A blueprint for IT and AI leadership
Opening a system of record is not one decision. It is five.
Give access in stages and let each stage be earned by evidence from the one before. Agents start with no connection at all, then reach mail and documents, then read the systems of record through a prepared copy, then write through one narrow path, and only then get distributed across the company. By the time the write question is real you know which uses people adopt, what your data can support, and who is accountable. Deciding it up front means deciding without any of that.
The shape of it
What you are optimizing for changes halfway up
Less than most organizations apply, until the moment it needs much more. While agents have no write access and run on enterprise accounts, the access boundary is doing the safety work and the goal is speed of learning. Once something works well enough that other functions want it, the goal changes to reliability and reuse, and ownership, traceability and a quality bar become necessary. Most programmes fail by applying one posture to both halves.
Production governance on rung one means nothing ever ships. Experiment governance on rung four means an agent writes to a system of record with no owner and no log. The five rungs below are the same five decisions in the order they actually arrive, and each one is set out the same way: why you climb it, what you are optimizing for, what can go wrong, how it works, and what has to be true before you leave it.
The climb
Five rungs, in the order they arrive
Each rung is set out the same way: why you climb it, what you are optimizing for, what can go wrong, how it works, and what has to be true before you leave it. The ground shifts as you go, from the cool end of the experiment to the warm end where this becomes company infrastructure.
Rung 01 of 05Experiment
People cannot specify the tool they have never held. Ask a leadership team which agents they want and you get a list of what they already do, slightly faster. Give them two working ones and the requests change completely within a fortnight. This rung exists to change what the organization can imagine, and it is the rung where IT carries no new risk at all.
Speed of learning. The number of people who form a daily habit.
One real one: people paste confidential material into consumer accounts, and enterprise accounts before anything else closes it. The other risk is treating this rung as the destination, running a successful pilot and stopping. That is the common failure and it looks like success for about a quarter.
Skills defined as instructions plus reference files, held in the user's own workspace. The person uploads what the work needs. No connection to any system.
Two or three uses are in genuine daily use by people who are not enthusiasts, and the requests coming back are for the tool to see something it cannot currently see.
Rung 02 of 05Experiment
The first thing every one of those requests asks for is context the person already has: the thread, the calendar, last quarter's deck. This is the cheapest capability increase available, and it runs entirely inside collaboration tooling you already govern.
Removing the copy and paste. The tool stops being a place you visit and becomes part of the working day.
Access is granted per person and inherits that person's permissions, so an over-permissioned employee becomes an over-permissioned agent. That is an existing access-governance problem AI makes visible rather than a new one, and it is worth resolving on its own terms. Expect central IT policy to be the blocker rather than technology.
Connectors to mail, calendar and the document store, scoped read only, under the individual's existing rights. Shared assets many skills draw on, such as the presentation template and brand basics, are installed at tenant level rather than carried around by each person.
People start asking questions whose answer lives in the CRM or the ERP.
Rung 03 of 05Experiment
Read from a prepared copy, never from production. Direct access to a live system of record means a jump host, a security review and a queue, and nothing at this stage needs live data. Export the twenty to fifty attributes that carry the meaning into a separate store, joined into a shape an agent can use, with a protocol layer over it. Choosing those attributes is the whole job and it belongs to whoever owns the data, not whoever owns the database. Handing over the full schema produces an agent that retrieves confidently and wrongly.
Everything up to here improves how an individual works. Reading the systems of record is where the conversation moves to the business, and it is the first rung where IT does substantial work. It is also, in practice, the rung that resolves the write debate, because it is where you find out what your data is actually like.
Learning two things at once: whether agents grounded in real data produce materially better judgment, and whether the data can support it. The second answer is frequently no at first, and finding that out on a copy costs nothing.
Going to production. A jump host, a security review and a queue, and a month before anyone learns anything. Dumping the schema. Hundreds of tables produce an agent that retrieves confidently and wrongly. Silent staleness. An agent reading partial data answers anyway, so coverage has to be stated rather than assumed.
A curated export from the warehouse into a separate store, joined into a shape an agent can use, with a protocol layer over it. The legacy system is not touched and not replaced. It gains an interface.
Bring in the data owner and process owner now, while the request is only to read. They are the people whose agreement rung four will require, and they will have spent a rung watching it work before anyone asks them for it.
Grounded answers are demonstrably better than ungrounded ones, the data gaps are documented, and the system owner has seen enough to have an opinion about writing.
Traceability scales with autonomy. Not with access.
Rungs one to three are an experiment, and the access boundary does the safety work. From rung four the goal changes to reliability, ownership and reuse.
