and on the evidence available, that decision sits outside anything DataHub's own permission model documents.

Agent Authority11 min read
25 August 2026

Your Admin Can Change It. Does That Mean Their AI Agent Should?

OpenAI's 25 August 2026 announcement describes an Admin plugin that lets a workspace administrator review activity and credit usage, add or remove members, update groups, adjust usage limits and approve or deny spending requests, entirely from a ChatGPT Work or Codex conversation. The plugin's own documented boundary is that it operates within each user's existing role and permissions, does not grant broader access, and maps administrator instructions to supported read or write actions. OpenAI describes pending usage requests routed to Slack or Microsoft Teams for an authorized reviewer to approve or deny, feature access requests granted automatically when predefined criteria are met with exceptions routed for review, and broader impact changes admins can review before they are applied. Moona Intelligence verifies that architecture against OpenAI's supporting plugin and admin control documentation, and separates four things this record keeps distinct: the administrator's own workspace role, the workspace's decision to install and configure the plugin and its underlying app, the specific operations the plugin currently supports, and the review step that applies to some of those operations and not others.

Agent Authority16 min read
25 August 2026

If You Can Do It in Salesforce, Your AI Agent Can Do It Too

Salesforce's Headless 360 MCP Server has run in open beta since July 2026, and a 19 August 2026 expansion, republished to Salesforce's Asia Pacific newsroom on 25 August, layers new Data 360, Slack and skills capability around it at varying maturity levels. The server's own documentation states plainly that every transaction executes as the authenticated user, scoped through an External Client App carrying a dedicated mcp_api scope, with object permissions, field level security, sharing rules, profile permissions and permission sets all applying before the Dispatch tool is allowed to run. If a person cannot perform an action in Salesforce, their agent cannot perform it through the MCP server either. Moona Intelligence verifies that claim precisely, narrows what inherited trust actually composes to, and finds a real, working boundary for technical permission sitting directly beside an undocumented one for organizational mandate: nothing in the architecture establishes that a user who can deactivate a colleague, deploy an Apex trigger or assign a permission set was ever asked whether an AI agent should be allowed to do the same thing on their login. Updated 28 August 2026 with Salesforce and Anthropic's 26 August 2026 Claudeforce announcement: Salesforce in Claude, a Plugin shipping to pilot customers with 37 prebuilt sales skills, calls the same Salesforce MCP architecture this record already verified, with Salesforce's own language stating explicitly that no new permissions model needs to be built.

Agent Authority28 min read
25 August 2026

The Dealer Had Permission to Hedge. Your Bourse Let an AI Agent Use It Too.

Your Bourse, the FX, CFD and crypto trading infrastructure provider, published a content hub piece on 18 August 2026 describing MCP for Trade Server, a connection that lets a broker link a compatible AI assistant to its Trade Server backend. Finance Magnates corroborated the same day that broker staff can query live data and initiate permitted hedges or position closures. Your Bourse's own material states the assistant inherits the permissions attached to the connected user's existing Trade Server credentials, that instructions affecting positions or funds return a preview before anything executes, and that execution follows only after a person approves it and is then recorded in Trade Server the same way as an action taken through the ordinary interface. Moona Intelligence verifies each part of that claim separately, keeps the employee's technical login permission apart from any organizational mandate to delegate it to software, and finds Your Bourse has not documented whether the confirmation step is enforced inside Trade Server itself or depends on the connected AI client honoring it.

Agent Authority15 min read
24 August 2026

Seeing What an Agent Did Is Not Stopping It. Okta's Case for a Cross Platform Kill Switch.

Harish Peri, Okta's SVP and General Manager of AI Security, published When AI Agents Go Rogue: The Case for an Enterprise Kill Switch on LinkedIn on 20 August 2026. The piece argues that an enterprise watching an agent is not the same as an enterprise that can stop one, that agents crossing several systems in a single task make manual containment impractical, and that the resulting enforcement layer has to reach across applications and vendors rather than stay inside one company's own product. Moona Intelligence verifies Peri's role and reads the argument against Okta's own six month public record making the same case, and keeps two things separate throughout: what a kill switch is argued to do, and what any implementation, Okta's included, has actually been shown to do.

Agent Security9 min read
24 August 2026

NIST Wants an Identity for the Agent. Authorization Is a Separate Question.

The NCCoE's concept paper, published 5 February 2026 with public comment open through 2 April 2026, proposes a practical demonstration project applying identity and access management standards including OAuth, OpenID Connect, SPIFFE and SPIRE, SCIM and Next Generation Access Control to software and AI agents in enterprise settings. Moona Intelligence verifies what the paper actually establishes: a draft proposal exploring a demonstration project, not a finished standard, not enacted policy, and not a completed practice guide. Its most useful contribution is not a technical answer but a structural one, that an agent's identity, its authorization to act, the human authority it acts under, and the record of what it did are four separate things a system has to get right, and having one does not prove the others.

