AI in practice · 24 September 2026

What is an AI agent allowed to do?

"What are AI agents?" has become one of the most searched business questions of the year, and most answers describe capability: software that can plan, use tools, and carry out multi-step work rather than just answering a prompt. That definition is accurate and almost useless for making a decision.

The useful definition is organisational. An AI agent is a new actor inside your business. It reads systems, writes to systems, and takes actions with consequences. The moment you frame it that way, the questions you already know how to ask about people become the questions to ask about agents: who is allowed to do what, with which data, and under whose supervision?

The permissions question

Every organisation we work with already has an answer for humans: role-based access, approval chains, segregation of duties, audit trails. Almost none have extended that answer to agents. The common failure mode is an agent running on a service account with broad access because that was the fastest way to get the demo working. It stays that way into production, and the CISO finds out later.

An agent should hold the narrowest permissions that let it do its job, exactly as a new hire would. If it drafts customer replies, it does not need write access to the billing system. If it reconciles invoices, it does not need the HR directory. This sounds obvious written down. It is rarely what the pilot actually shipped.

The supervision question

Autonomy is not a single setting; it is a dial you turn per task. The pattern that works in practice has three levels: the agent drafts and a human approves; the agent acts and a human reviews the log; the agent acts alone within hard limits. Most work starts at the first level and earns its way down. What moves it down the dial is evidence: instrumentation showing the agent's error rate, an audit trail of every action, and a defined owner who reviews both.

Regulators in this region are already thinking this way. In February the Central Bank of the UAE launched a sovereign financial cloud ecosystem with Core42, built so that licensed institutions can run AI and data workloads on infrastructure inside national borders and under national supervision. Infrastructure decisions of that size are a statement of direction. If you operate in a regulated sector in the Gulf, agent governance is not a future problem; it is a current supervisory expectation.

The accountability question

When an agent makes a bad call, someone owns the consequence. Naming that person before go-live changes design decisions for the better. Suddenly the audit trail matters, the rollback path matters, and the hard limits get written down. We have found that the single strongest predictor of an agent surviving contact with production is whether a named human wanted it instrumented properly, because they knew it was theirs.

Start with one agent, governed properly

The temptation is to draw an agent architecture for the whole enterprise. The better move is to ship one agent into one workflow with permissions, supervision and accountability designed in, then let the pattern spread. That first governed agent teaches your organisation more than any framework document.

That is the shape of our ninety-day method: choose the wedge in a two-week diagnostic, ship the first system into live workflows by week eight, and hand over governance your team can inherit by week thirteen. The front door is the two-week diagnostic, and the whole method is public.

Related on triway.ai

Begin here

Start with a two-week diagnostic

A paid, two-week working engagement. We map where intelligence compounds in your business and leave you with a plan worth keeping, whoever you choose to build with.

Not ready to book? See where AI would pay off first: twelve questions, three minutes.