Dominic Chiappe · People, capability & transformation

Thinking about how organisations perform in an AI-enabled world

AyEye — Workforce Management ·

The firm is acquiring a machine-facing border

Portable agent identity, cross-platform action and digital human credentials point to a capability border through which people, agents and machines can contribute without permanent membership.

Workforce intelligence · Issue 4

AyEye — Workforce Management

Human systems in the agentic enterprise

Wednesday, 16 September 2026

A border is appearing around the agentic enterprise—but it is not the old corporate perimeter. AI agents can now carry portable identity between organisations, enterprise platforms are exposing their capabilities to agents from elsewhere, and consumer agents are beginning to transact inside business systems. At the same time, Europe wants human qualifications to travel in a digital wallet. The strategic question is becoming: which capability may cross your boundary, on whose authority, and what travels back out?


The executive brief

  • DigiCert has made its AI Trust Manager generally available. It gives agents cryptographically signed “passports”, time-limited permissions and revocation across organisational boundaries. This is a supplier capability, not yet evidence of an accepted industry standard.
  • Salesforce’s new AIforce architecture opens Salesforce data, logic and actions to outside AI interfaces. Its ecosystem includes agents and tools from major model providers, developers and an HR platform. The user interface is becoming less important than the governed capability behind it.
  • Salesforce and Google Cloud say agents on their platforms can reason and act on shared data without bespoke integration. Their commerce integration will also let customers buy from inside Google’s AI surfaces while payment and order control remain with the merchant.
  • The European Commission has proposed digital, verifiable qualifications and social-security documents. The parallel with agent passports suggests that portable proof—not employment status—could become the connective tissue of a mixed workforce.
  • Air India offers a useful implementation signal. It reports that agents now execute multi-system customer work only above a 95% confidence threshold, with human oversight where required; the figures are company claims, not independently audited outcomes.
  • Physical and professional work are reorganising around objectives rather than applications. Agility’s new humanoid is designed to share human space, while Autodesk is previewing AI that follows a project across products and teams.

ORIGINAL SYNTHESIS · Confidence: medium-high · Horizon: 12–36 months

The firm is acquiring a machine-facing border

Portable agent identity, headless enterprise platforms, agentic commerce and digital human credentials look like separate developments. Together they point to a new organisational layer: a capability border that admits useful work without surrendering control of the enterprise.

Signal one: an agent can arrive with a passport

REPORTED FACT. On 15 September, DigiCert announced general availability of AI Trust Manager. Its “AI Passport” is a portable, cryptographically signed credential intended to identify an agent and connect it to an accountable owner. Policy-based “visas” can specify which systems, data and actions an agent may access and for how long. A receiving organisation can deny access, while a kill switch can revoke the credential or quarantine the agent.

DigiCert says the credential can be verified by another company without both organisations sharing the same identity provider. That is the important part: trust is being designed to travel across corporate boundaries. The product’s effectiveness and interoperability at scale remain to be proven. DigiCert’s accompanying survey was vendor-sponsored and should not be treated as neutral prevalence data. DigiCert announcement, 15 September

ANALYSIS. Yesterday’s edition argued that an internal agent should earn a licence. A portable passport is different. It lets an external capability present evidence at the border: who owns me, what am I permitted to do, and how can my authority be withdrawn?

Signal two: the enterprise suite is becoming callable from elsewhere

REPORTED FACT. Salesforce announced AIforce on 15 September, a headless layer that exposes Salesforce data, workflows, business logic, permissions and actions to AI interfaces through MCP, APIs, plug-ins and skills. Its AgentExchange marketplace includes interfaces from Anthropic, AWS, Google and Microsoft, builders including Lovable and Vercel, and agents or tools from companies including DocuSign, Gamma, Jasper and Rippling.

The claims come from Salesforce, and availability varies by product and region. Even so, the architectural direction is clear: the system of record no longer expects all work to arrive through its own screen. Salesforce AIforce announcement, 15 September

ANALYSIS. Enterprise access used to be designed around employees logging into applications. Headless systems invert that assumption. An agent working in Claude, Gemini, Slack or another interface can potentially call a governed business capability without becoming a conventional application user.

