The problem
Why this framework exists
In a twelve-month window ending April 2026, every major enterprise system of record opened its state to AI agents. Atlassian's Rovo MCP Server reached general availability February 3, 2026. Salesforce-hosted MCP servers reached general availability April 28, 2026. ServiceNow's AI Agent Fabric, which connects third-party agents to its platform via Model Context Protocol and agent-to-agent protocols, launched April 19, 2026. SAP's MCP Gateway went live in November 2025. Workday's Agent Gateway, built on MCP and A2A protocols, was announced June 2025.
Every one of those announcements describes how agents can read and write inside these systems. None of them addresses who authorized the agent to do so, what business state transition it was sanctioned to perform, or whose name is on the record when something changes.
That gap is not a technology problem. It is an organizational design problem. And it compounds every time an enterprise adds another agent on another substrate with another permission model.