The AI agent bottleneck isn't model performance — it's permissions
Workday says enterprise AI agents are hitting a permissions wall, so it is using its system of record to govern access and actions.
Intelligence analysis by GPT-5.4 Mini
The story argues that enterprise AI agents fail less on intelligence than on control: what they can touch, who they act for, and how their work is audited. Workday is positioning Sana and its record system as the permissioning layer for that problem, with Google Gemini Enterprise as the conversational front end.
Workday thinks smart robot helpers are not getting stuck because they are dumb. They are getting stuck because nobody is clearly telling them what they are allowed to do.
It is like giving a helper a giant office building but no key card rules. The helper might be clever, but it still needs to know which doors it can open and which papers it can touch.
Workday wants its own records and rules to be the place where those key cards live. That way, the helper can do useful work without making a mess.
Analysis
The core bottleneck
Workday’s view is that enterprise AI agents do not stall mainly because the models are weak. They stall because companies do not have a clean answer to a harder question: what is the agent allowed to do, on whose behalf, and under what rules?
Gerrit Kazmaier, Workday’s president for product and technology, said customers often run into trouble when they assemble agent systems themselves and connect them directly to raw data. In that setup, he argued, the organization’s security logic gets flattened and the output can become too broad.
Why HR and finance are different
The article stresses that accuracy matters more in HR and finance than in many other AI use cases. Being “close enough” is not acceptable when the system is paying people, closing books, or scheduling work. Small mistakes can compound because policy settings, role-based permissions, and org structures are tightly linked.
Workday says it addresses that by using Gemini as the base reasoning layer, then layering its own context engine and business-process logic on top. It also adds verification and classification models that check outputs before they are executed.
Governance as the product
Workday’s Sana system of record is meant to be the place where agent governance lives. The user is authenticated through Workday’s identity and security model, and Sana agents only act within that user’s current permissions. Workday says audit logs stay in its own system and with the customer, while Gemini keeps interaction logs.
The company also expanded its partnership with Google so Sana agents can be discovered in Gemini Enterprise. The broader message from the article is blunt: in regulated enterprise settings, agent capability is not enough; permissioning and ownership are part of the product.
Key points
- Workday says the main blocker for enterprise AI agents is permissions, not model quality.
- The company is using its system of record as the governance layer for agent actions.
- HR and finance workflows need tighter accuracy because small errors can have immediate consequences.
- Workday says Sana agents act only within the user’s current permissions and audit trails stay in Workday.
- Workday expanded its partnership with Google so Sana agents are discoverable in Gemini Enterprise.



