AI Agents Are Getting Access to Your Business: 8 Security Questions Every IT Leader Should Ask

Share it
Facebook
Twitter
LinkedIn
Email

Artificial intelligence at work used to be simple. You opened a chat window, asked a question, got an answer, and whatever it produced stayed there until a person moved it. That era is closing. The tools arriving now connect to business applications, company files, calendars, email and customer records, and depending on how they are set up they do not just answer. They act.

An agent with access is closer to a new employee than a new feature

An employee hands one a goal instead of a question: research this customer, pull the documents, update the record, draft the follow-up, then do the same for the next forty accounts. There is obvious value in that, which is why adoption is moving so fast.

But it raises questions most businesses have not answered yet:

  • What is this software allowed to see inside our systems?
  • What is it allowed to change, send or delete on an employee’s behalf?
  • If something goes wrong, can we explain what it did and who authorized it?

Those are access and identity questions, not artificial intelligence questions. Most organizations already know how to answer them for people. The work now is extending that thinking to software that behaves like people.

Know What Is Connected

Inventory every tool and agent in use, including the ones running on personal accounts, before deciding what should be allowed.

Scope What It Can Reach

Give each agent its own identity, a named owner, and access to the specific locations its job requires.

Prove What It Did

Keep a record of agent activity, require approval for consequential actions, and be able to revoke access quickly.

What is an artificial intelligence agent?

Compare one against a chatbot. A chatbot waits. You say “summarize these notes,” it does, and it stops. There is nothing it can reach on its own.

An agent gets a goal: find every customer follow-up in today’s notes, create the tasks, draft the emails, remind me tomorrow about anything outstanding. To do that it needs permission to read notes, reach customer records, create tasks, open a calendar and touch email, and it chooses the steps itself.

  Chat assistant Agent
What you give it
The instruction
A question or a piece of text. A goal, sometimes a recurring one that runs on a schedule.
What it can reach
Scope
Only what you paste into the window. Email, files, calendars, customer records and other connected systems.
Who decides the steps
Control
You do, one prompt at a time. The agent does, then acts on its own decisions.
What it leaves behind
Consequence
Text you choose to use or discard. Sent messages, changed records, moved data.
The security question
What to ask
What did an employee paste into it? What may it see, change and send, and who is accountable for it?

That ability to move between systems and take action is the entire value. It is also why permissions matter far more than they used to. Microsoft has agents throughout its Copilot products, OpenAI offers workspace agents in ChatGPT’s business and enterprise plans, Google has Gemini Enterprise, and Salesforce has Agentforce. None is inherently unsafe. The risk lives in how they are connected and what they can reach.

Why this is arriving on the agenda now

Adoption is outrunning policy, and there is data on the gap. An Okta-commissioned 2026 survey of 292 executives and 492 knowledge workers found that 52 percent of the workers had used a tool for work without approval from their technology or security team. Among them, more than half had put internal messages or email into it, and 39 percent had shared confidential documents such as contracts or financial records.

Meanwhile 90 percent of executives said they were confident in their visibility into what tools employees were using, and 58 percent reported an artificial-intelligence-related security incident or close call in the previous year. That is a vendor-commissioned survey rather than a census, but the gap between what leadership believes and what employees report is wide enough to check against your own environment.

The major security vendors moved in the same direction within a few months of each other. Microsoft’s August 2026 security guidance is built around constraining what agents can do without human approval and governing their identities and permissions. On September 2, CrowdStrike announced a product premised on giving every agent a verifiable identity of its own and tying each action back to the person behind it. Google’s cloud platform now issues agents their own identities with narrow, per-agent permissions for sensitive resources.

Treat an agent the way you would treat a new employee: a defined job, scoped access, a named manager, a record of what it did, and a last day.

1. Do we know which tools are actually in use?

You cannot protect what you do not know exists. Plenty of companies have an approved platform and assume that settles it, while employees are trying browser extensions, meeting recorders, writing assistants and coding tools nobody reviewed.

