Saltar al contenido
Lixto Labs
Back to the blog
AI AgentsGovernancePermissionsCentella

From assistants to operators: governing AI agents that already execute in your business

Companies tripled their AI agents in 15 months, yet only 34% trust their decisions. The difference comes down to permissions, limits and traceability.

August 15, 2026 · Lixto Labs Team · 3 min read

The 2026 figure that stands out to us isn't how much agentic AI grew, but the gap it left behind. Companies went from an average of 5 active agents in 2025 to 13 by April 2026, the time to put one into production dropped 53% — it's now around two days — and Gartner estimates that 74% of companies will deploy autonomous agents within the next two years.

At the same time, only 34% say they trust the decisions those agents make.

That gap between deployment and trust is the real implementation problem today.

An assistant suggests; an operator changes your database

While AI only drafted text, the worst case was a mediocre answer. When AI creates a quote, applies a payment, moves inventory or messages a customer, the worst case is different: a real transaction, done wrong, with your name on it.

So the jump to agents that execute isn't a model change, it's a governance change. And it's solved with the same tools you already use for your human team: permissions, limits, approvals and logs.

The five controls that shouldn't be missing

  1. Identity and permissions inherited from the user. The agent shouldn't have powers of its own: it should act with the role of whoever invokes it. If a sales rep can't approve a 40% discount, neither can the assistant.
  2. Scope bounded by branch, warehouse and portfolio. An agent that sees the entire company is an unnecessary risk when the user only operates one branch.
  3. Human approval thresholds. Actions above a certain amount, cancellations and credit notes should require explicit confirmation. Autonomy is earned in stages.
  4. Full traceability. Every action should record who requested it, which agent executed it, with what data and when. Without a log there's no possible audit.
  5. Verifiable data instead of memory. The agent should query the source — inventory, receivables, catalog — and cite the figure. That's where most of the hallucinations executives worry about disappear.

What the ones doing it well are actually getting

When these controls exist, results stop being promises. In customer service, agents are autonomously resolving 7 out of 10 interactions with no human intervention. In retail, companies that deployed agents reported online sales growth four times higher than those that didn't.

What's interesting is that none of those numbers come from a bigger model. They come from agents connected to real data and allowed to act within clear rules.

How we apply it in Centella

In Centella, the AI assistant operates under the same scheme of users, roles, permissions, branches and audit trail as the rest of the system. It can check available inventory, overdue receivables or a customer's history, and execute business actions by chat or voice — always within the scope of whoever is asking, and always leaving a record.

It isn't an AI layer on top of the software: it's the same permission engine applied to an operator that happens to be an agent.

Governance checklist before granting autonomy

  1. Does the agent inherit the user's permissions, or does it have its own?
  2. Which actions can it execute without human confirmation, and up to what amount?
  3. Can I see a log of what it did last week?
  4. Where does it get its figures, and can I verify them in one click?
  5. How do I stop it if something goes wrong, and who has that button?

Frequently asked questions

Should I start with autonomous agents or with read-only assistants? Start with queries, on real data. Once the team trusts the answers, enable execution in stages: drafts first, then actions with approval, then bounded autonomy.

Do I need an IT team to govern this? Not if governance lives inside the system itself. If your ERP already handles roles and auditing, extending it to the agent is configuration, not development.

What if the agent makes a mistake? With a log, you see it and reverse it like any other transaction. Without a log, you hear about it from the customer. That's the whole difference.


Want to see an AI agent operating with real permissions on real data? Try the Centella demo, review our services or tell us about your case.

From assistants to operators: governing AI agents that already execute in your business · Lixto Labs