Enterprise contact centres are deploying AI agents from multiple vendors simultaneously without basic visibility into what those agents can access, who authorised them, or how to revoke their permissions. Microsoft, SAP, and Salesforce have all shipped autonomous agents directly into customer-facing operations—Dynamics 365 Contact Center handling voice and digital interactions, SAP automating ticket resolution at scale, and AgentForce expanding Salesforce's platform footprint—yet most organisations lack a single system of record spanning all deployments. The governance infrastructure has failed to keep pace with automation velocity. Each vendor brings its own identity model, data connection logic, and permission framework, leaving no single team with complete visibility. For CX leaders managing multi-vendor stacks, this fragmentation creates a critical blind spot: agents are routinely credentialed into CRM systems, customer data platforms, ticketing infrastructure, and telephony layers, operating on behalf of customers with access to purchase histories, account credentials, and personal data. The risk is not operational inefficiency alone—it is customer trust exposure at scale.
The consequences of this visibility gap are concrete and immediate. When permissions are distributed across vendor dashboards, IT procurement records, and individual team deployments, the question becomes not whether misconfiguration or compromise will occur, but whether organisations will detect it quickly enough to respond. Okta CEO Todd McKinnon frames the operational reality bluntly: agent behaviour is non-deterministic, meaning governance frameworks must account for unexpected actions, not just intended ones. The practical response is what Okta calls a "kill switch"—the ability to revoke an agent's access to every connected system instantly, effectively removing it from the network without shutting down the agent itself. For teams running SAP's autonomous ticket resolution or Microsoft's Dynamics 365 agents at scale, this capability and the speed of its deployment may prove essential. Yet the deeper tension remains unresolved: agent value is proportional to data access, and so is its risk. There is no free lunch between granting agents sufficient access to be genuinely useful and constraining them to irrelevance.
What separates organisations that navigate this trade-off successfully from those facing avoidable incidents is not platform choice—it is governance discipline. CX leaders must build an inventory first, mapping every agent across platform-native deployments, third-party CCaaS layers, and internally built automations into a single maintained register. They must then define and control connection points by demanding clarity from vendors on how agent authentication is managed and what audit trails exist. The defining question for teams already running Agentforce or equivalent deployments is whether they have treated those agents with the same governance rigour they would apply to a new human hire: knowing what access they have, who authorised it, and how to take it back. Without that discipline, the speed advantage of agentic AI becomes a liability.
Ask any CX leader to produce a complete list of every AI agent currently running in their contact centre environment – what it is connected to, what data it can access, and who approved its permissions. Most cannot. This issue is growing by the quarter as major enterprise platform vendors ship
Your AI Agents Are Already Inside Your Contact Center - Do You Know What They're Doing? CX Today