Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

Agentic security: Enterprises enforce agent permissions two-thirds of the time

Agent security enforcement across enterprises reveals a critical gap between deployment velocity and operational safeguards. Two-thirds of the 116 enterprises surveyed do enforce scoped permissions at runtime, suggesting baseline governance awareness, yet this figure masks a more troubling reality: barely one in five isolates high-risk agents, leaving containment as the weakest link in agentic security architecture. The majority have already experienced confirmed security events or near-misses, indicating that agents are moving into production faster than the defensive infrastructure required to manage them. This pattern mirrors broader agentic deployment challenges—teams are racing to operationalise AI agents without proportional investment in the permission models and isolation protocols that prevent lateral movement when incidents occur.

For CX teams specifically, this creates an immediate tension between competitive pressure and operational risk. Support leaders deploying agents through Zendesk, Salesforce, or similar platforms are inheriting responsibility for systems whose security posture depends on enforcement decisions made upstream. The question becomes whether your organisation's permission scoping is genuinely granular enough to contain a compromised agent before it accesses customer data, payment information, or sensitive case histories—or whether you're relying on the assumption that incidents won't happen. The data suggests they will. Teams already running agentic systems should audit isolation capabilities now, particularly for agents handling high-value or sensitive interactions, rather than treating containment as a post-incident concern.

The broader implication is that agentic governance maturity is unevenly distributed. Whilst permission enforcement has achieved reasonable adoption, the failure to isolate high-risk agents suggests either a lack of tooling, unclear risk classification, or organisational friction in implementing harder boundaries. For CX operations, this means security cannot be delegated entirely to platform vendors or IT—support leaders need visibility into which agents pose the greatest risk and what isolation mechanisms are actually in place. The gap between permission enforcement and containment is where incidents propagate.