The firm is acquiring a machine-facing border
Portable agent identity, cross-platform action and digital human credentials point to a capability border through which people, agents and machines can contribute without permanent membership.
Workforce intelligence · Issue 4
AyEye — Workforce Management
Human systems in the agentic enterprise
Wednesday, 16 September 2026
A border is appearing around the agentic enterprise—but it is not the old corporate perimeter. AI agents can now carry portable identity between organisations, enterprise platforms are exposing their capabilities to agents from elsewhere, and consumer agents are beginning to transact inside business systems. At the same time, Europe wants human qualifications to travel in a digital wallet. The strategic question is becoming: which capability may cross your boundary, on whose authority, and what travels back out?
The executive brief
- DigiCert has made its AI Trust Manager generally available. It gives agents cryptographically signed “passports”, time-limited permissions and revocation across organisational boundaries. This is a supplier capability, not yet evidence of an accepted industry standard.
- Salesforce’s new AIforce architecture opens Salesforce data, logic and actions to outside AI interfaces. Its ecosystem includes agents and tools from major model providers, developers and an HR platform. The user interface is becoming less important than the governed capability behind it.
- Salesforce and Google Cloud say agents on their platforms can reason and act on shared data without bespoke integration. Their commerce integration will also let customers buy from inside Google’s AI surfaces while payment and order control remain with the merchant.
- The European Commission has proposed digital, verifiable qualifications and social-security documents. The parallel with agent passports suggests that portable proof—not employment status—could become the connective tissue of a mixed workforce.
- Air India offers a useful implementation signal. It reports that agents now execute multi-system customer work only above a 95% confidence threshold, with human oversight where required; the figures are company claims, not independently audited outcomes.
- Physical and professional work are reorganising around objectives rather than applications. Agility’s new humanoid is designed to share human space, while Autodesk is previewing AI that follows a project across products and teams.
ORIGINAL SYNTHESIS · Confidence: medium-high · Horizon: 12–36 months
The firm is acquiring a machine-facing border
Portable agent identity, headless enterprise platforms, agentic commerce and digital human credentials look like separate developments. Together they point to a new organisational layer: a capability border that admits useful work without surrendering control of the enterprise.
Signal one: an agent can arrive with a passport
REPORTED FACT. On 15 September, DigiCert announced general availability of AI Trust Manager. Its “AI Passport” is a portable, cryptographically signed credential intended to identify an agent and connect it to an accountable owner. Policy-based “visas” can specify which systems, data and actions an agent may access and for how long. A receiving organisation can deny access, while a kill switch can revoke the credential or quarantine the agent.
DigiCert says the credential can be verified by another company without both organisations sharing the same identity provider. That is the important part: trust is being designed to travel across corporate boundaries. The product’s effectiveness and interoperability at scale remain to be proven. DigiCert’s accompanying survey was vendor-sponsored and should not be treated as neutral prevalence data. DigiCert announcement, 15 September
ANALYSIS. Yesterday’s edition argued that an internal agent should earn a licence. A portable passport is different. It lets an external capability present evidence at the border: who owns me, what am I permitted to do, and how can my authority be withdrawn?
Signal two: the enterprise suite is becoming callable from elsewhere
REPORTED FACT. Salesforce announced AIforce on 15 September, a headless layer that exposes Salesforce data, workflows, business logic, permissions and actions to AI interfaces through MCP, APIs, plug-ins and skills. Its AgentExchange marketplace includes interfaces from Anthropic, AWS, Google and Microsoft, builders including Lovable and Vercel, and agents or tools from companies including DocuSign, Gamma, Jasper and Rippling.
The claims come from Salesforce, and availability varies by product and region. Even so, the architectural direction is clear: the system of record no longer expects all work to arrive through its own screen. Salesforce AIforce announcement, 15 September
ANALYSIS. Enterprise access used to be designed around employees logging into applications. Headless systems invert that assumption. An agent working in Claude, Gemini, Slack or another interface can potentially call a governed business capability without becoming a conventional application user.
