The S Curve
Mon, 28 SeptMelbourne · Singapore · New York
Book a call
News

Why CIOs must redesign how SAP, Salesforce and ServiceNow grant authority

You have probably watched a finance analyst wait three days for a ServiceNow ticket to surface a dashboard she could have built herself in twenty minutes.

The S-Curve··5 min read
Synthwave editorial collage

Why CIOs must redesign how SAP, Salesforce and ServiceNow grant authority

You have probably watched a finance analyst wait three days for a ServiceNow ticket to surface a dashboard she could have built herself in twenty minutes. Or seen a sales manager ask IT to pull a Salesforce report that lives two clicks away inside the platform he opens every morning. The pattern is older than cloud software: enterprise systems hoard capability behind permission walls, and the people closest to the problem queue for someone else to solve it.

Deloitte now argues that the arrival of agentic AI inside SAP, Salesforce and ServiceNow forces CIOs to rethink how authority flows through these platforms. When an AI agent can provision a user, approve a purchase order or update a customer record without human review, the old model – IT owns the keys, business users file requests – stops being cautious and starts being a bottleneck that slows decisions the organisation needs to make in minutes, not days.

What agentic AI changes about enterprise software

Traditional enterprise platforms gate features by role. A procurement officer sees supplier records. A finance lead approves invoices. A service desk analyst closes tickets. Each function lives in a silo, and crossing silos requires either a manual handoff or an integration project that takes quarters to scope and ship.

Agentic AI collapses that structure. An agent can read a ServiceNow incident, check inventory in SAP, propose a vendor in Salesforce and draft a purchase order – all in a single workflow that no one designed in advance. The agent does not wait for a human to log in, navigate four screens and copy data between systems. It acts on intent, and it acts fast.

That speed is useful when the task is routine and the risk is low. It becomes dangerous when the agent inherits permissions designed for humans who understand context, read between the lines and know when to escalate. A person who can approve a ten-thousand-dollar invoice will pause before approving ten of them in an hour. An agent with the same permission will not pause unless someone writes the pause into its instructions.

Why the current permission model breaks

Enterprise platforms today grant authority by job title and department. You are a finance manager, so you can approve invoices up to a threshold. You are a sales director, so you can discount deals within a band. You are a service desk lead, so you can reassign tickets across teams. The system assumes that a human with that title will apply judgment, follow norms and ask for help when something looks wrong.

Agentic AI does not carry job titles, and it does not apply judgment the way a person does. It follows instructions, and those instructions are often implicit – buried in training data, encoded in a prompt or inferred from past behaviour. When an agent acts on behalf of a user, it inherits that user's permissions but not that user's experience, caution or understanding of what the business actually needs.

The result is a mismatch. The permission model says the agent can do something. The organisation's actual risk appetite says it should not do that thing without a human checking the context. And the platform has no way to distinguish between a routine action that deserves automation and an edge case that deserves scrutiny.

What CIOs need to redesign

Deloitte's argument is that CIOs must move from role-based access control to task-based access control. Instead of asking whether a user has permission to approve invoices, the system should ask whether this specific invoice, in this specific context, with this specific history, should be approved without human review.

That shift requires three changes. First, platforms need to log not just what an agent did but why it did it – the chain of reasoning, the data it consulted and the rules it followed. Second, organisations need to define guardrails that are explicit, testable and tied to outcomes rather than roles. Third, IT teams need to build monitoring that flags anomalies in real time, not after a quarterly audit surfaces a problem that has been running for months.

The technical work is straightforward. SAP, Salesforce and ServiceNow already expose APIs that let organisations layer policy engines on top of their permission models. The harder work is organisational. Finance, sales, procurement and service teams have spent years negotiating who can do what inside these platforms. Agentic AI forces those teams to renegotiate the deal, and this time the negotiation must account for actors that do not get tired, do not second-guess themselves and do not stop to ask whether a pattern that looks normal is actually an outlier.

What this means for L&D and digital transformation leaders

Learning and development teams that run enterprise software training today focus on teaching people how to navigate SAP, Salesforce and ServiceNow – where to click, which fields to fill and how to interpret what the system returns. That curriculum assumes the user is the actor. Agentic AI flips the assumption. The user becomes the supervisor, and the agent becomes the actor.

The new training challenge is teaching people how to write instructions that are clear enough for an agent to execute safely, how to recognise when an agent has misunderstood context and how to intervene before a mistake compounds. That is not a software skills problem. It is a judgment problem, and judgment is harder to teach than navigation.

Digital transformation leaders face a parallel challenge. Most transformation programmes today measure success by adoption – how many people log in, how many transactions flow through the system and how much manual work disappears. Agentic AI will push those numbers up quickly, because agents do not resist new software and they do not need time to learn the interface. But high adoption does not mean the system is doing what the organisation needs. It means the system is doing what someone told it to do, and if the instructions were vague or the guardrails were missing, the organisation will not know until the damage is visible.

The stake for both groups is the same. Enterprise platforms are about to become faster, more autonomous and harder to audit. The organisations that redesign authority before the agents arrive will capture the speed without the risk. The organisations that wait will spend the next decade cleaning up after systems that did exactly what they were permitted to do.

Enterprise platforms grant authority by role, but agentic AI collapses silos and acts on intent without waiting for human navigation.
Enterprise platforms grant authority by role, but agentic AI collapses silos and acts on intent without waiting for human navigation.

Sources:

From The S Curve

News and insights for innovation, digital transformation, future of work and L&D leaders.

Stay ahead of learning and development, corporate innovation and digital transformation news. Plus the future of work. For leaders in AU, NZ, HK, SG, the US, the UK and Canada.