Signal three: agents can act across platforms—and customers can enter the workflow

REPORTED FACT. Google Cloud and Salesforce said on 15 September that agents on their platforms can reason and act on shared Salesforce data without custom integration. The connection uses MCP and retains Salesforce permissions and row-level controls. They also announced Universal Commerce Protocol-powered checkout: from this autumn, shoppers will be able to purchase inside Google Search, AI Mode and Gemini while payment, compliance and order management remain on a merchant’s commerce infrastructure.

Cross-platform action is partly available and partly on a forward roadmap. Product integration is not the same as seamless organisational accountability. Google Cloud–Salesforce announcement, 15 September

ANALYSIS. This moves the enterprise boundary twice. A supplier’s agent can enter a company’s workflow; a customer’s agent can initiate a transaction that employees once handled. The external party is no longer merely sending a request. Its software may participate directly in objective delivery.

Signal four: people are acquiring portable proof too

REPORTED FACT. The European Commission proposed a Fair Labour Mobility package on 15 September. It includes a European Social Security Pass and a Skills Portability Act. Qualifications would be issued in a standard digital format, stored in the EU Digital Identity Wallet and verifiable across countries. The Commission also proposes faster digital recognition for regulated professions. These are legislative proposals, not enacted rules; the main skills measures would be phased in over several years if adopted. European Commission, 15 September

ANALYSIS. Human and machine identity systems are not equivalent. People possess rights, dignity and legal status that software does not. Yet both developments address the same coordination cost: useful capability is trapped when a receiving institution cannot verify what is being presented.

The capability border

Outside the enterpriseBorder questionInside the objectiveExit evidence
Employee or contractorIdentity, qualification, right to work, obligationsRole and decision rightsOutcome, contribution, updated evidence
Supplier’s agentOwner, version, tested capability, time-limited authorityBounded action through tools and dataTrace, exceptions, revocation status
Customer’s agentMandate, consent, payment and fraud assuranceDiscovery, negotiation or transactionReceipt, commitment and dispute route
Robot or machine serviceSafety certification, location, skill and maintenance statePhysical task and hand-offsTelemetry, incident and service record
What to notice: the border does not decide whether something is “an employee”. It decides whether a specific capability may contribute to a specific objective, under a specific mandate, with evidence retained when the engagement ends.

The causal chain

SignalConstraint changedNewly possibleOrganisational consequence
Portable agent identityTrust need not stop at one identity domainExternal agents can present verifiable ownership and authorityThird-party risk begins to cover machine counterparties
Headless enterprise systemsWork need not enter through the vendor’s interfaceAgents from many environments can call the same governed capabilityApplication access becomes objective-specific capability access
Agentic commerceCustomers need not personally navigate the seller’s workflowCustomer agents can discover and transact directlySome service and sales work moves to the boundary between agents
Portable human credentialsQualifications can be verified without slow manual translationPeople can move faster between institutions and countriesTalent pools become more permeable and evidence-led

ORIGINAL SYNTHESIS. The mixed workforce is becoming a federated capability market. Capability can be supplied by an employee, contractor, partner agent, customer agent or machine without every contributor becoming a permanent member of the organisation.

This does not abolish the firm. It changes what the firm must be good at. The scarce competence shifts from owning every resource to admitting, combining and withdrawing capability safely. Procurement knows counterparties and contracts; security knows identities and permissions; HR knows competence, rights and accountability; operations knows objectives and exceptions. The capability border is where those disciplines meet.

Unexpected connection

EU skills wallets + cryptographic agent passports + headless business systems + AI checkout

All four reduce the friction of moving capability across a boundary. The connection matters because enterprises may soon compose an objective from contributors they do not employ, software they do not host and customers who arrive through agents they have never seen. The organisational perimeter becomes a sequence of verifications and revocable mandates rather than a network address or payroll list.

PROVOCATION

The next contingent worker may never appear in your vendor-management system

A partner’s agent could enter through an MCP connection, use internal data for minutes, complete part of an objective and disappear. Commercially it may be a software feature; operationally it has contributed labour. If nobody records its owner, competence, mandate, decisions and exit, the enterprise has accepted contingent capability without contingent-workforce governance.

What if we are right?

Opportunity. Small firms could borrow sophisticated capability safely; large firms could assemble temporary teams across partners without months of integration; people could move between projects with portable proof rather than repeatedly re-establishing competence. The enterprise becomes more permeable without becoming indiscriminate.