Start with an inventory: which tools people use, which are approved, what they connect to, who can create an agent, whether anyone is using a personal account for company work, and whether anything runs on a schedule.

This is not a prelude to banning everything. Okta’s team noted that unclear policies and hard prohibitions tend to push usage further out of sight rather than reduce it. And do not punish what you find; you need the truth more than a clean report.

2. What information can each agent see?

The most consequential question here, because an agent inherits whatever mess already exists. You would not give a new hire access to every folder on their first morning. Agents rarely get that courtesy, because broad access is faster to configure.

Here is how it goes wrong. A folder was shared with the whole company in 2021 for a project that ended, and nobody cleaned it up. It has never caused a problem because nobody had reason to look. Then an agent gets connected, and it has no judgment about what it ought to be looking at, only permissions. Within a week it surfaces a salary spreadsheet in a summary for someone who should not see it, and the company learns its access was far broader than anyone assumed.

The agent did not create that exposure. It found it, instantly, and put it in front of a person.

So a sales agent needs the sales folder, not payroll. An agent reading calendars may not need permission to change them. Google’s platform supports exactly this split, with broad grants for low-risk permissions and narrow per-agent grants for data access, but the principle holds regardless of vendor. Cleaning up file sharing and group membership is not preparation for later. It is what you do before anything gets connected.

3. Can it only read, or can it act?

“Show me today’s customer emails” and “reply to today’s customer emails” are different requests. The second changes something outside the artificial intelligence system.

For every agent, get specific. Can it send? Change? Delete? Approve? Can it move data somewhere else? Most agents doing useful work need far less write access than they are granted.

4. Does the agent have its own identity?

This sounds technical, but the idea is not. If an agent performs every action using Sarah’s account, the log says Sarah did it. Did she, or did it act for her? That matters the moment you are investigating an error or explaining to a client how their information was accessed.

Microsoft, Google and CrowdStrike have all landed on the same fix: agents get their own identities rather than borrowing a person’s. CrowdStrike’s September announcement goes further, tying each action back to the human or system that authorized it. You do not need to buy any of it to take the lesson. Four questions should always have answers: who did this, was it a person or an agent, which agent, and who authorized it.

One related trap. OpenAI’s documentation warns administrators that letting agents publish with personal connections means anyone using that agent may reach data through the creator’s credentials. Convenient, and a fast way to lose the audit trail you just built.

5. Which actions need a person to approve them?

Automation is fine until the cost of being wrong gets expensive. An agent summarizing 200 documents does not need sign-off on each one. An agent changing payment information is a different proposition, as is one that deletes files, sends money, creates users, changes security settings, or emails on behalf of an executive.

Microsoft’s August guidance is explicit about constraining agent actions that happen without explicit user approval. Google has said its forthcoming access policies will support requiring human approval for sensitive actions, though that is announced rather than shipped, so check its current state before planning around it. Either way the rule does not depend on a vendor roadmap: the threshold should track the consequence and how reversible it is.

6. What if the agent receives a bad instruction?

Almost nobody is asking this one, and it breaks a comfortable assumption. Agents do not only take instructions from the employee using them. They read documents, websites, emails, and the descriptions attached to the tools they connect to. A person who spotted a strange line buried in a document would ignore it. An agent may read it as a legitimate instruction.

On June 30, 2026, Microsoft’s incident response and Defender researchers published guidance on a specific version of this. Many agents connect to business tools through an open standard called the Model Context Protocol, where each tool carries a plain-language description of what it does, and the agent reads those descriptions to decide which tool to use. Microsoft showed that an attacker who modifies one can steer an agent into collecting sensitive information and routing it somewhere it should not go.

What makes it hard to catch is that every step looks legitimate. The tool was approved. The query ran with the employee’s own permissions. The outbound connection was allowed when it was set up. The employee gets a normal answer and sees nothing wrong. Microsoft was clear that this is not a bug in Copilot. It is a trust problem created when agents treat outside tool descriptions as instructions.

Which means the reassuring version of security awareness, the one where nobody clicked anything so we are fine, does not cover it.

