Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

The guest agent problem is coming to enterprise collaboration

Enterprise collaboration platforms face a fundamental architectural problem: they were built to manage human guests with traceable identities and bounded access, but AI agents operate under entirely different parameters. An agent deployed by a partner organisation can continuously consume workspace context, communicate with other agents and invoke tools across external systems—all whilst the host organisation may have no visibility into who created it, how it operates or what data it processes. This represents a distinct security and governance challenge that cannot be addressed through conventional guest access controls. UC and security leaders must now treat agent admission as a separate trust decision, requiring verifiable cryptographic identity protocols (OAuth 2.0 extensions or mutual TLS) tied directly to verified domains, combined with explicit human ownership and accountability chains. Without this distinction, organisations risk reintroducing the shadow IT problem they spent the last decade solving, except now the unsanctioned software operates autonomously within critical workflows.

The operational implications demand a fundamental shift in how CX teams architect access and oversight. Rather than granting agents blanket workspace permissions—the standard model for human guests—access must become ephemeral and task-specific, with permissions calibrated to actual risk. A scheduling agent touching only calendar data requires fundamentally different controls than one authorised to edit documents or reallocate budgets. This raises a critical question for teams already running agentic workflows: are your current permission models distinguishing between read-only summarisation and autonomous action, or are you applying legacy guest access patterns that expose far more information than necessary? The answer determines whether your agent deployments remain manageable or become compliance liabilities. Critically, accountability cannot be delegated to the agent itself—responsibility must remain with the human owner of the affected workflow, with explicit approval required before agents execute consequential actions.

Cross-organisational agent governance requires a shared-responsibility model where the host enterprise controls boundary enforcement and environment controls, whilst the organisation introducing the agent remains accountable for its configuration, safeguards and compliance. This demands comprehensive telemetry covering agent identity, triggering user, retrieved context, decision provenance and execution history—enough detail to reconstruct incidents from beginning to end. Real-time guardrails and data loss prevention filters should sit between host workspaces and external agents, blocking or redacting sensitive data before it enters agent context. The goal is not to prevent external agents from participating in collaboration, but to ensure they remain identifiable, constrained and observable before handling meaningful work. For CX teams managing multi-vendor ecosystems, this means building agent catalogs, establishing clear ownership records and implementing logging infrastructure that may not yet exist in your current platform stack.