34% of Companies Govern Their Agents Like Employees. Martech Futurist | August 28, 2026

Two days ago I argued that your leverage in a martech renewal equals the precision of the specification you bring to it. Four items published this week narrow that argument to a single line on the spec sheet. The clause that decides what your AI stack can actually do names who the agent is and what it may commit on your behalf. Most marketing organizations have written neither, and this week vendors and analysts started putting a price on both.

Okta shipped agent identity into its core product. Gartner published two datasets that put access control at the center of what buyers now fund. A practitioner piece in MarTech named the diagnostic step that makes any of it useful after something goes wrong. Read together, they move Identity and Permissions in my AI capability framework from an assumed condition to a priced, purchasable line item.

Here is the uncomfortable part. Marketing runs the most automated function in the enterprise, and marketing sits furthest from the identity provider that governs it.

Register every agent that touches a customer

Okta made Agent SSO generally available on August 24, bringing the open Cross App Access standard into the single sign-on product it sells to more than 20,000 customers. When a supported agent connects to an enterprise application, Okta registers it as a first-class identity in Universal Directory alongside employees, then issues short-lived, identity-governed tokens in place of stored credentials. Administrators assign, monitor, and update agent policy in the same console they use for people. Okta included it in core SSO at no additional charge and kept discovery, lifecycle management, and governance of unregistered agents in a separate paid product.

The number Okta published with the release does the real work. Thirty-four percent of organizations apply the same identity and security controls to their agentic workforce that they apply to human employees. Two out of three do not.

That gap has a specific shape inside marketing. Your bid management agent, your subject line generator, your on-site personalization engine, and your service deflection bot were each provisioned by a different team, in a different platform, on a static API key or a broadly scoped OAuth token. Nobody registered them anywhere. Nobody assigned them a human owner. When the contractor who built two of them left in March, their own access got revoked on schedule and the agents they created kept authenticating.

Tara DeZao, Director of Product Marketing for Ad Tech and Martech at Pega, named the mechanism precisely when I interviewed her on The Agile Brand podcast: "I consider agentic AI a layer… it's the connective tissue between being able to create something with generative AI, let's say, and then actually put it into production. So the agent acts autonomously on your behalf regardless of what it's doing, whether it's a marketing agent or a shopping agent."

On your behalf. That phrase carries a legal weight most marketing teams have not priced. Agile Brand Principle 4 commits you to respecting customers and their data. You cannot honor that commitment through an agent whose authority nobody wrote down.

Start with the inventory. The Agile Brand Guide wiki entry on identity resolution covers the customer side of this problem, and the discipline transfers: persistent profiles, survivorship, provenance, audit trails. Apply the same rigor to the non-human identities operating inside your stack.

Put customer identity and access on your 2027 buying list

Gartner surveyed 199 service and support leaders in April and May and published the results on August 26. AI spending in the function grew 38%. Overall function budgets grew 2%. Kim Hedlin, Director Analyst in the Gartner Customer Service and Support practice, described leaders redirecting spend away from labor and overhead toward technology, and named the open question as whether those investments produce measurable business value.

The finding that matters for martech buyers sits further down. Gartner identified three platform categories expected to deliver substantially greater value over the next two years: no-code agent builders, communications platforms as a service, and customer identity and access management.

Gartner placed customer IAM in a top-three value list for a function that spent the last decade buying case management and knowledge bases. Daniel O'Sullivan, Senior Director Analyst in the same practice, framed the shift as organizations moving from isolated AI use cases toward connected ecosystems of agents, and said the technologies creating the most value help organizations build, deploy, and govern those agents securely and at scale.

Service and marketing buy from the same vendors and increasingly run the same agents against the same customer records. The service function reached this conclusion first because its agents talk to customers all day and its budget stopped growing. Marketing is one planning cycle behind on both counts.

Price access control before someone else prices it for you

Gartner published a second forecast on August 26. The market for software that secures AI reaches nearly $4.783 billion in 2027, up 68.7% from $2.835 billion in 2026, and approaches $7.7 billion in 2028. Shailendra Upadhyay, Senior Principal Analyst, attributed the growth to enterprises securing AI systems against emerging vulnerabilities and supply chain attacks involving third-party and open-source software, and said AI initiatives without adequate security and visibility controls face a high risk of failure.

Two segment details belong in your budget conversation. AI governance platforms grow from $275 million in 2026 to $462 million in 2027. AI usage control grows 73%, the fastest rate in the category. And Gartner predicts that by 2029, more than half of successful cyberattacks on AI agents will exploit access control weaknesses and prompt injections.

More than half. The dominant failure mode for agents is an authorization problem, and you fix authorization by configuring it.

Work the numbers on a single workflow. Your personalization agent holds authority to issue promotional offers. The approved cap is 10%. Through a stale rule in the campaign platform, it issues 20% to a 60,000-record segment with a $180 average order value. Eight percent redeem. That is 4,800 orders carrying an extra ten points of discount, or roughly $86,000 of margin surrendered in one send.

Now the part that determines your recovery time. If that agent authenticates with a static API key shared across three workflows, revoking the key stops all three and you spend the afternoon explaining to two other teams why their campaigns went dark. If it holds a registered identity with tokens scoped per workflow, you revoke one scope in the console and the other two keep running. Same incident, two different Mondays. The difference costs a line in a contract you have not written yet.

Find out which layer failed before you fix anything

Allen Martinez, Chief AI Architect of the Brand Experience AI Operating System, published a piece in MarTech on August 26 that supplies the diagnostic discipline the other three items assume. His argument starts where most governance programs stop. Your audit trail worked, the record is complete, and it proves your AI did exactly the wrong thing in an email that already went out.