Governance & Policy10 min read
24 August 2026

Your Employee Has Access. Whether an Agent Inherits It Is Not Their Call.

Okta's Cross App Access did not launch today. It was announced 23 June 2025, expanded to a 25 plus partner ecosystem on 23 June 2026, and given Auth0 implementation guidance on 6 August 2026 that named 24 August 2026, the current radar date, as when integrations including Anthropic, Asana, Canva, Cloudflare, Cursor, Datadog, Docker, Figma, VS Code and Zoom were expected to reach the Okta Integration Network. Two days before that, on 22 August 2026, the Model Context Protocol's own Lead Maintainers published a new roadmap making agent identity and enterprise ready security one of five top level protocol priorities, naming cloud workload agents, absent users and subagent delegation as cases the current browser consent model does not serve, and pointing at DPoP, Workload Identity Federation and the ID JAG grant behind Enterprise Managed Authorization as the intended path. Moona Intelligence verifies each stage of that chronology separately, reads the protocol's own mechanics and its own roadmap post directly, and separates what is confirmed stable today from what remains directional specification work. The distinct question underneath all of it: Cross App Access moves the decision to let an AI agent inherit an employee's application access from a consent screen the employee clicks through to a policy an administrator configures once, and the employee whose access is exercised is not necessarily the actor who was organizationally entitled to make that decision, a question the new roadmap now extends to cloud workloads and to agents acting for other agents.

Agent Authority29 min read
23 August 2026

The Agent That Wrote the Code Cannot Approve It

The AI-native SDLC playbook describes six stages, Plan, Design, Build, Test, Deploy and Maintain, run as a loop rather than a line, with AI embedded at each point. The part worth reading closely is not the stages. It is what Anthropic puts at the seam between them: a hook, described as the deterministic control behind an advisory instruction, that can allow, ask or block before Claude acts, a production deploy hook that holds a release until a named release manager authorizes it, and a rule that a non interactive agent run carries its own identity so a pipeline log can tell what the agent did from what the engineer did.

Agent Authority11 min read
22 August 2026

You Can Approve Every Trade. Or You Can Delegate the Subaccount in Advance.

Binance introduced Agent OS on 20 August 2026 as a developer platform linking compatible AI applications, including ChatGPT, Codex, Claude Code and Cursor, to Binance trading, market data, wallet, payment and onchain capabilities, gated by user configured permissions. TechCrunch's reporting, built on an interview with Binance VP of Product Jeff Li, describes the primary constraint as a dedicated subaccount with withdrawals blocked by default, and quotes Binance describing a genuine choice between per order approval and autonomous execution once permissions are configured. Binance's own MCP Server documentation, modified the next day, describes something narrower: every order, cancellation and transfer inside that subaccount confirmed by the user before it executes, with no autonomous mode documented alongside it. Moona Intelligence reads this against what a human can delegate in advance, where that delegated envelope actually ends, and what is vendor statement rather than documented enforcement. Updated 23 August 2026 with the MCP Server's own confirmation requirement, the subaccount's empty starting balance, the absence of a withdrawal scope, an itemized revocation path and a direct comparison against Robinhood's bounded autonomous execution, on top of the 22 August Authority Provenance ledger verifying who is documented as entitled to grant an agent trading authority. Updated again 25 August 2026 after Moona Intelligence's radar flagged further Binance explanatory material on the same permission and approval model. That specific material could not be independently reached in this environment. This update instead adds a second, independent secondary account of the confirm before execute pattern, and records plainly that the underlying findings, and their open questions, are otherwise unchanged.

Agent Authority28 min read
21 August 2026

The Agent Can Move the Money. It Still Does Not Hold the Keys.

BNB Agent Studio v2 launched on 13 August 2026 and gained a second wallet option, Altana, on 18 August 2026. Altana lets a builder keep custody of a wallet's underlying keys while an agent acts through a session key bounded by a spending limit, a contract allowlist and an expiry, recorded on chain so the bound can be checked from outside the agent and revoked in one transaction. Moona Intelligence reads what is actually being separated: the ability to transact from the authority to redefine what transacting is allowed to mean.

Agent Authority10 min read
21 August 2026

Slack Put the Approval Where the Conversation Is. It Did Not Put the Enforcement There.

