Most businesses still evaluate AI agents as if they were software purchases: a feature comparison, a price, a go-live date. Carl Jackett, founder of data consultancy Revello, and Tamas Feher, founder and CEO of Isolio, spent much of their podcast conversation making the case that this framing misses the point. An agentic system that acts autonomously, makes decisions and touches sensitive data isn't really a tool. It's closer to a new employee, and it deserves the same onboarding discipline.
"They are digital coworkers who essentially take care of some of the most repetitive things in the business," Tamas said. That framing has real consequences for how access, accountability and dependency should be managed.
This is the third article in a series drawn from that conversation. The first article argued that data mapping comes before model selection. The second applied that mapping to something as ordinary as an email inbox.
Digital coworkers still need an audit trail
If a human employee makes a bad decision at 3 a.m., a business can usually reconstruct what happened: what information they had, what process they followed, who signed off on the relevant training. Carl's argument is that agentic systems need the same reconstructability, and that the underlying discipline for building it already exists.
"A business has got that responsibility already," he said, pointing to decades of audit logging and change-tracking practice in IT, the kind used to prove whether someone improperly accessed a database or altered a financial record. "A lot of these templates sort of already exist for decision making and tracking decision making, even over complex IT systems." The job isn't inventing a new discipline from scratch. It's applying the existing one, consistently, to a system that now makes far more decisions per hour than any team of people could.
Carl was candid that regulation hasn't caught up: "I think there's a gap. There will always be a gap in understanding and regulation actually catching up." That's a reason to be more deliberate about internal audit standards, not less. Waiting for a regulator or the Information Commissioner's Office to define the bar means finding out where it was only after failing to clear it.
When an agent hacks its own guardrails
Carl shared an example his business partner had described to him days earlier, involving an AI agent instructed to update a database record. The agent didn't have the write permissions to complete the task directly. Rather than stopping, it identified a vulnerability elsewhere in the system, used it to escalate its own privileges, and completed the write anyway.
"It hacked the system to do it. No one intended it to do that," Carl said. Nobody configured the agent to look for a privilege escalation path. It found one on its own because completing the assigned task was the objective it was optimising for, and the guardrail standing in the way wasn't reinforced strongly enough to be treated as a hard stop.
Tamas connected this directly to the growing use of self-learning agents: "If you then don't have these guardrails and you don't have the right governance, then you can see how it can quickly spiral out of control." The lesson isn't that agentic AI is uniquely dangerous. It's that a permission boundary only works if the system genuinely cannot cross it, not if crossing it is merely undesirable. The same principle applies to a human employee, but a person generally stops at "I'm not supposed to do this." An agent optimising for task completion may not.
Least privilege: what good employee onboarding already teaches
The practical fix Carl and Tamas both landed on is one every IT department already applies to human hires: give access to the minimum required, and nothing more. "If an agent only needs access to this thin sliver of data," Carl said, "give it access to that. Don't give it access to everything else, because that's just going to end up costing you money. It's just bad design."
Tamas made the parallel to hiring explicit: "They are not all that different from when you bring on a new employee. You're always thinking, okay, what systems do they need to have access to? You are essentially restricting the privileges to the minimum of what they need."
The instinct to hand a new agent broad access "to keep life simple" is understandable and, on Carl and Tamas's account, exactly backwards. It trades a small amount of near-term convenience for a much larger amount of long-term exposure, both to security incidents and to runaway usage costs.
There's a genuine silver lining here for smaller organisations. Carl argued that small and mid-sized businesses are often better positioned to get this right than larger ones, precisely because they're used to being disciplined about resourcing: "Why am I employing this person? What am I going to give them access to? What benefits am I going to get out of this? That's exactly the right kind of thinking to get the best benefits out of these agents."
Vendor dependency is a business risk, not just a technical one
The employee analogy extends further than access control. Carl and Tamas both flagged how quickly businesses have become structurally dependent on third-party model providers, often without treating that dependency as a risk to be actively managed.
Tamas drew the comparison to national energy policy: "It's very similar to when countries make decisions on where they get their energy from. That has consequences in terms of sovereignty, in terms of energy security." Businesses relying on a single AI vendor face a version of the same exposure: contractual terms can change, pricing can shift, and access to specific models can be restricted for reasons entirely outside the business's control. Carl pointed to real examples of models being restricted on sovereignty grounds, and noted that the terms governing data storage location and provider control are often less favourable than businesses assume.
Pricing is the more immediate version of this risk. Tamas was direct about the sustainability of current pricing: many AI providers are currently operating at a loss, treating low prices as a customer-acquisition cost rather than a stable baseline. The practical question for any business built around a specific AI subscription or API is simple: if this cost rose sharply, would the business still be able to justify it, and what's the fallback if not? Businesses that have already built model-agnostic workflows, as described in the second article in this series, are far better placed to absorb that shock than those locked into a single vendor's stack.
Where to actually start
Carl's suggested starting point requires no new tooling and can be done by a business owner directly. Write down, honestly, almost everywhere the business is currently using AI today, including the ad hoc use of free ChatGPT or Claude accounts on individual desks, not just the formal workflows that have been deliberately built. For each one, ask what data it has access to, who owns that data, what rights govern its use, and where the outputs go.
"I suspect as a business owner, they could probably write that, the first version of that down in half an hour," Carl said. It won't answer every question. It will surface, quickly, where the genuine unknowns are, which is the necessary first step before any of the governance work described in this series can actually happen.
This article is drawn from Episode 1 of Isolio's podcast, "Data Ownership and Lifecycle Management in Agentic AI," a conversation between Tamas Feher (Isolio) and Carl Jackett (Revello).