Signal three: agents can act across platforms—and customers can enter the workflow
REPORTED FACT. Google Cloud and Salesforce said on 15 September that agents on their platforms can reason and act on shared Salesforce data without custom integration. The connection uses MCP and retains Salesforce permissions and row-level controls. They also announced Universal Commerce Protocol-powered checkout: from this autumn, shoppers will be able to purchase inside Google Search, AI Mode and Gemini while payment, compliance and order management remain on a merchant’s commerce infrastructure.
Cross-platform action is partly available and partly on a forward roadmap. Product integration is not the same as seamless organisational accountability. Google Cloud–Salesforce announcement, 15 September
ANALYSIS. This moves the enterprise boundary twice. A supplier’s agent can enter a company’s workflow; a customer’s agent can initiate a transaction that employees once handled. The external party is no longer merely sending a request. Its software may participate directly in objective delivery.
Signal four: people are acquiring portable proof too
REPORTED FACT. The European Commission proposed a Fair Labour Mobility package on 15 September. It includes a European Social Security Pass and a Skills Portability Act. Qualifications would be issued in a standard digital format, stored in the EU Digital Identity Wallet and verifiable across countries. The Commission also proposes faster digital recognition for regulated professions. These are legislative proposals, not enacted rules; the main skills measures would be phased in over several years if adopted. European Commission, 15 September
ANALYSIS. Human and machine identity systems are not equivalent. People possess rights, dignity and legal status that software does not. Yet both developments address the same coordination cost: useful capability is trapped when a receiving institution cannot verify what is being presented.
The capability border
| Outside the enterprise | Border question | Inside the objective | Exit evidence |
|---|---|---|---|
| Employee or contractor | Identity, qualification, right to work, obligations | Role and decision rights | Outcome, contribution, updated evidence |
| Supplier’s agent | Owner, version, tested capability, time-limited authority | Bounded action through tools and data | Trace, exceptions, revocation status |
| Customer’s agent | Mandate, consent, payment and fraud assurance | Discovery, negotiation or transaction | Receipt, commitment and dispute route |
| Robot or machine service | Safety certification, location, skill and maintenance state | Physical task and hand-offs | Telemetry, incident and service record |
The causal chain
| Signal | Constraint changed | Newly possible | Organisational consequence |
|---|---|---|---|
| Portable agent identity | Trust need not stop at one identity domain | External agents can present verifiable ownership and authority | Third-party risk begins to cover machine counterparties |
| Headless enterprise systems | Work need not enter through the vendor’s interface | Agents from many environments can call the same governed capability | Application access becomes objective-specific capability access |
| Agentic commerce | Customers need not personally navigate the seller’s workflow | Customer agents can discover and transact directly | Some service and sales work moves to the boundary between agents |
| Portable human credentials | Qualifications can be verified without slow manual translation | People can move faster between institutions and countries | Talent pools become more permeable and evidence-led |
ORIGINAL SYNTHESIS. The mixed workforce is becoming a federated capability market. Capability can be supplied by an employee, contractor, partner agent, customer agent or machine without every contributor becoming a permanent member of the organisation.
This does not abolish the firm. It changes what the firm must be good at. The scarce competence shifts from owning every resource to admitting, combining and withdrawing capability safely. Procurement knows counterparties and contracts; security knows identities and permissions; HR knows competence, rights and accountability; operations knows objectives and exceptions. The capability border is where those disciplines meet.
Unexpected connection
EU skills wallets + cryptographic agent passports + headless business systems + AI checkout
All four reduce the friction of moving capability across a boundary. The connection matters because enterprises may soon compose an objective from contributors they do not employ, software they do not host and customers who arrive through agents they have never seen. The organisational perimeter becomes a sequence of verifications and revocable mandates rather than a network address or payroll list.
PROVOCATION
The next contingent worker may never appear in your vendor-management system
A partner’s agent could enter through an MCP connection, use internal data for minutes, complete part of an objective and disappear. Commercially it may be a software feature; operationally it has contributed labour. If nobody records its owner, competence, mandate, decisions and exit, the enterprise has accepted contingent capability without contingent-workforce governance.
What if we are right?
Opportunity. Small firms could borrow sophisticated capability safely; large firms could assemble temporary teams across partners without months of integration; people could move between projects with portable proof rather than repeatedly re-establishing competence. The enterprise becomes more permeable without becoming indiscriminate.
