What Happens to Governance When AI Agents Bypass the Interface What Happens to Governance When AI Agents Bypass the Interface Schedule a meeting
This article draws on OSF Digital's published point of view on the agentic enterprise, developed by Sean Catlin, EVP and Global Head of Strategy at OSF Digital. Sean was named to Channel Insider's 2026 AI Leaders in the Channel list, which recognizes executives across vendors, integrators, and solution providers delivering measurable outcomes with AI. The full list was compiled by Channel Insider's editorial team.

Do AI agents replace the user interface?

No, nothing is being taken away. Salesforce has been explicit that Lightning and browser experiences are not going away, and the same is true across the enterprise stack. Your people will keep working in the same screens tomorrow that they worked in yesterday. What has changed is that a second route now exists to the same data, the same workflows, and the same actions. Agents reach the platform through APIs and open standards rather than through a screen, because agents cannot navigate screens and were never meant to. Two routes to the same system, one of which was never designed to carry anything. That is the whole issue in one sentence, and it is worth being precise about it, because "AI is replacing the interface" is both wrong and reassuring in the wrong way. The interface staying put is exactly what makes this easy to miss.

What was the user interface actually enforcing?

Ask most organizations where their operating rules live and they will point to policy documents, permission sets, and approval matrices. That inventory is accurate but incomplete, because a significant share of enterprise governance was never encoded anywhere. It was enforced by the shape of the screen. Sequence. Screen flows and page layouts imposed an order of operations. You could not approve before you reviewed, because the button was not there yet. Scope. A person working a queue handles one record at a time. Not because a rule forbids more, but because the interface presents one. The practical ceiling on how much a single mistake could affect was set by how fast someone could click. Pause. Every action taken through a screen passed through a moment of human attention. That pause caught the misfiled case, the wrong account, the request that technically passed validation but obviously should not proceed. It was the cheapest control in the enterprise and it appeared on no register. None of this was designed. It accumulated. And it held reliably enough that nobody had reason to examine it, because for thirty years there was only one way in. The screen was never a control layer for the system. It was a control layer for one route into it. That distinction did not matter until a second route existed.

Why does agentic AI expose this governance gap now?

Because of where the remaining work sits. As Sean Catlin sets out in OSF's point of view on the agentic enterprise, even mature organizations have automated only 30 to 40 percent of a typical priority process domain. The other 60 to 70 percent is still executed by people in email, spreadsheets, chat threads, and manual handoffs. That split matters more than it first appears, and not only as a measure of opportunity. The automated portion carries explicit governance by construction. You cannot automate a process without stating its rules, because the machine will not infer them. Every rule in that 30 to 40 percent had to be written down to work at all, which also means it already governs both routes. The unautomated portion carries no such thing. It has been governed by judgment, convention, and the friction of the interface. It works because experienced people know the exceptions, and because doing the wrong thing has always taken deliberate effort. Agentic systems are aimed precisely at that 60 to 70 percent. That is the entire point of them. Which means the governance deficit is not spread evenly across the enterprise. It is concentrated exactly where the new capability is being applied.

Why are permissions not the same as agentic AI governance?

Platform vendors are correct that agents inherit the identity, permissions, sharing rules, and compliance controls already defined in the system. Salesforce says so directly of Headless 360, and it is a substantial protection. Permissions are one of the few controls that genuinely travel with the actor rather than with the route. It is also a narrower claim than it sounds, because permissions answer one question: what can this actor reach? Governance answers four more, and all four were route-dependent. In what order? Sequence was enforced by screen design, not by permissions. At what scale? An agent operating entirely within its permissions can still act on a thousand records where the intent was ten. Reach and volume are different controls. At what moment? Batch timing, business hours, and freeze periods were previously enforced by when people were at their desks. With what escalation? The unwritten rule that certain cases get a second pair of eyes usually lives in someone's head, not in an approval object. An organization with an immaculate permission model can be fully exposed on all four. Catlin's argument in the OSF Digital whitepaper is that enterprise governance should be treated as a feature rather than a constraint, and that security, auditability, manageability, and human oversight are the conditions under which AI can be trusted at scale. This is what that means concretely. The feature set has to cover more than access, and it has to be independent of how the system is reached.

Does this mean fixing your governance before deploying AI agents?

No, and this is where the market advice goes wrong in a familiar way. The dominant integrator narrative says analyze everything, repair the foundations, and only then begin. OSF's position is the opposite, and deliberately so: capture the first wave of value by orchestrating the work that exists today, then re-engineer from a position of evidence. Sequential multi-year programs do not ship. AI leadership is measured by how effectively organizations turn agentic potential into a new way of operating. Sean Catlin EVP and Global Head of Strategy, OSF Digital The same sequencing applies to governance. The objective is not a complete policy inventory before anything runs. It is to write down the rules that the first production process actually depends on, at the moment you put that process into production. That work is small and specific. For one process: what has to happen in what order, how many records a single action may touch, when it may run, and what gets escalated to a person. Four questions, one process, answered during the build rather than in an assessment that precedes it. Do that five times and you have something better than a policy document. You have a governance model derived from live processes rather than from a workshop, and one that holds whichever route the work arrives on.

