The smartest move you can make with your CRM AI agents this year is a familiar one: treat them like employees. Give each agent a name, a manager, a defined scope of work and a login you can revoke. It sounds obvious, yet it is also the single biggest opportunity sitting in front of revenue and IT leaders in 2026. The agents are already delivering. The teams that get the most from them next will be the ones that decide, deliberately, to govern every agent as a first-class identity.
This is good news, because identity is a discipline most organisations already understand. You onboard people, you scope their access, you offboard them when they leave. Applying that same muscle to autonomous software is well within reach, and the firms that do it early will scale their agents faster and with far more confidence than those still treating them as anonymous background processes.
AI agents have moved from pilot to payroll
The pilot phase is over. According to Salesforce’s 2026 Connectivity Benchmark, the average enterprise now runs around twelve AI agents, with that figure projected to reach twenty within two years. These are not chatbots answering FAQs. They interpret instructions, make decisions and take actions across CRM records, billing systems and customer-facing channels.
And the returns are landing. Gartner’s 2026 Agentic AI Pulse reports that 41% of agent rollouts cross positive ROI within twelve months, while McKinsey’s 2026 Global AI Survey puts median time saved at 6.4 hours per knowledge worker per week. On unit economics the gap is stark: a contained service ticket resolved by an agent costs roughly 0.46 dollars against 4.18 dollars handled by a person. The capability is real and the value is measurable.
That progress is precisely why the next step matters. When agents were one-off experiments, it was reasonable to run them loosely. Now that a dozen of them touch live customer records and revenue processes every day, the question quietly changes from can they work to how we manage them well. The good news is that this is a planning question, not a technology gap, and it rewards the teams who address it early rather than penalising those who started experimenting first.
How many AI agents does the average enterprise run in 2026? Recent benchmark data puts the average enterprise at about twelve active AI agents, rising towards twenty within two years. These agents increasingly operate inside core systems such as Salesforce, HubSpot and Microsoft Dynamics 365, where they read and write customer data, progress deals and trigger downstream actions. The shift is significant because it moves agents from isolated experiments into the daily flow of revenue work, which is exactly why giving each one a managed identity now pays off later.
What is an AI agent identity?
What is an AI agent identity? An AI agent identity is the digital credential and set of permissions that define who an autonomous agent is, what it is allowed to do and which human or team is accountable for it. Unlike a traditional service account, an agent acquires permissions dynamically at runtime, can spawn sub-agents, invokes external APIs and chains multiple actions together. That makes it a non-human identity with real reach inside your CRM. Treating it as an identity means giving it a unique credential, a scoped set of rights and a clear line back to a human sponsor, rather than letting it borrow a shared account.
This is the conceptual shift that unlocks everything else. Once an agent is an identity, every familiar tool in the security and operations playbook becomes available to you: least-privilege access, audit trails, lifecycle management and the ability to switch it off cleanly. The agent stops being a mystery process and becomes a managed member of the team.
Why does treating agents as identities help you scale faster?
Here is the encouraging part. The organisations that already run a real-time inventory of their agents are a minority, which means getting this right is a genuine competitive edge rather than table stakes. The Strata and Cloud Security Alliance research published in May 2026 found that only 23% of organisations have a formal, enterprise-wide strategy for agent identity, and just 21% keep a live inventory of active agents. The opportunity is wide open.
Why should organisations treat AI agents as managed identities? Treating each agent as a managed identity gives leaders something they currently lack: visibility. The same research found 82% of organisations had discovered at least one agent created without the knowledge of their security, IT or governance teams. Rather than a scare story, this is a clear signal of where the value is. When every agent has an owner, a scope and an inventory entry, you can confidently expand what your agents do, prove their impact to the board and retire the ones that underperform. Visibility is what turns enthusiastic experimentation into dependable, scalable capability.
What is agent sprawl, and how do you turn it into orchestration?
What is AI agent sprawl? Agent sprawl describes the rapid, often uncoordinated growth of AI agents across an organisation, where new agents are spun up in different teams and tools without shared context or a common governance model. Salesforce’s benchmark found that around half of enterprise agents operate in silos with no shared context, and 27% of the connections between them run ungoverned. Left unmanaged, sprawl means duplicated effort and blind spots. Managed well, the same population of agents becomes an orchestrated workforce where each one knows its role and hands work to the next.
The reframe matters. Sprawl is not a reason to slow down; it is a sign that adoption is working and that coordination has not yet caught up. A simple agent registry, a shared naming convention and a map of which agent touches which CRM object turn a scattered set of helpers into a coherent operating layer. Most teams already have the building blocks in their existing identity and integration platforms. The work is to point them at agents.
How do you govern AI agents inside a CRM?
How do you govern AI agents in a CRM? Governing AI agents in a CRM starts with giving every agent a unique, named identity rather than a shared service account, then scoping its permissions to the minimum it needs. From there, trace each agent’s actions back to a human sponsor, keep a live inventory of which agents are active, and prefer short-lived, rotating credentials over static API keys. The Strata research found 44% of agents still authenticate with static API keys and only 28% of organisations can reliably trace agent actions to a human owner, so these are practical, high-impact steps. Salesforce, HubSpot and Dynamics 365 all expose the connection and permission controls needed to do this.
None of this requires exotic tooling. It is the same identity hygiene that mature CRM teams already apply to human users, extended to software actors. The vendors are moving in the same direction: capabilities for mapping agents to their permissions, identities and reachable resources are arriving across the major platforms through 2026. The teams that adopt them early will find scaling their agent estate a calm, repeatable exercise rather than a scramble.
A practical starting point is to pick one agent already in production and run it through the full lifecycle: give it a unique credential, write down its owner, list the CRM objects it can touch and set an expiry on its access. The exercise usually takes an afternoon and surfaces exactly the questions you will want answered before agent number thirteen arrives. From there, the pattern repeats, and each new agent becomes easier to onboard than the last because the model is already in place.
Does identity-first governance slow your agents down?
The instinctive worry is that all this governance adds friction. The opposite tends to be true. When you can see what every agent is doing and trace it to an owner, you can hand agents more responsibility, not less, because you can prove the work is safe and auditable. The cost of logging and oversight, sometimes called the trust tax, becomes a trust dividend: the confidence to let agents act on higher-value tasks.
Think of it the way you would a new hire. Clear scope and accountability do not hold good employees back; they free them to do more, faster, because everyone knows the boundaries. Identity-first governance does the same for agents. It is the foundation that lets you expand confidently rather than the brake that holds you in pilot mode. The firms treating governance as an enabler are precisely the ones moving fastest from a handful of agents to a genuine agentic operating model.
The Sirocco perspective
We see agent identity as one of the most constructive opportunities in CRM right now. The capability question has largely been answered: agents work, and they pay back. The interesting question is how to give them a managed identity so you can scale them with confidence, and that is a problem we genuinely enjoy solving with clients. As an independent, vendor-agnostic partner, we are not tied to a single platform’s view of governance, which means we can help you design an approach that works consistently across Salesforce, HubSpot and Dynamics 365 rather than locking you into one vendor’s model.
Our advice is simple and optimistic. Start treating your agents like the valuable team members they are becoming. Name them, scope them, give each one an owner, and build a living inventory. Do that now, while you run a dozen agents, and reaching twenty will feel like growth rather than risk. The organisations that get identity right will be the ones that turn agentic AI from a promising experiment into a durable advantage.
Get in Touch
If you are working out how to give your CRM agents real identities, scoped permissions and a human owner, we can help you design the model before the agent count climbs from a dozen to twenty.