Organisational consequence. Workforce planning expands from “how many people and agents do we own?” to “which capabilities can we verify, combine and withdraw?” HR, procurement, security and enterprise architecture need a shared counterparty model.
Likely horizon. Cross-platform agent access and portable agent credentials are available in partial form now. Controlled machine counterparties should appear within 12–24 months; broad, interoperable capability markets are a three-to-five-year possibility.
What would prove us wrong?
The thesis weakens if portable credentials remain vendor-specific, companies refuse external agents access to consequential systems, or cross-platform integrations prove too brittle and expensive. It also fails if liability cannot be allocated when multiple agents contribute to one outcome.
Human credentials may remain too coarse to represent real competence, while agents may change too quickly for any passport to stay meaningful. In that case, organisations will retain tightly integrated vendor stacks and conventional employment or outsourcing relationships rather than federated capability markets.
Optimistic possibility: permeability without precarity
A capability border could widen access rather than merely tighten control. A nurse, engineer or technician moving country could prove qualifications faster. A small supplier could contribute a specialised agent without surrendering its intellectual property. A disabled professional could combine personal assistive agents with verified expertise. A customer’s agent could handle routine negotiation while a human decides what matters.
The constructive design test is whether portability increases agency for people as well as utility for firms. Rights, attribution, consent and appeal must travel with human capability; ownership, limits and revocation must travel with machine capability.
EVIDENCE FROM PRACTICE · IMPLEMENTATION SIGNAL
Air India is turning confidence into a work-allocation rule
Air India is expanding Agentforce from refunds into multi-intent email resolution, passenger-name corrections and a knowledge assistant. It says the agent can split a customer email into several requests, call specialised sub-agents, validate information across systems, execute actions and produce one response. Eligible cases are automated only when confidence exceeds 95%, with human oversight where required.
The airline reports that refund turnaround fell from about 14 days to four hours and name corrections from three days to 30 minutes. Its environment spans more than 140 enterprise systems and over 30 agentic-AI initiatives. These are company-supplied figures reported by The Financial Express; they are not an independent evaluation and reveal neither error rates nor the share of cases eligible for automation. Financial Express, updated 15 September
ANALYSIS. A confidence threshold is not merely a model setting. It is a staffing rule. Raising it routes more work to people; lowering it expands delegated execution. That means the threshold should be managed against consequence, reversibility, customer vulnerability and reviewer capacity—not accuracy alone.
Confidence is only one axis of delegation
| Agent confidence | Consequence of error | Reversibility | Control state |
|---|---|---|---|
| High | Low | Easy | Automate and sample |
| High | High | Difficult | Require prior human approval |
| Low | Low | Easy | Ask, route or provide options |
| Low | High | Difficult | Stop and transfer with evidence |
WORK & ORGANISATION · OUTSIDE-IN ANALYSIS
Project context is beginning to outrank the application—and perhaps the job
Autodesk previewed a next-generation Assistant spanning architecture, engineering, construction, manufacturing and media workflows. It is intended to follow project context across products and teams, route work to different models or specialist capabilities and show downstream effects when a design changes. Customers will also be able to connect their own agents and tools. The expanded system is a preview, with rollout details expected in 2027. Autodesk announcement, 15 September
ANALYSIS. Knowledge work has usually been organised around professional roles using applications. Autodesk’s direction starts with the project: a change to a building can propagate into fabrication, cost, scheduling and operations, then summon the capabilities required to respond.
The same pattern can travel beyond design. In an agentic enterprise, a product launch, clinical pathway, acquisition or supply disruption could become a persistent context to which people and agents attach temporarily. Organisation design then shifts from stable departments handing work to one another towards objective-centred constellations.
Operating question. If the project context can route work itself, what is the manager for? Less task distribution; more priority, trade-off, resource legitimacy, conflict resolution and responsibility for the whole outcome.