Organisational consequence. Workforce planning expands from “how many people and agents do we own?” to “which capabilities can we verify, combine and withdraw?” HR, procurement, security and enterprise architecture need a shared counterparty model.

Likely horizon. Cross-platform agent access and portable agent credentials are available in partial form now. Controlled machine counterparties should appear within 12–24 months; broad, interoperable capability markets are a three-to-five-year possibility.

What would prove us wrong?

The thesis weakens if portable credentials remain vendor-specific, companies refuse external agents access to consequential systems, or cross-platform integrations prove too brittle and expensive. It also fails if liability cannot be allocated when multiple agents contribute to one outcome.

Human credentials may remain too coarse to represent real competence, while agents may change too quickly for any passport to stay meaningful. In that case, organisations will retain tightly integrated vendor stacks and conventional employment or outsourcing relationships rather than federated capability markets.

Optimistic possibility: permeability without precarity

A capability border could widen access rather than merely tighten control. A nurse, engineer or technician moving country could prove qualifications faster. A small supplier could contribute a specialised agent without surrendering its intellectual property. A disabled professional could combine personal assistive agents with verified expertise. A customer’s agent could handle routine negotiation while a human decides what matters.

The constructive design test is whether portability increases agency for people as well as utility for firms. Rights, attribution, consent and appeal must travel with human capability; ownership, limits and revocation must travel with machine capability.


EVIDENCE FROM PRACTICE · IMPLEMENTATION SIGNAL

Air India is turning confidence into a work-allocation rule

Air India is expanding Agentforce from refunds into multi-intent email resolution, passenger-name corrections and a knowledge assistant. It says the agent can split a customer email into several requests, call specialised sub-agents, validate information across systems, execute actions and produce one response. Eligible cases are automated only when confidence exceeds 95%, with human oversight where required.

The airline reports that refund turnaround fell from about 14 days to four hours and name corrections from three days to 30 minutes. Its environment spans more than 140 enterprise systems and over 30 agentic-AI initiatives. These are company-supplied figures reported by The Financial Express; they are not an independent evaluation and reveal neither error rates nor the share of cases eligible for automation. Financial Express, updated 15 September

ANALYSIS. A confidence threshold is not merely a model setting. It is a staffing rule. Raising it routes more work to people; lowering it expands delegated execution. That means the threshold should be managed against consequence, reversibility, customer vulnerability and reviewer capacity—not accuracy alone.

Confidence is only one axis of delegation

Agent confidenceConsequence of errorReversibilityControl state
HighLowEasyAutomate and sample
HighHighDifficultRequire prior human approval
LowLowEasyAsk, route or provide options
LowHighDifficultStop and transfer with evidence
A 95% confidence rule can be sensible for one task and reckless for another. The workforce design lives in the routing policy and the human capacity behind it.

WORK & ORGANISATION · OUTSIDE-IN ANALYSIS

Project context is beginning to outrank the application—and perhaps the job

Autodesk previewed a next-generation Assistant spanning architecture, engineering, construction, manufacturing and media workflows. It is intended to follow project context across products and teams, route work to different models or specialist capabilities and show downstream effects when a design changes. Customers will also be able to connect their own agents and tools. The expanded system is a preview, with rollout details expected in 2027. Autodesk announcement, 15 September

ANALYSIS. Knowledge work has usually been organised around professional roles using applications. Autodesk’s direction starts with the project: a change to a building can propagate into fabrication, cost, scheduling and operations, then summon the capabilities required to respond.

The same pattern can travel beyond design. In an agentic enterprise, a product launch, clinical pathway, acquisition or supply disruption could become a persistent context to which people and agents attach temporarily. Organisation design then shifts from stable departments handing work to one another towards objective-centred constellations.

Operating question. If the project context can route work itself, what is the manager for? Less task distribution; more priority, trade-off, resource legitimacy, conflict resolution and responsibility for the whole outcome.


