All posts
Resources5 min read

What Happens When One AI Agent Can Access Every App?

What Happens When One AI Agent Can Access Every App?
Ghita El Haitmy
Ghita El Haitmy
Software Engineer @ Eli · Aug 18, 2026

More access means more value — and more risk

An assistant that only reads your calendar is easy to manage. It has one job, limited access and a small blast radius if something goes wrong.

A cross-app agent is different.

Imagine an agent that drafts a sales email, pulls the prospect’s history from your CRM, checks whether they have unpaid invoices and logs the next step in your project tool.

That is useful because it can move across systems without asking for approval at every step.

But that is also the risk.

The more useful an agent becomes, the more access it needs. And the more access it has, the harder it becomes to answer a basic question:

What did it change, where and why?

The permissions problem grows quietly

Connecting an agent to a new tool is becoming easier. That means teams can add access quickly, often one integration at a time.

On its own, each decision can look harmless:

  • Connect it to the CRM so it can update leads.
  • Connect it to billing so it can check payment status.
  • Connect it to email so it can follow up.
  • Connect it to the project tool so it can assign actions.

Before long, the agent has access that no single employee would normally be given.

The problem is rarely one dramatic decision. It is the build-up of many small decisions, made by different teams, without one clear owner looking at the full picture.

Agent sprawl is also a finance problem

This often gets treated as an IT or security issue. It is also a cost issue.

A cross-app agent does not create one neat bill. Its cost is spread across:

  • Model usage
  • Software subscriptions
  • Integration or orchestration tools
  • Engineering and maintenance
  • Time spent fixing broken workflows
  • Duplicate agents doing similar jobs

Each cost can look reasonable on its own. Together, they can become a meaningful amount of spend that nobody is tracking properly.

Most companies know who every employee reports to, which systems they can access and what they cost.

Very few can answer the same questions for their AI agents.

That needs to change.

What operators and CFOs need to put in place

Once an agent works across several apps, three things become essential.

1. A clear owner

Every agent needs one named person who is accountable for what it does, what it can access and whether it still delivers value.

If ownership is assumed, nobody really owns it.

2. Limited access

An agent should only have the permissions it needs for the task it is doing.

Do not give it broad access just because that makes setup easier. Convenience today can create risk tomorrow.

3. One view of activity and cost

You need to see which agents are running, which apps they can reach, who owns them and what they cost.

If you cannot see the connections, you cannot manage the risk or the spend.

See what ELI finds in your stack.

Connect one source. Five minutes. Free to start.

Connect your stack →