7. Can we see what the agent did?

Imagine asking an employee whether they changed a customer’s account and hearing “not sure, maybe.” That is a problem, and it is an equally serious one when an agent cannot be accounted for.

What a usable record of agent activity should show

What the agent accessed, including files and records it opened while completing a task nobody was watching.
What it changed or sent, so a mistaken email or an edited record can be traced rather than guessed at.
Who or what started the task, whether an employee, a schedule, or another connected system.
Whether it tried something unusual, such as reaching for data unrelated to its stated purpose.

The major platforms are building toward this. OpenAI gives business administrators visibility into agent configuration and activity along with the ability to suspend one. Microsoft’s guidance stresses separating agent activity from human activity in the first place, which is what makes the rest legible.

8. How do we shut one down?

Ask your team today: if we had to revoke every agent connected to our email by tomorrow morning, could we?

Employee offboarding is solved at most companies. Agent offboarding usually does not exist, so agents accumulate. One built six months ago for a finished project, by someone who has since changed departments, still connected because nobody remembers it is there. Microsoft maintains a registry of agents across its own environment for exactly this reason, since tracking them individually stops working as the count grows.

You should be able to say who owns each agent, why it exists, what it reaches, when it was last reviewed, and how fast it can be switched off. A question without an answer means that agent has more independence than anyone intended.

The eight questions in one place

If you cannot answer these yet, that is not a reason to stop using artificial intelligence. It is a reason to find the answers while the number of agents in your environment is still small enough to count.

Question What a good answer looks like
1. Which agents are in use?A current list, including tools running on personal accounts, not just the approved platform.
2. What can each one see?Specific locations and systems, documented, with sharing and group membership already cleaned up.
3. Can it act, or only read?Read access and the ability to send, change or delete are recorded separately for every agent.
4. Does it have its own identity?Every agent has an identity and a named owner, and none of them operate inside an employee’s account.
5. Which actions need approval?Consequential and hard-to-reverse actions require a person to confirm before the agent proceeds.
6. What if it gets a bad instruction?Permissions are scoped tightly, connected tools are reviewed, and outbound data movement is monitored.
7. Can we see what it did?Agent activity is logged and distinguishable from human activity, and someone reviews it.
8. Can we remove its access?Agents appear in access reviews, have review dates, and can be revoked without a discovery exercise.

A practical way to sequence the work

This does not need to be a program with a steering committee. The early steps take days, and doing them in order saves rework.

Stage What it involves Why it comes here
See what exists
First 30 days
Find which artificial intelligence services the network and cloud tenant are reaching, list every agent already connected, and identify who created each one. Every later decision depends on knowing what is actually in the environment rather than what was approved.
Clean up access
Before expanding
Fix open sharing links, oversized groups and inherited permissions from old migrations. An agent with correct settings and overexposed data still puts the wrong document in front of the wrong person.
Give agents identities
Accountability
Assign each agent its own identity and a named owner, and stop agents from operating inside employee accounts. Without this, activity records cannot separate what a person did from what an agent did on their behalf.
Set approval thresholds
Consequence control
Decide which actions require a person to confirm, based on how costly and how reversible they are. Automation is worth having everywhere except the places where being wrong is expensive.
Make it repeatable
Ongoing
Write a short acceptable-use policy with role-specific guidance, confirm what activity is logged, add agents to access reviews, and set retirement dates. Agent counts grow quickly, and a list nobody maintains stops being useful within a quarter.

What belongs in an acceptable-use policy

Short enough that people read it, specific enough to be usable. Okta’s research found only about a fifth of workers had received guidance tailored to their actual role, which is usually why policies get ignored rather than followed.

Which tools are approved and how someone requests a new one. If approval takes six weeks, expect people to skip it.
What information never goes into an outside tool, named in plain terms: customer records, employee files, financial detail, anything under a client confidentiality agreement.
Who may connect an agent to a company system and who signs off. This should generally not be self-service.
What the person stays responsible for. An agent drafting a client email does not make the sender any less accountable for what it says.
How agents get retired, who reviews the list, and how often that review happens.
Where to report a problem, without blame, so a mistake surfaces in hours rather than after a quarter-end audit.