Martinez runs the same 20% offer through three scenarios that produce structurally identical receipts. In the first, the approved cap was 10% and enforcement failed: a stale rule, a permission that did not propagate, a gate that did not fire. That is an implementation bug and every team is ready for it. In the second, 20% was the approved rule and the system followed it exactly, and three quarters later the segment has learned to wait for the discount and full-price conversion has collapsed. Nothing broke. The rule was legitimate, correctly enforced, and wrong. In the third, marketing says the segment qualifies, finance says no offer may drop contribution margin below a floor, and revenue says strategic accounts get no generalized promotional pricing. All three rules govern the offer. Nobody with standing ever decided which one wins, so the build proceeded and a vendor default settled it.

He puts a name on the consequence: CMOs accumulate accountability for systems they did not configure, operating on rules nobody ever wrote down, at a volume no one can review.

He calls this the correction test. You have to tell whether the fix belongs in the rule, the control, the implementation, or the authority behind the rule, and whether you can prove the fix held the next time. An organization that passes the screenshot, board, and audit tests and fails this one has excellent forensics and no learning loop.

This is a second guiding principle I use in doing operational work. Intelligence tells you what happened and what is likely. Deciding which rule wins is a normative act, and it stays with a human who holds the standing to make it. Formalize that standing. The Agile Brand Guide entry on the AI Governance Board covers the charter mechanics: purpose, authority, scope, escalation paths, and decision rights including exception handling.

One warning about the fashionable fix. Matt Blumberg, CEO of Markup AI, described the emerging pattern when I interviewed him on The Agile Brand podcast: "AI has flipped the script on content creation: it used to be armies of writers producing lower quantities of really high-quality content, and what AI enables you to do is produce mass volumes of content but inherently with lower quality. A guardian agent is an AI system that corrects an AI system."

A guardian agent is an agent. It needs a registered identity, a scoped permission set, and a named human owner, on exactly the same terms as the agent it supervises. Teams that deploy correction layers without that discipline add a second unregistered actor to the incident they are trying to prevent.

Featured Insights

Okta. Okta Brings First-Class Identity to AI Agents With Agent SSO. August 24, 2026. Agent SSO reaches general availability, bringing Cross App Access into core Okta SSO at no additional cost, registering supported agents in Universal Directory and issuing short-lived tokens in place of stored credentials. Takeaway: Ask your identity team this week how many marketing agents appear in the directory. The answer sets your starting position.

Gartner. AI Spending by Customer Service Leaders Has Surged by 38%. August 26, 2026. AI spending up 38% against 2% overall budget growth across 199 service and support leaders, with customer IAM named among the three platform categories expected to deliver the greatest value. Takeaway: Add customer identity and access management to your 2027 martech evaluation list before your service counterpart buys it without you.

Gartner. Gartner Forecasts the Market for Securing AI Will Reach $4.8 Billion in 2027. August 26, 2026. The securing AI market grows 68.7% to nearly $4.783 billion in 2027, with AI usage control the fastest-growing segment at 73%, and Gartner predicting access control weaknesses and prompt injections behind more than half of successful attacks on AI agents by 2029. Takeaway: Put agent scope, token lifetime, and revocation procedure in the SOW for every agentic capability you buy this cycle.

MarTech. The AI Governance Test Most Marketers Are Missing. August 26, 2026. Allen Martinez separates implementation failures from rule failures from authority failures, and argues that auditability without a correction loop produces immaculate records of the same mistake. Takeaway: Add one line to your incident template: which layer failed, and who has standing to change it.

Key insights

  • An agent without a registered identity is an unpriced liability. Inventory every agent touching customer data, assign a named human owner to each, and record where its credential lives.

  • Scope tokens per workflow. Shared static keys convert a single-workflow incident into a multi-team outage, and you pay that difference in hours before you pay it in dollars.

  • Customer IAM belongs in the martech evaluation. Gartner's service data puts it in the top three value categories for the next two years, and marketing runs agents against the same records.

  • Authority conflicts resolve upstream or a vendor default resolves them for you. When marketing, finance, and revenue each hold a legitimate rule over the same decision, someone with standing settles the precedence before the build starts.

  • Every correction layer is itself an actor. Guardian agents, reviewer agents, and QA agents get the same registration, scope, and ownership treatment as the systems they check.

What to do this week

Pull the list of AI agents running against customer data in your function. For each one, write down four things: the human owner, the credential type, the maximum commitment it can make without approval, and who has standing to change that limit. Bring the rows you cannot complete to your identity team and your next vendor conversation.

Your leverage in the renewal equals the precision of the specification you bring to it. This week the specification with the shortest fuse names who your agent is and what it may promise in your name.

A closing note

As a two-time CEO and co-founder of a few companies, the document that took me longest to appreciate was the delegation of authority matrix. It reads like bureaucracy until the first time somebody commits the company to something they had no standing to commit it to, and then you understand that the matrix was never about control. It was about knowing, in advance, whose signature the commitment carried.

Marketing organizations are now deploying software that signs things. It sends offers, quotes prices, makes support promises, and adjusts spend, all on the company's behalf, at a volume no reviewer can keep up with. The delegation matrix for that population mostly does not exist. Writing it is unglamorous work that will take a few afternoons and prevent a quarter you would rather not spend explaining.

Write it before you need it.

Previous
Previous

CMSWire: Oreo Dunked in the Dark. Marketing Has Been Chasing That Moment Ever Since

Next
Next

You can only buy what you’re able to specify. Martech Futurist | August 26, 2026