Rung 04 of 05Industrialize
Not broad write permission, which nobody should grant. A narrow, mediated write path is a different proposition. A gateway exposes one operation rather than the API, the agent writes a defined structure rather than free prose, and a human approves each write until the approvals stop changing anything. The common fear is that agents degrade CRM data. In practice the free-text fields are already inconsistent because writing them is manual work that competes with selling, and a skill writing the same fields in the same shape every time tends to improve the record.
The objection to write access is that AI will degrade the data. It is a reasonable fear, it is pointed at broad write permission, which nobody should grant, and it is not an argument against writing. Look at what the free-text fields in a mature CRM contain today. One person writes three words. Another writes everything that was said. Most write nothing, because the meeting is over and the next one starts in five minutes.
Getting knowledge out of individual inboxes and into shared systems. A meeting outcome sitting in one person's mail is invisible to the company. The same outcome on the customer record is available to everyone who touches that account next.
Broad write scopes, obviously. Less obviously, writes that no human ever reads back, which is how a small systematic error becomes ten thousand records. And accountability going vague at exactly the moment it starts to matter.
Constrain the surface. A gateway exposes one operation, not the API. Create an activity. Nothing else. Constrain the shape. The agent writes a defined structure rather than free prose, in a field the system already has. Keep a person in the loop, at first. Every write is proposed and approved until the approvals stop changing anything.
The write path has run under human approval long enough to have a boring error rate, and the system owner will say so in writing.
Rung 05 of 05Industrialize
No new permission is granted here. Something built by one team turns out to be wanted in six countries, and without somewhere to put it you get one of two bad outcomes: everyone rebuilds it slightly differently, or a central team becomes a queue.
Reuse without a bottleneck, and consistency in what agents say about the company.
The first attempt is almost always a page of downloadable files with no version control behind it. It works for a month, then nobody knows which copy is current. The quieter risk: handing someone a skill is not the same as them using it, and a library measured on installs rather than use will look healthy while nothing changes.
A curated library people install from, filtered by role, with an owner, a version history and a published quality bar. And a company context layer every skill draws on: who we are, the competitive picture, how we write, the current template. Distribution carries the training with it.
Ownership has moved. A presentation skill used in four countries belongs to whoever owns the brand, because when the template changes the skill must change with it.
Underneath all five
The control layer
Traceability scales with autonomy, not with access. While a person asks and the agent answers, that person is the accountable actor, the conversation is the record, and existing controls cover it. When work runs without a person in the loop each time, three things become necessary: an identity per agent so actions are attributable, a log of what was done and on what basis, and a named human owner for every agent in production. Policies are not the mechanism, because nobody reads them. Build the rules into the tools people already use.
Policies are not the mechanism. Nobody reads the policy. Make the correct path the cheap one and build the rules into the tools people already use.
Governance fails in two directions. Too little is the one everyone anticipates. The other is a review body that meets and does not decide, and the early symptom is a long argument about vocabulary, usually whether a given tool counts as an agent. Give each decision a named owner and a date, and let the vocabulary settle later.
Where to start
The first ninety days
Weeks 1 to 4
Enterprise accounts. One leadership group on rung one. No integration work at all.
Weeks 4 to 8
Workspace connectors for that group. Open the rung-three scoping conversation with the data owner. It is a business conversation about which attributes matter, not a technical one.
Weeks 8 to 12
A curated extract in a separate store, and agents rebuilt against it. Choose the single write case that would most improve the record and design its gateway. Do not build it yet.
By then the organization argues from evidence rather than opinion. The system owners are already in the room, and the write decision has become small and specific.
Questions IT actually asks
How should you give AI agents access to company systems?
Give access in stages and let each stage be earned by evidence from the one before. Agents start with no connection at all, then reach mail and documents, then read the systems of record through a prepared copy, then write through one narrow path, and only then get distributed across the company. By the time the write question is real you know which uses people adopt, what your data can support, and who is accountable.
Should AI agents have write access to the CRM?
Not broad write permission, which nobody should grant. A narrow, mediated write path is a different proposition: a gateway that exposes one operation rather than the API, a defined structure rather than free prose, and a human approving each write until the approvals stop changing anything.
What data should an AI agent read first, and how?
Read from a prepared copy, never from production. Export the twenty to fifty attributes that carry the meaning into a separate store with a protocol layer over it. Choosing those attributes is the whole job, and it belongs to whoever owns the data rather than whoever owns the database.
How much governance does an AI pilot need?
Less than most organizations apply, until the moment it needs much more. While there is no write access and everyone is on enterprise accounts, the access boundary is doing the safety work. Once other functions want what you built, ownership, traceability and a quality bar become necessary.
How do you make AI agents traceable and accountable?
Traceability scales with autonomy, not with access. Once work runs without a person in the loop each time, you need an identity per agent, a log of what was done and on what basis, and a named human owner for every agent in production.
Six pages, no form.
The full blueprint sets out each rung with what you are optimizing for, the risks, how it works, and what has to be true before you climb.