PHYSICAL AI · REPORTED FACT + ANALYSIS

When the safety cage disappears, workforce planning enters the robot deployment

Agility Robotics unveiled Digit 5 on 15 September. The humanoid is designed to work near people without the physical barriers used in traditional automation. It uses human detection, visual and auditory intent cues and a separate safety controller that can slow, stop or place the robot into a seated state. Agility says Digit 4 has logged more than 65,000 operating hours; Digit 5 early access is planned for the first half of 2027 and general availability by the end of that year. Agility Robotics, 15 September

ANALYSIS. Traditional automation redesigns the facility around the machine. A mobile humanoid that shares aisles, shelves and stations asks the organisation to redesign the social system instead.

Safe separation used to make the boundary obvious. Cooperative proximity introduces dynamic questions: who may approach, how intent is signalled, how a worker challenges a machine priority, what happens during fatigue or distraction, and whether production incentives encourage people to ignore warnings. Safety performance is therefore jointly produced by robot behaviour, job design, staffing, training, pace and local culture.

Constructive interpretation. If the machine absorbs repetitive lifting and travel while people teach exceptions, coordinate flow and improve the system, physical work can become safer and more developmental. But those higher-quality roles must be designed; they do not emerge automatically from removing the cage.


CAPABILITY & SKILLS · ANALYSIS

Enterprise know-how can now be manufactured as synthetic practice

Salesforce and NVIDIA introduced Koa, a specialised CRM reasoning model, on 15 September. Salesforce says no customer data was used in training. Instead it created synthetic scenarios across more than 14 industries, pairing personas with tasks and mapping the action and tool sequence required to complete them. Koa is in selected pilots, with general availability expected in the US in winter 2026. Vendor benchmark claims should await external replication. Salesforce–NVIDIA announcement, 15 September

ANALYSIS. Yesterday’s edition examined employees teaching agents. Koa adds a materially different route: an organisation can turn its accumulated understanding of workflows into simulated practice environments, then train a model against them without copying individual customer records.

This suggests a new asset class: the enterprise practice corpus—not documents describing work, but scenarios containing objectives, constraints, tool calls, exceptions and successful trajectories. Learning teams already know how to build cases and simulations for people. Model teams know how to optimise against them. Together they could create shared practice environments in which humans and agents learn the same operating logic, then are assessed differently according to their rights and risks.

Limitation. Synthetic practice can faithfully reproduce yesterday’s assumptions at industrial scale. It needs counterexamples, dissent, edge cases and periodic challenge by people close to the work.


TENUOUS BUT PLAUSIBLE · Confidence: medium-low · Horizon: 24–60 months

Your customers may become part of the workforce

Google and Salesforce plan to let shoppers complete purchases inside Google’s AI experiences while the merchant retains payment, compliance and order control. Today this is commerce plumbing, not organisation design.

But follow the mechanism. A customer’s agent can interpret a need, search, compare, negotiate preferences and initiate a transaction. The seller’s agents can configure an offer, check inventory, route fulfilment and manage exceptions. Human sales and service employees meet only where judgement, emotion or dispute remains.

SPECULATION. Customers’ agents could eventually perform work that firms now count as sales, service, onboarding and administration. That is not “self-service” in the old sense: the customer is no longer doing the labour. An external automaton is participating in the supplier’s operating model.

What to watch. Agent-to-agent negotiation, mandate and consent standards, liability for unwanted purchases, service-level agreements designed for machines and customer agents requesting structured evidence rather than marketing copy.


GOVERNANCE · PORTABILITY

Humans must not receive the weaker passport

The EU proposal would put standardised qualifications and social-security documents into a digital identity wallet, with faster verification across borders. DigiCert’s product aims to give agents ownership, permission and revocation evidence across organisations.

ANALYSIS. There is an uncomfortable possibility: enterprises may create richer, more current and more machine-readable evidence for agents than for people. An agent passport might show version, owner, permitted tools, tested behaviour and recent performance, while a person is represented by a job title, degree and stale skills profile.

The answer is not to score people like software. It is to make human capability evidence more useful while preserving context and rights: validated work samples, current licences, experience with exceptions, peer recognition and the person’s ability to contest what the system says. Portability without agency becomes surveillance that follows the worker.


NOISE FILTER

“Open” does not mean interoperable, and a marketplace is not a labour market

Dreamforce announcements repeatedly use “open”, “headless” and “any interface”. Those are important architectural signals, but buyers should separate four claims:

  • A protocol can connect two systems.
  • Two products have a supported integration.
  • Identity, permissions and telemetry survive the hand-off.
  • Liability and accountability remain intelligible when the outcome fails.