What should leaders do about agentic AI governance first?

Ask what your interface has been enforcing. For the process you intend to agentify first, list the rules nobody wrote down. Experienced operators can produce that list in an hour, and it is usually longer than anyone expects. Separate reach from scale. Confirm that someone owns the question of how much a single automated action may affect. In most organizations today, nobody does, because nobody has needed to. Put governance in the build, not the gate. If governance arrives as a review after the process is designed, it becomes the constraint the integrator narrative claims it is. Designed in alongside delivery, it is a specification. Give the digital workforce an owner. The question of who governs agents once they are doing meaningful work is an operating model question, not a technical one, and it belongs to the center of excellence rather than to a project. The uncomfortable part of this shift is not that the technology is unproven. It is that organizations are about to find out how much of their operating discipline was never a decision, and how much of it was just the way the screen happened to work.

Where this leads

The organizations that handle this well will not be the ones with the most complete policy library. They will be the ones that treated the first five processes as an opportunity to write down what they had never had to state, and built controls that hold no matter which route the work arrives on. Talk to OSF about where to start.

Frequently asked questions about agentic AI governance

Do AI agents replace the Salesforce user interface? No. Salesforce has stated that Lightning and browser experiences are not going away. Agents reach the same data and actions through APIs and open standards rather than through screens, which creates a second route to the system rather than a replacement for the first. What is agentic AI governance? Agentic AI governance is the set of controls that determine how autonomous AI systems act within a business process: what they can reach, in what order they act, how many records a single action may affect, when they are permitted to run, and what gets escalated to a person. It extends beyond access permissions, which answer only the first of those questions. Do AI agents inherit our existing Salesforce permissions? Yes. Salesforce states that agents inherit the identity, permissions, sharing rules, and compliance controls already defined in the org. That covers what an agent can reach. It does not by itself govern sequence, volume, timing, or escalation, which were previously enforced by the interface rather than by the permission model. What is the difference between permissions and governance for AI agents? Permissions define reach: which objects, fields, and records an actor can access, and they apply the same way regardless of how the system is reached. Governance defines behavior within that reach: order of operations, scale of a single action, permitted timing, and escalation thresholds. An organization can have a well-maintained permission model and still have no defined answer to any of the four. Why does agentic AI create governance exposure that automation did not? Traditional automation required rules to be written down, because a rules-based system cannot infer them. According to OSF Digital's point of view on the agentic enterprise, that work covered roughly 30 to 40 percent of a typical process domain. The remaining 60 to 70 percent has been governed by human judgment and interface friction rather than by documented rules, and it is exactly the portion agentic systems are designed to address. Do we need to document all our processes before deploying AI agents? No. Documenting everything before starting is the approach that produces multi-year programs and no shipped value. The workable scope is the governance the first production process requires, defined during that build, and repeated per process as you expand. Who should own AI agent governance in an enterprise? In practice it belongs with the center of excellence that owns the agentic operating model, working with process owners and security rather than being handed to either alone. It is an operating model responsibility, not a project deliverable. How do you control how much damage a single AI agent action can cause? By treating volume as a distinct control from access: setting explicit limits on how many records a single action may affect, exposing governed process steps rather than raw object access, and defining escalation thresholds. These are design decisions made at build time, not settings that exist by default.
Contact: Kateryna Melkomukova
Sign up for the latest news, trends and insightsSUBSCRIBE
BROWSE AND READFor More On This Topic
This Is Not Another Technology Cycle: An Executive Point of View on the Agentic EnterpriseThis Is Not Another Technology Cycle: An Executive Point of View on the Agentic Enterprise
White Papers
Pilots are succeeding. Scale is not following. The narrative coming from AI platforms, global integrators, and AI-native specialists is contradictory by design. This paper sets out the honest view: where enterprises actually are after two decades of automation, why 60 to 70 percent of priority process work is still human-executed, and what the agentic enterprise actually requires from your operating model, your architecture, and your delivery approach.Download
Six Questions That Determine Whether Agentic AI Scales in the EnterpriseSix Questions That Determine Whether Agentic AI Scales in the Enterprise
Blog
Most agentic AI pilots work; far fewer reach production. Six questions enterprise leaders should answer before scaling, and why method beats the platform alone.Read more
A Guide to Salesforce Headless 360A Guide To Salesforce Headless 360
Blog
Salesforce Headless 360 turns your CRM from a place you log in to an engine that powers work across Slack, voice, mobile, and AI agents. A guide for leaders. Read more