Gartner forecast on 24 February 2026 that 62% of cloud ERP spending will go to AI-enabled solutions by 2027, up from 14% in 2024. An agent that posts a journal, releases a payment or changes a supplier's bank details is a new kind of user. It deserves the scrutiny given to any new joiner holding those rights.

The vendors have already drawn the line

The ERP vendors say so themselves. SAP's Architecture Center states that AI agents "require a dedicated identity that defines their boundaries, permissions, and allowed interactions". Oracle's March 2026 release on Fusion Agentic Applications, anchored by its AI Agent Studio, describes agents operating "entirely inside the existing Oracle Fusion Applications security framework", with role-based access, approval frameworks and end-to-end traceability.

For JD Edwards, Oracle's Orchestrator documentation requires an EnterpriseOne user ID to be authenticated before any orchestration runs, and that user must hold authorised access to the application where the transaction lands. On all three platforms the mechanism is the same: the agent is a user, and the ERP decides what a user may do.

Regulators draw the same boundary. The Central Bank of the UAE's guidance note on AI, issued in February 2026, sets out three models of human oversight and reserves the one with no direct human involvement for "low-risk, non-material processes". The Reserve Bank of India's FREE-AI report of August 2025 holds that AI should augment human decisions and defer to human judgement.

Six conditions to confirm before take-off

Each condition below is a test, and each has an artefact you can ask to see.

The agent has its own identity. Ask for its user ID and assigned roles. Under a shared service account, nobody can later say which actions were the agent's.

Every action is a named service. The agent calls a published business service, such as "create supplier invoice". It never drives screens.

Limits live in the authorisation model. Company codes, document types and amount ceilings are set where the ERP enforces them. Ask where the payment ceiling is configured. If the answer is "in the instructions", there is no ceiling.

Segregation of duties covers agents. An agent that raises a purchase order cannot approve it. Ask to see the agent in the same conflict report that covers your people.

The evaluation set is last year's exceptions. Take the duplicate invoices and the changed bank details your team actually caught. Ask for the agent's results on those cases, replayed, before it meets this year's.

Stop and reversal have been rehearsed. Ask who can suspend the agent's user, how long the last drill took and how its postings would be reversed. Article 14 of the EU AI Act sets this bar for high-risk systems: the overseer must be able to "disregard, override or reverse" the output and bring the system to a halt in a safe state. That bar suits anything with posting rights.

Procurement leads compare contract copies with a supplier manager.

The prompt is an instruction; the role is the control

A prompt tells a model what you would like it to do. It is text, and other text can outweigh it: a persuasive note in an invoice's description field, or an email claiming urgency. An authorisation check cannot be persuaded. When the agent attempts a payment above its limit, the ERP refuses and logs the refusal.

So ask where each safeguard is enforced. Anything enforced only in the prompt is a preference. Anything enforced by the role or the approval workflow is a control, and your auditors already know how to test it. The control framework finance spent years building is the AI governance it needs, once the agent sits inside it.

That points to the cheapest safe first step: agents prepare, people post. Matching a document, coding it and attaching the evidence carry most of the labour. Posting carries most of the risk. Split the work along that line and the business collects much of the benefit before it grants any authority that could move money.

Forty prepared, three flagged, none posted

Picture a payables supervisor's queue at eight on a Monday. Overnight the agent has prepared forty invoices, each matched to its purchase order and goods receipt, coded, with the evidence attached. She posts them in batches.

Three sit apart. One supplier's bank details differ from the master record. One invoice repeats the amount and reference of a document paid in March, and another exceeds its order by more than the tolerance. The agent has explained each flag and posted nothing, because its role cannot post.

Her work has moved from keying to judging. Every document shows the agent's ID as preparer and hers as poster. We expect finance teams to widen the agent's role one document type at a time, starting with low-value invoices that match their orders. A role assignment can be withdrawn in a single change.

Ask for the agent's role on one page

This quarter, pick one agent that is live or planned in finance and ask for a single page: its user ID, its roles, the services it can call, where its limits are enforced and the date of the last stop drill. Its gaps are your work list.

An Dependable Core readiness review with NectarGlobal begins with that page, and shows which finance workflows are ready for an agent that prepares and which have earned one that posts.