Only the first two are primarily technical. The last two determine whether cross-enterprise agents can become dependable productive capacity. Do not mistake a catalogue of agents for an operating labour market until capability, price, evidence, accountability and exit are comparable.


Operating-model implication

Create a machine-counterparty rulebook

Border decisionQuestionPrimary stewards
AdmissionWhich external human, agent or machine may contribute to this objective?Business owner, HR, procurement, security
ProofWhat identity, competence and ownership evidence is sufficient?HR, IAM, legal, risk
MandateWhich data, tools, funds and decisions are available, and for how long?Architecture, finance, operations
ObservationWhich actions, outcomes, exceptions and human overrides are recorded?Operations, audit, employee representatives
ExitWhat is revoked, retained, returned or deleted when work ends?Security, legal, records, data owners

The rulebook should not force every contributor into one category. Its purpose is to ensure that any capability crossing the enterprise boundary has enough proof, a narrow enough mandate and a clean enough exit.


Human control watch

Assistance: an external tool supplies information; an employee retains the task and decision. Control sits with source selection and verification.

Delegated execution: an identified external agent performs bounded steps inside enterprise systems. Control sits with the mandate, entry checks and review capacity.

Autonomous control: agents on different sides of the boundary negotiate or transact within preset limits. Control sits with protocols, financial limits, monitoring, dispute handling and revocation.

Today’s shift: human control is moving from supervising a known internal tool to governing an unfamiliar machine counterparty. The receiving organisation must be able to refuse, constrain and remove it even when another company issued its credentials.


Capability-model update

Gaining valueUnder pressure
Machine-counterparty architectEmployee-only access models
Portable evidence designerJob title as proxy for capability
Objective constellation leadApplication-centred process ownership
Agent-entry and exit controllerPermanent credentials for temporary work
Enterprise practice-corpus curatorStatic process documentation
Human–robot environment designerSafety defined only by physical separation

1

ONE THING

IF I WERE TO DO ONE THING NOW

Trace one capability crossing

EXTERNAL AGENT ○ ─── ◇ VERIFY ─── □ ONE WORKFLOW ─── ✕ REVOKE

A thin border is safer than an invisible one: identity in, bounded work through, evidence and revocation out.

Choose one live workflow in which an external model, agent, supplier tool or customer-facing AI touches company data or takes an action, and ask its business owner, security lead and HR or procurement partner to trace that single crossing this week: who owns the capability, what evidence is checked, what it may do, what is recorded and how access ends. Do not launch a programme or build an inventory; produce one reviewed border trace for one real objective. It will reveal whether existing access controls describe the work as it actually happens and create a reusable pattern for the next crossing.


Mental-model update

Two days ago, the mixed workforce became something that needed a lifecycle of earned authority. Yesterday, it acquired an executable constitution that travels with the work.

Today it gains a border—not a wall, but a membrane. People, agents and machines can contribute without permanent membership, provided identity, capability, mandate, evidence and exit remain legible.

The emerging North Star is a permeable enterprise: open enough to assemble the best capability around an objective, disciplined enough to protect people and purpose when capability comes from elsewhere.

Questions for the executive table

  1. Which external agents can already reach your enterprise systems, and which function believes it owns that decision?
  2. If a partner’s agent causes harm inside your workflow, can you identify its owner, version, mandate and contribution without reconstructing the event manually?
  3. Where are people still asked to prove capability with weaker, older evidence than the agents being introduced beside them?
  4. Which objectives would benefit from temporary capability constellations rather than another permanent team or systems integration?
  5. When a customer’s agent performs sales or service work, who designs the experience, the control and the route for human disagreement?

Evidence note. DigiCert, Salesforce, Google Cloud, NVIDIA, Autodesk and Agility Robotics describe their own products, partnerships and plans; availability and performance claims are not the same as independently verified outcomes. The EU package is proposed legislation. Air India’s results are company-supplied and do not disclose error rates or eligibility volumes. Original concepts in this edition—capability border, federated capability market, objective-centred constellation, enterprise practice corpus and machine counterparty—are AyEye analysis, not claims made by the cited sources.