On 20 August 2026 Slack, a Salesforce company, launched Slack Code: a new channel type that partner coding agents create through a Slack API, carrying a plan, a repository and branch, code diffs and a live preview. Slack documents that anyone in the channel can pause, redirect or stop an agent mid task, that agents inherit Slack's permissions and admin controls so no new identities are provisioned, and that the channel archives itself into an audit log when the task ends. Slack also says that for high stakes moves, like pushing code to production, the agent packages its work for an expert to sign off on, right in the channel. That is a description of a workflow, not of an enforcement mechanism. Slack states plainly that Slack Code is not a coding model, a harness or an agent runtime, which means the code does not execute in Slack and neither does the deployment. Nothing published establishes who counts as an expert, whether a sign off binds to a specific diff, commit or deployment, whether an agent can proceed without one, or what downstream system enforces the decision. Moona Intelligence reads the launch as the approval moment moving onto a general purpose chat surface while the enforcement point stays somewhere Slack does not document.

Agent Authority10 min read
21 August 2026

Enterprises Are Picking Orchestration Platforms on Whether They Can Constrain the Agent

VentureBeat Pulse Research surveyed 107 organizations of 100 or more employees in a single July 2026 wave about how they run and buy agent orchestration. Flexibility across models and tools led the reasons for picking a platform at 29%. Security and permissions came next at 17%, with control over agent execution and production reliability at 15% each. Looking forward, 30% named security and permissions enforcement as a planned investment over the next twelve months, second only to agent monitoring and debugging at 31%. And 53% expect their primary control plane to be hybrid by the end of 2026, with the risk most associated with a provider resident control plane being that provider's security and permissioning limitations, at 37%, ahead of vendor lock in at 23%. This is a small, self selected, technology heavy sample. It is a directional signal about a specific set of AI active enterprises, not a measurement of enterprise behaviour in general.

Enterprise Adoption5 min read
17 August 2026

Fortinet Bought an AI Security Company. Look at Where It Puts the Control.

On 17 August 2026, Fortinet announced it had acquired Virtue AI, describing the company as an innovator in AI runtime protection, automated AI validation, and security for autonomous AI systems. Financial terms were not disclosed. The interesting sentence is not about the deal. In the capability list, Fortinet writes that the technology monitors agent behavior and blocks malicious tool calls before they act. Virtue AI describes the same capability on its own site under the name Action Guard: monitor agent behavior as it happens and block malicious tool calls before they fire. Traditional security is largely organised around detection and response after activity occurs. A control that decides at the tool call is organised around something else: the moment before a consequential action executes.

Enterprise Adoption3 min read
17 August 2026

The Agent Did Not Make the Payment Alone. It Passed Your Authority Down a Chain.

Alipay announced a full stack agentic commerce platform and the AHA cross agent protocol system at its AI Ecosystem Partner Conference in Hangzhou on 17 August 2026, with more than 20 device makers, automakers and model companies joining an interconnection plan. Alipay's own documentation reports 300 million agent payments and 100 million users across 12 commercial scenarios, and describes several distinct authorization modes. Moona Intelligence reads the launch as an authorization propagation problem: when one instruction crosses several agents before producing a real payment, connectivity between those agents is not the same thing as inherited authority. Updated 23 August 2026 with newly surfaced evidence from Uber Engineering, published 21 May 2026, describing a production actor chain architecture that carries a human user's identity and every intermediate agent's identity through a chain of short lived tokens, verified against a strict Authority Provenance ledger. Updated again 24 August 2026 with the AI AGENT Act, introduced in the Senate as S.5051 on 21 July 2026 and now referred to the Committee on Commerce, Science, and Transportation, and with Aashis Luitel's 13 August 2026 analysis in The Conversation of a cross system evidence gap: an agent provider, a merchant and a payment provider can each hold an individually accurate record of one transaction while none of them, alone, can show the user authorized that specific action as part of that specific task. Updated again 26 August 2026 with this desk's own independent verification of S.5051: the bill's own official short description at Congress.gov, the precise scope of the redelegation restriction, the duties a permitted downstream delegate keeps, the FTC's registration process and its authority to set specialized terms for particular commercial settings, what a large online platform may do on its own side of a revocation, and the exact capabilities the bill directs NIST to identify or build standards for, with introduction date, sponsor and committee status confirmed unchanged as of 26 August 2026. Updated again 29 August 2026 with the Payment & Clearing Association of China's Self-Regulatory Convention on Agent Payment Applications, issued 24 August 2026 under People's Bank of China guidance: an industry self-regulatory instrument, not a statute or a PBOC regulation, that asks member institutions to sort out an authorization boundary between a user and an agent payment application, sign clear authorization agreements, verify transaction intent, protect a user's right to revoke, cap standing authority through transaction limits, and explore both a Know Your Agent mechanism built on top of KYC and a trusted evidence mechanism spanning user authorization, model decision, payment instruction and risk control, read against the same distinctions between authentication, agent identity, authorization and intent this record has kept separate throughout, and against PBOC Vice Governor Lu Lei's 27 August 2026 public call for market participants to actively implement it.

