Governing SAP AI Agents: Why the Control Plane Matters More Than the Model

Our most recent Insights post, Autonomous Audits: Applying SAP AI to Continuous Assurance, explored how SAP AI enables an autonomous approach to audits, shifting assurance from periodic sampling to continuous, population-level monitoring.

That conversation raised a question we hear from nearly every CFO, CIO and audit committee we work with: if AI agents are going to act inside our core financial processes, who is governing the agents?

That is the right question, and it is arriving at the right time. Over the past year the industry conversation has been dominated by models, which LLM is smartest, fastest, or cheapest. But for enterprises running mission-critical finance, revenue and compliance processes on SAP, the model is rarely the most important issue. The deciding factor is the control plane: the layer that determines which agents exist, who owns them, what they are allowed to do, how their actions are recorded, and how they are retired.

From a Bramasol perspective, the companies that will get durable value from agentic AI are the ones that treat agent governance as architecture from day one, rather than a policy document written after the first incident.

The-SAP-AI-Control-Plane

Agent Sprawl Is the New Shadow IT

Anyone who lived through the sprawling first wave of adoption in SaaS platforms will recognize the pattern. Individual teams, motivated by genuine productivity goals, deploy agents independently. Each one solves a specific problem. None of them were designed to work together, and nobody has a complete list.

The data on this is striking:

That last statistic should concern any finance leader. An agent whose actions cannot be distinguished from a human user's, operating with more access than it needs, is precisely the kind of control deficiency that surfaces in a Sarbanes-Oxley (SOX) walkthrough.

It also helps explain Gartner's widely cited prediction that over 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear business value or inadequate risk controls. The failures will rarely be about model capability. They will be about governance and operational discipline.

The Regulatory and Control Frameworks Are Converging

Three developments in 2026 have made agent governance a near-term operational requirement rather than a future-state aspiration.

  • COSO has brought generative AI into internal control. In February 2026 the Committee of Sponsoring Organizations of the Treadway Commission (COSO), released Achieving Effective Internal Control Over Generative AI, which aligns AI risks with the 17 principles of the 2013 Integrated Framework and explicitly covers capabilities such as automated transaction processing, reconciliation, workflow orchestration and autonomous task execution. Its six-step roadmap — govern, inventory, assess, design, implement and monitor — is designed to be used by management, internal audit, boards and external auditors alike. For SAP customers subject to SOX, this is the framework auditors will reference.
  • The EU AI Act timeline is now fixed. The Digital Omnibus on AI entered into force on July 27, 2026, moved most high-risk system obligations to December 2, 2027, while transparency obligations continue to apply from August 2026. The extension buys time; it does not reduce the work.
  • The execution layer is being hardened. SAP and NVIDIA have deepened their collaboration around OpenShell, an open-source secure runtime for autonomous agents that SAP is embedding within Joule Studio runtime as part of SAP Business AI Platform.

The practical implication is that "we'll govern it once it scales" is no longer a viable position. The inventory, ownership and control evidence for agents need to exist before the agents do.

How SAP Structures the Control Plane

What makes SAP's approach distinctive is that governance is layered into the platform rather than bolted alongside it. In practical terms, there are four layers that matter.

1. Business governance: should this action happen at all?
Joule Studio runtime applies business authorization, role-based policy and process context before a request reaches execution.
This is where SAP's decades of ERP authorization design pay off. Agents inherit the same role model, approval workflows and segregation-of-duties logic that already govern human users.

2. Identity and authorization: who is acting, and on whose behalf?
SAP's governance principles for Joule Agents state that every agent operates under a uniquely provisioned identity, that agents acting on behalf of a user are bound to a subset of that user's authorizations, and that agents operate inside existing controls rather than alongside them.
That directly addresses the "can't tell agents from humans" gap identified in the survey data above.

3. Runtime containment: how does the agent execute?
OpenShell governs what an agent can see and do and where inference goes. The SAP and NVIDIA collaboration connects that runtime environment to enterprise authorization models, Identity and Access Management (IAM) frameworks and audit trails.
Business permissions address only part of the problem, for example an agent may be authorized for a task while still needing limits on the systems and resources it uses to complete it.