PHYSICAL AI · REPORTED FACT + ANALYSIS
When the safety cage disappears, workforce planning enters the robot deployment
Agility Robotics unveiled Digit 5 on 15 September. The humanoid is designed to work near people without the physical barriers used in traditional automation. It uses human detection, visual and auditory intent cues and a separate safety controller that can slow, stop or place the robot into a seated state. Agility says Digit 4 has logged more than 65,000 operating hours; Digit 5 early access is planned for the first half of 2027 and general availability by the end of that year. Agility Robotics, 15 September
ANALYSIS. Traditional automation redesigns the facility around the machine. A mobile humanoid that shares aisles, shelves and stations asks the organisation to redesign the social system instead.
Safe separation used to make the boundary obvious. Cooperative proximity introduces dynamic questions: who may approach, how intent is signalled, how a worker challenges a machine priority, what happens during fatigue or distraction, and whether production incentives encourage people to ignore warnings. Safety performance is therefore jointly produced by robot behaviour, job design, staffing, training, pace and local culture.
Constructive interpretation. If the machine absorbs repetitive lifting and travel while people teach exceptions, coordinate flow and improve the system, physical work can become safer and more developmental. But those higher-quality roles must be designed; they do not emerge automatically from removing the cage.
CAPABILITY & SKILLS · ANALYSIS
Enterprise know-how can now be manufactured as synthetic practice
Salesforce and NVIDIA introduced Koa, a specialised CRM reasoning model, on 15 September. Salesforce says no customer data was used in training. Instead it created synthetic scenarios across more than 14 industries, pairing personas with tasks and mapping the action and tool sequence required to complete them. Koa is in selected pilots, with general availability expected in the US in winter 2026. Vendor benchmark claims should await external replication. Salesforce–NVIDIA announcement, 15 September
ANALYSIS. Yesterday’s edition examined employees teaching agents. Koa adds a materially different route: an organisation can turn its accumulated understanding of workflows into simulated practice environments, then train a model against them without copying individual customer records.
This suggests a new asset class: the enterprise practice corpus—not documents describing work, but scenarios containing objectives, constraints, tool calls, exceptions and successful trajectories. Learning teams already know how to build cases and simulations for people. Model teams know how to optimise against them. Together they could create shared practice environments in which humans and agents learn the same operating logic, then are assessed differently according to their rights and risks.
Limitation. Synthetic practice can faithfully reproduce yesterday’s assumptions at industrial scale. It needs counterexamples, dissent, edge cases and periodic challenge by people close to the work.
TENUOUS BUT PLAUSIBLE · Confidence: medium-low · Horizon: 24–60 months
Your customers may become part of the workforce
Google and Salesforce plan to let shoppers complete purchases inside Google’s AI experiences while the merchant retains payment, compliance and order control. Today this is commerce plumbing, not organisation design.
But follow the mechanism. A customer’s agent can interpret a need, search, compare, negotiate preferences and initiate a transaction. The seller’s agents can configure an offer, check inventory, route fulfilment and manage exceptions. Human sales and service employees meet only where judgement, emotion or dispute remains.
SPECULATION. Customers’ agents could eventually perform work that firms now count as sales, service, onboarding and administration. That is not “self-service” in the old sense: the customer is no longer doing the labour. An external automaton is participating in the supplier’s operating model.
What to watch. Agent-to-agent negotiation, mandate and consent standards, liability for unwanted purchases, service-level agreements designed for machines and customer agents requesting structured evidence rather than marketing copy.
GOVERNANCE · PORTABILITY
Humans must not receive the weaker passport
The EU proposal would put standardised qualifications and social-security documents into a digital identity wallet, with faster verification across borders. DigiCert’s product aims to give agents ownership, permission and revocation evidence across organisations.
ANALYSIS. There is an uncomfortable possibility: enterprises may create richer, more current and more machine-readable evidence for agents than for people. An agent passport might show version, owner, permitted tools, tested behaviour and recent performance, while a person is represented by a job title, degree and stale skills profile.
The answer is not to score people like software. It is to make human capability evidence more useful while preserving context and rights: validated work samples, current licences, experience with exceptions, peer recognition and the person’s ability to contest what the system says. Portability without agency becomes surveillance that follows the worker.
NOISE FILTER
“Open” does not mean interoperable, and a marketplace is not a labour market
Dreamforce announcements repeatedly use “open”, “headless” and “any interface”. Those are important architectural signals, but buyers should separate four claims:
- A protocol can connect two systems.
- Two products have a supported integration.
