More access means more value — and more risk
An assistant that only reads your calendar is easy to manage. It has one job, limited access and a small blast radius if something goes wrong.
A cross-app agent is different.
Imagine an agent that drafts a sales email, pulls the prospect’s history from your CRM, checks whether they have unpaid invoices and logs the next step in your project tool.
That is useful because it can move across systems without asking for approval at every step.
But that is also the risk.
The more useful an agent becomes, the more access it needs. And the more access it has, the harder it becomes to answer a basic question:
What did it change, where and why?
The permissions problem grows quietly
Connecting an agent to a new tool is becoming easier. That means teams can add access quickly, often one integration at a time.
On its own, each decision can look harmless:
- Connect it to the CRM so it can update leads.
- Connect it to billing so it can check payment status.
- Connect it to email so it can follow up.
- Connect it to the project tool so it can assign actions.
Before long, the agent has access that no single employee would normally be given.
The problem is rarely one dramatic decision. It is the build-up of many small decisions, made by different teams, without one clear owner looking at the full picture.
Agent sprawl is also a finance problem
This often gets treated as an IT or security issue. It is also a cost issue.
A cross-app agent does not create one neat bill. Its cost is spread across:
- Model usage
- Software subscriptions
- Integration or orchestration tools
- Engineering and maintenance
- Time spent fixing broken workflows
- Duplicate agents doing similar jobs
Each cost can look reasonable on its own. Together, they can become a meaningful amount of spend that nobody is tracking properly.
Most companies know who every employee reports to, which systems they can access and what they cost.
Very few can answer the same questions for their AI agents.
That needs to change.
What operators and CFOs need to put in place
Once an agent works across several apps, three things become essential.
1. A clear owner
Every agent needs one named person who is accountable for what it does, what it can access and whether it still delivers value.
If ownership is assumed, nobody really owns it.
2. Limited access
An agent should only have the permissions it needs for the task it is doing.
Do not give it broad access just because that makes setup easier. Convenience today can create risk tomorrow.
3. One view of activity and cost
You need to see which agents are running, which apps they can reach, who owns them and what they cost.
If you cannot see the connections, you cannot manage the risk or the spend.