Not All AI Agents Need the Same Rules

Not every AI agent in your CRM needs the same rules, and the organisations that understand this are about to pull ahead. The most encouraging finding in enterprise AI this year is not that agents work, though they increasingly do. It is that the teams getting real value are the ones learning to govern each agent according to what it actually does, rather than wrapping every agent in one blanket policy and hoping for the best.

In late May 2026, Gartner published guidance that cuts against the instinct of almost every risk committee it has met. Applying uniform governance across all AI agents, regardless of their autonomy level and scope, will lead to enterprise AI agent failure. The analyst went further, predicting that by 2027 a large share of enterprises will demote or decommission autonomous agents because governance gaps only surfaced after something went wrong in production. Read pessimistically, that is a warning. Read the way we prefer to read it, it is a roadmap: the fix is known, it is practical, and the teams who adopt it first get to move faster than everyone still arguing about a single master policy.

For CRM leaders juggling Salesforce, HubSpot and Dynamics 365, this is genuinely good news. You do not need a perfect, all-encompassing AI policy before you let agents do useful work. You need a way to sort agents by risk and match the controls to the job. That is a far more achievable goal, and it is one you can start on this quarter.

Why does treating every AI agent the same hold teams back?

Most enterprises reached for uniform governance for an understandable reason: it felt safe and it was simple to explain to a board. One policy, one approval flow, one set of guardrails applied to everything from a chatbot that drafts email replies to an agent that can update pipeline records and trigger renewals. The trouble is that this simplicity quietly punishes the low-risk agents while under-protecting the high-risk ones.

Why does uniform AI governance cause agent failure? Uniform governance fails because it treats agents as if they carry equal risk when they do not. Gartner’s core observation is that enterprises tend to see agent governance as binary, either locked down or fully trusted, when in reality agents operate at different autonomy levels and across different trust boundaries. A blanket lockdown smothers the simple agents in approvals they never needed, so people stop using them or route around them. The same blanket, stretched to cover a highly autonomous agent, leaves dangerous gaps because it was never designed for that level of access. The result is friction where you wanted adoption and exposure where you wanted safety.

The upside is that the failure mode is completely avoidable. Once you accept that a summarising agent and an agent that can move money or change a customer record are not the same animal, the path forward becomes obvious. You govern them differently, and both get better.

What is tiered AI agent governance?

What is tiered AI agent governance? Tiered AI agent governance is an approach that sorts agents into levels based on how much autonomy they have and how sensitive the systems they touch are, then applies proportionate controls to each level. A read-only agent that summarises account activity sits in a light-touch tier with minimal oversight. An agent that can write to CRM records, send external messages or trigger downstream processes sits in a stricter tier with logging, human review on defined actions, and tighter access scopes. The point is proportion: controls scale with consequences, so low-risk agents stay fast and high-risk agents stay safe.

This is not a new idea in disguise. It is how mature organisations already govern people. A junior team member and a finance director do not have the same system permissions, the same spending authority or the same review requirements, because their roles carry different consequences. Tiered agent governance simply extends that common sense to software that now acts on its own. The tiers give you a shared language for a question every CRM team is about to face repeatedly: how much rope does this particular agent get?

How do you classify an AI agent’s autonomy level?

How do you classify an AI agent’s autonomy level? Classify an agent by asking three questions: what can it read, what can it change, and how far do its actions reach without a human. An agent that only reads data and suggests a next step is low autonomy. An agent that drafts an action for a person to approve is medium autonomy. An agent that executes changes to records, systems or communications on its own is high autonomy. Layer on data sensitivity, whether it touches customer records, financial data or personal information, and you have a simple grid that tells you which tier an agent belongs in.

The practical value of this exercise is that it forces a conversation many teams keep postponing. When you sit down to place your Agentforce, Copilot or HubSpot agents on the grid, you quickly discover that most of them are lower risk than the anxiety around them suggests. A large share of CRM agents read, summarise and suggest. Those can be released with light governance and start earning their keep immediately. The genuinely autonomous, high-consequence agents are usually a smaller set, which means your heavy governance effort can concentrate where it matters instead of being spread thin across everything.