4. Portfolio governance: what agents exist, and who owns them?
SAP AI Agent Hub is designed as the system of record for SAP and non-SAP agents, models and  Model Context Protocol (MCP) servers, supporting discovery, ownership, lifecycle governance, evaluation, policy evidence and retirement controls
. This is the layer that turns COSO's "inventory" step from a spreadsheet exercise into a managed process.

None of these layers is sufficient alone. Together, they give finance and audit leaders something they can actually test.

What Every Production Agent Should Have

In our client work, we recommend that no agent enters a production finance, revenue or compliance process until it has what amounts to an enterprise identity card. At a minimum:

  • A named business owner accountable for the agent's outcomes, not just its technical operation.
  • A defined autonomy level and risk tier that determines whether the agent operates human-in-the-loop, human-on-the-loop, or under direct human command.
  • Documented authorization boundaries using least privilege, with agent permissions included in the normal access certification cycle.
  • Separation of detection and remediation, so the agent that identifies an exception is not the same one that resolves it.
  • Complete, reconstructable logging of the user, agent, model, tool calls, system actions, approvals, errors and business outcome.
  • An escalation and retirement path, including what happens when the agent misbehaves, when the underlying process changes, or when the agent is no longer needed.

If that list looks familiar, it should. It is essentially the same discipline mature organizations already apply to privileged users and critical automated jobs. Agents simply make it non-negotiable.

Bramasol's Perspective

Bramasol has spent more than 30 years helping companies implement compliance-critical SAP processes, including revenue recognition under ASC 606 and IFRS 15, lease accounting, treasury and quote-to-cash. In those areas, as SAP CEO Christian Klein said at Sapphire 2026, "almost right" is not acceptable. That standard applies equally to the agents now being introduced into those processes.

Our view is that agent governance is a finance and controllership issue as much as an IT issue. The authorization model, the segregation-of-duties rules, the approval workflows and the audit evidence that make an agent trustworthy are all defined in the business process layer, which is where Bramasol's Finance-First S/4HANA Transformation methodology starts.

The sequence we recommend is pragmatic:

  • Create governance inventory first. Name owners, define risk tiers, and establish a single system of record for agents before the portfolio grows.
  • Build on the existing control model. Extend SAP roles, workflows and Segregation of Duty (SoD) rules to agents rather than inventing parallel structures.
  • Pilot with evidence. Run two or three governed scenarios with defined evaluation criteria, documented escalation paths, and a cost baseline.
  • Scale where it is proven. Expand only where quality, auditability and economics have been demonstrated, not where the demo was most impressive.

Summary

The agentic AI conversation is maturing quickly. The early question was whether AI agents could do meaningful work inside enterprise systems. The current question is whether organizations can govern them well enough to let them.

SAP's layered approach, business governance in Joule Studio runtime, identity-bound authorization, runtime containment through the OpenShell collaboration, and portfolio governance through SAP AI Agent Hub, gives enterprises a credible foundation.

But architecture alone does not produce assurance. That still requires clear ownership, disciplined process design, and controls your auditors can test.

Bramasol combines deep expertise in SAP Finance, Revenue Accounting, Treasury, Compliance and Quote-to-Cash with practical AI and S/4HANA implementation experience to help organizations build that foundation, so that AI agents strengthen governance rather than eroding it.

 

About the author

David Fellers

Dave is CEO of Bramasol. After joining the company in 2007 as VP of Professional Services, he became CEO in 2011 and has led the company through record-setting growth and revenues highlighted by a successful re-focusing on serving the Office of the CFO. By building a deep and broad consulting practice that leverages our expertise, disciplines and a track record of co-innovation with SAP, In his 15 years at the helm, Dave has positioned Bramasol as the go-to partner for clients that are looking to move into the Digital Solutions Economy and/or to leverage the Digital Transformation of finance using SAP S/4HANA.