Agent Authority55 min read
14 August 2026

You Authorized the Goal at 9 AM. What Is the Agent Allowed to Do Until 5 PM?

WRITER announced Palmyra X6 on 13 August 2026 and says it can hold a single objective for up to eight hours without supervision, planning, executing, verifying its own output and correcting its work. WRITER Agent batches tasks, delegates to sub agents, calls MCP tools and connectors, and recovers from errors with fewer interruptions. Every one of those is a real improvement. Together they also mean that one authorization at the start of the day can sit behind a very long sequence of decisions nobody sees until the work comes back.

Agent Authority11 min read
14 August 2026

The AI Security Agent Found the Problem. Now It Has Authority to Fix It.

IBM and OpenAI announced an expanded cybersecurity partnership on August 13, 2026. IBM describes its Autonomous Defense Agents as providing automated policy enforcement and rapid remediation across IT and security tools, and its Autonomous Threat Operations Machine as orchestrating multiple AI agents and executing remediation at machine speed. When a security agent can take that kind of action, the transition from detection to remediation is also a transition in authority. The question is what governs what the agent is permitted to do at the moment it decides to change something in a live environment. Updated 27 August 2026 with Mate Security's Gamebooks, an independently built architecture that separates an organization's investigative mandate from the path an AI agent chooses and from the execution layer that reaches a real system. Updated the same day with Visa's Vulnerability Agentic Harness (VVAH), a shipped, open-source implementation that predates the day's corporate announcement by two months. Verified directly against the repository's current main: the shipped default profile runs remediation and validation automatically after every scan, the remediation stage can write a candidate fix into the target's actual working tree using only Read/Glob/Grep/Edit/Write with Bash denied on every shipped profile, and no commit, push or merge call exists anywhere in the codebase. A second, read-only panel scores the candidate without touching the target. Visa's own account, corroborated by VentureBeat, places human review before the tool runs, on the specific patch, and again before anything merges. That is evidence that mutation authority and adoption authority are separate transitions, not one boundary.

Agent Authority19 min read
14 August 2026

Claude Code Just Automated the Decision to Ask You for Permission

Anthropic has made auto mode the default permission mode for new Claude Code sessions on Pro, Max and Team plans, starting 14 August 2026. Auto mode is not unrestricted execution: a separate classifier reviews each tool call, deny and explicit ask rules still fire first, and repeated blocks fall back to manual prompts. The interesting shift is architectural. The decision about when a human is needed has moved up a layer. Updated 26 August 2026: Anthropic says Claude in Chrome, generally available on every paid plan, now decides the same question for actions Claude takes inside a browser, through websites a person is already logged into. The classifier moved from a terminal to a browser tab. What it is actually deciding, and what it cannot decide, did not move with it. Updated 28 August 2026: Claude Code v2.1.248 adds a --restricted launch mode that removes the built-in tools that run commands or code and WebFetch by default, confines file tools to the working directory, refuses bypassPermissions, and loads only managed settings, leaving project, local and user settings files unread. Where auto mode decides whether an available action may proceed, restricted mode decides which actions are available to the session at all, and this record reads what Anthropic's own current documentation does and does not establish about that difference. Updated 29 August 2026: v2.1.251 narrows the gap between a permission decision and the resource it actually reaches, fixing a symlink that could be swapped after a file tool's permission check, a matching gap in Grep and Glob's deny rules, a Workflow tool script path read before its own permission check, and consolidating Claude in Chrome onto Claude Code's own permission checks, while server managed settings that weaken the sandbox boundary now require the developer's approval before they apply.

Agent Authority35 min read
13 August 2026

Nobody Told the Agent to Use the Camera. It Worked That Out on Its Own.

RebelDot describes a coding agent that was asked to run a robot arm data collection task with two unlabelled cameras. Nobody told it to capture reference frames, copy them over SSH or use the cubes on the table as a landmark. It did all of that, inferred the mapping, and then paused for human confirmation before proceeding. The interesting question is not the vision. It is what authorizes the steps an agent invents for itself. Updated 28 August 2026: Anthropic's Model Hardware Standard research preview, opened 27 August 2026, gives the actuator side of that question a concrete architecture, a common driver with read and write primitives and device level safety limits, and this record reads it as first party evidence for the sensor and actuator distinction argued below.

Agent Authority15 min read
13 August 2026

Robinhood Didn't Just Add a Chatbot. It Authorized Software to Move Your Money.

On 27 May 2026 Robinhood opened Agentic Trading and the Agentic Credit Card to third-party AI agents, letting a connected agent place real trades and real purchases inside a customer's account. The safeguards Robinhood built are real. The harder question is what execution-time control means once software, not a person, decides whether an action actually runs.

Agent Authority9 min read

Where to go next

All topics →