How HTG can help

Most of this work is not new. It is identity, permissions, monitoring and offboarding applied to something that behaves like an employee, which is why it fits alongside the rest of a managed security program rather than sitting apart from it.

Area What it includes How HTG helps
Visibility
What is connected
Discovery of artificial intelligence tools and agents in use, including unapproved tools on personal accounts. HTG helps build an accurate picture of what is already reaching company systems before decisions get made about it.
Identity and access
Permissions
Agent identities, ownership, least-privilege access, administrator separation, and sharing and group cleanup. HTG helps scope what each agent can reach and keep human and agent activity distinguishable.
Data protection
Sensitive information
Data loss prevention rules, sensitivity labeling, upload controls, and review of externally shared content. HTG helps reduce the chance that a correctly configured agent still surfaces the wrong document.
Monitoring and response
Detection
Logging of agent activity, alerting on unusual access or outbound data movement, escalation and containment. HTG helps make sure someone is responsible for reviewing what agents did and acting when something looks wrong.
Governance
Policy and lifecycle
Acceptable-use guidance, approval thresholds, access reviews that include agents, and retirement processes. HTG helps turn a set of good intentions into a repeatable process that survives staff and project changes.

The real issue is not artificial intelligence. It is access.

Agents are going to become ordinary. Some will handle repetitive work, others will research, assist customers or prepare reports, and there is real value in that.

But software that reaches company information should not be treated like a harmless chat window. Once something can act on a person’s behalf, permissions and oversight stop being optional.

The encouraging part is that businesses already understand this. We have spent years deciding what employees can access, reviewing accounts, watching for unusual activity and removing access when people leave. Agents do not replace that thinking; they raise the cost of skipping it.

Start small. Pick one useful task, limit the access, watch what happens, and expand carefully.

Not sure what is already connected to your email, files and business systems?

HTG Inc. can help your organization inventory the artificial intelligence tools in use, review identity and permissions, clean up file sharing before agent access expands, set practical approval and offboarding rules, and improve visibility into what those agents are doing.

Talk to HTG Cybersecurity Services MDR & Threat Detection

FAQ: AI agent security

What is an AI agent, and how is it different from a chatbot?

A chat assistant answers questions inside a window and cannot reach anything on its own. An agent is given a goal plus access to systems such as email, files, calendars or customer records, and it decides which steps to take and carries them out. That ability to act is what turns permissions into a security question.

Should AI agents have their own identities?

Yes. If an agent acts inside an employee’s account, activity records cannot distinguish what the person did from what the agent did. Microsoft, Google and CrowdStrike have all released capabilities that give agents their own identities with defined owners, and the underlying principle applies regardless of which platform a business uses.

What is shadow AI?

Shadow AI is the use of artificial intelligence tools for work without approval or oversight, usually through personal accounts. Okta’s 2026 survey found 52 percent of knowledge workers had done it, and many had shared internal messages, human-resources information or confidential company documents through those tools.

How do we keep sensitive information out of unapproved AI tools?

Make the approved path the easy path. Provide a sanctioned tool that is genuinely useful, give role-specific guidance rather than one generic policy, and add controls that catch honest mistakes such as data loss prevention rules, upload restrictions on company devices, and sensitivity labels on the documents that matter most. Blanket bans tend to move usage out of sight rather than stop it.

What should an AI acceptable-use policy contain?

Which tools are approved and how to request a new one, what information never goes into an outside tool, who may connect an agent to a company system and who signs off, what the employee remains accountable for, how agents are reviewed and retired, and where to report a problem without blame.

Can HTG help before we connect AI agents to Microsoft 365 or company files?

Yes, and that is usually the better sequence. HTG can help inventory what is already in use, review identity and permissions, clean up sharing links and group membership, define approval requirements for consequential actions, confirm what activity is being logged, and establish a review and offboarding process for agents.

Share it
Facebook
Twitter
LinkedIn
Email

Related Posts