- Identity, permissions and telemetry survive the hand-off.
- Liability and accountability remain intelligible when the outcome fails.
Only the first two are primarily technical. The last two determine whether cross-enterprise agents can become dependable productive capacity. Do not mistake a catalogue of agents for an operating labour market until capability, price, evidence, accountability and exit are comparable.
Operating-model implication
Create a machine-counterparty rulebook
| Border decision | Question | Primary stewards |
|---|---|---|
| Admission | Which external human, agent or machine may contribute to this objective? | Business owner, HR, procurement, security |
| Proof | What identity, competence and ownership evidence is sufficient? | HR, IAM, legal, risk |
| Mandate | Which data, tools, funds and decisions are available, and for how long? | Architecture, finance, operations |
| Observation | Which actions, outcomes, exceptions and human overrides are recorded? | Operations, audit, employee representatives |
| Exit | What is revoked, retained, returned or deleted when work ends? | Security, legal, records, data owners |
The rulebook should not force every contributor into one category. Its purpose is to ensure that any capability crossing the enterprise boundary has enough proof, a narrow enough mandate and a clean enough exit.
Human control watch
Assistance: an external tool supplies information; an employee retains the task and decision. Control sits with source selection and verification.
Delegated execution: an identified external agent performs bounded steps inside enterprise systems. Control sits with the mandate, entry checks and review capacity.
Autonomous control: agents on different sides of the boundary negotiate or transact within preset limits. Control sits with protocols, financial limits, monitoring, dispute handling and revocation.
Today’s shift: human control is moving from supervising a known internal tool to governing an unfamiliar machine counterparty. The receiving organisation must be able to refuse, constrain and remove it even when another company issued its credentials.
Capability-model update
| Gaining value | Under pressure |
|---|---|
| Machine-counterparty architect | Employee-only access models |
| Portable evidence designer | Job title as proxy for capability |
| Objective constellation lead | Application-centred process ownership |
| Agent-entry and exit controller | Permanent credentials for temporary work |
| Enterprise practice-corpus curator | Static process documentation |
| Human–robot environment designer | Safety defined only by physical separation |
ONE THING
IF I WERE TO DO ONE THING NOW
Trace one capability crossing
EXTERNAL AGENT ○ ─── ◇ VERIFY ─── □ ONE WORKFLOW ─── ✕ REVOKE
Choose one live workflow in which an external model, agent, supplier tool or customer-facing AI touches company data or takes an action, and ask its business owner, security lead and HR or procurement partner to trace that single crossing this week: who owns the capability, what evidence is checked, what it may do, what is recorded and how access ends. Do not launch a programme or build an inventory; produce one reviewed border trace for one real objective. It will reveal whether existing access controls describe the work as it actually happens and create a reusable pattern for the next crossing.
Mental-model update
Two days ago, the mixed workforce became something that needed a lifecycle of earned authority. Yesterday, it acquired an executable constitution that travels with the work.
Today it gains a border—not a wall, but a membrane. People, agents and machines can contribute without permanent membership, provided identity, capability, mandate, evidence and exit remain legible.
The emerging North Star is a permeable enterprise: open enough to assemble the best capability around an objective, disciplined enough to protect people and purpose when capability comes from elsewhere.
Questions for the executive table
- Which external agents can already reach your enterprise systems, and which function believes it owns that decision?
- If a partner’s agent causes harm inside your workflow, can you identify its owner, version, mandate and contribution without reconstructing the event manually?
- Where are people still asked to prove capability with weaker, older evidence than the agents being introduced beside them?
- Which objectives would benefit from temporary capability constellations rather than another permanent team or systems integration?
- When a customer’s agent performs sales or service work, who designs the experience, the control and the route for human disagreement?
Evidence note. DigiCert, Salesforce, Google Cloud, NVIDIA, Autodesk and Agility Robotics describe their own products, partnerships and plans; availability and performance claims are not the same as independently verified outcomes. The EU package is proposed legislation. Air India’s results are company-supplied and do not disclose error rates or eligibility volumes. Original concepts in this edition—capability border, federated capability market, objective-centred constellation, enterprise practice corpus and machine counterparty—are AyEye analysis, not claims made by the cited sources.