What is a trust boundary, and why does it matter for CRM agents?

What is a trust boundary for an AI agent? A trust boundary is the line an agent crosses when it moves from a contained, low-stakes context into one where its actions affect customers, revenue or regulated data. An agent summarising internal notes sits inside a safe boundary. The moment that agent can email a customer, alter a contract record or push data into a finance system, it has crossed into a higher-trust zone that warrants stronger controls. Mapping these boundaries tells you exactly where to place your approval steps, logging and access limits.

Trust boundaries are where uniform governance does its quiet damage, and where differentiated governance pays off fastest. In a multi-platform CRM estate, an agent might read from Dynamics, write to Salesforce and trigger a message through a marketing tool, crossing several boundaries in a single workflow. A one-size policy either blocks that whole chain out of caution or waves it through out of convenience. Governing by boundary lets you keep the safe steps frictionless and put a checkpoint precisely at the moment the agent reaches into a system where mistakes are expensive. That is how you get speed and safety in the same workflow rather than trading one for the other.

How does differentiated governance help you deploy faster?

How does differentiated governance accelerate AI deployment? Differentiated governance accelerates deployment because it removes the bottleneck of treating every agent as high risk. When low-risk agents can go live under light-touch rules, teams stop waiting months for a single all-encompassing policy and start capturing value from the easy wins straight away. Meanwhile the high-risk agents get the focused scrutiny they deserve. Analysts tracing why agents get pulled from production point less to weak models and more to unclear success criteria and missing data access, both of which a tiered model forces you to define upfront, tier by tier.

This is the part CRM leaders should find most motivating. The organisations that will win with agents are not the ones with the strictest governance or the loosest. They are the ones with the most precise governance, applied at the right level to the right agent. Precision is what lets you say yes quickly and often to the many low-risk agents, while saying a careful, well-instrumented yes to the few that carry real consequence. Done well, governance stops being the thing that slows AI down and becomes the thing that lets you scale it with confidence.

Where should CRM leaders start?

What should CRM leaders do first about agent governance? Start by inventorying the agents already running or planned across your CRM platforms, then place each one on a simple grid of autonomy and data sensitivity. Define two or three tiers, agree the controls for each, and release your low-risk agents under the lightest tier without further delay. Reserve your detailed review, logging and human-in-the-loop steps for the agents that cross into customer, revenue or regulated territory. Revisit the grid quarterly, because an agent’s tier can change as its permissions grow.

None of this requires a heroic transformation programme, and that is rather the point. It is a structured afternoon of classification, a short agreement on what each tier allows, and a decision to stop holding your simple agents hostage to your fear of the complex ones. Teams that take this step tend to be pleasantly surprised by how much value was sitting behind an overcautious policy, and how much calmer the high-risk conversations become once they are separated out and given proper attention. The capability is real and the opportunity is immediate. The only thing standing between most teams and it is the assumption that governance has to be one size.

The Sirocco perspective

In our work across Salesforce, HubSpot and Dynamics 365, we see the same pattern the analysts are now naming. The clients who struggle with agents are rarely the ones who moved too fast. They are the ones who tried to write a single perfect policy before letting any agent do anything, and stalled. As an independent CRM partner, we are not tied to one vendor’s view of how their agents should be governed, which lets us look at your whole estate and draw the tiers where they actually belong. We help teams inventory their agents, sort them by autonomy and trust boundary, and put proportionate controls in place so the easy wins ship now and the sensitive work gets the scrutiny it needs. Governed well, agents are one of the clearest opportunities in CRM today, and the path to getting there is more practical than most leaders expect.

If you would like a second, independent view on how to tier and govern the agents in your CRM, schedule a consultation with our team.

Get in Touch

If you are working out which of your CRM agents can be trusted to act on their own and which still need a human in the loop, we can help you draw those lines with confidence. Tell us where your agents run today and we will map a governance model that fits each one.

So where do you start?

As your long-term partner for sustainable success, Sirocco is here to help you achieve your business goals. Contact us today to discuss your specific needs and book a free consultation or workshop to get started!