AI agents can install software, write code and take actions, so their operating permissions matter as much as their apparent intelligence. In a Baaz.nl article published on 9 October, Salesforce AI expert Reinier van Leuken argues that organisations should treat agents as digital users with clear limits, monitoring and human oversight.
Watch Desk analysis
What happened
Van Leuken uses OpenClaw as an example of a locally run agent that may try to install software or start processes when given a task beyond its immediate capabilities. His central argument is that agents should operate within a controlled environment, under defined permissions, with tools that let administrators inspect what they did and why.
He also draws a line between quick, disposable software made with “vibe coding” and core business systems. A one-off event tool may be a reasonable experiment; a CRM handling sensitive customer data and supporting thousands of employees is another proposition entirely. For agent-to-agent work, he points to registries, authentication rules and an orchestrator as ways to make collaboration more structured.
Why it matters
An agent does not merely produce an answer. It can use tools and change things, which makes the permissions and environment around it part of the safety question. Van Leuken’s distinction between a disposable app and a business-critical system gives organisations a practical place to start: decide what an agent may access and do before letting it loose on important data or services.
These are the arguments of a Salesforce expert, not a neutral assessment of every agent or deployment. But they raise a useful question for teams adopting the technology: how much autonomy is acceptable, and what controls should come with it?
Our read
The best advice here is less glamorous than an agent swarm and more useful on Monday morning: give agents limited permissions, monitor their actions and keep human approval where the consequences warrant it. A clever agent is not a substitute for deciding what it is allowed to touch.
What to watch
- Whether organisations set permissions and approval requirements before deploying agents.
- How monitoring tools explain an agent’s actions, not just record them.
- Whether multi-agent systems make control clearer or simply add more moving parts.
Discussion spark: Should organisations require human approval for every action an AI agent takes, or only for actions involving sensitive data and consequential systems?
Sources and evidence
- The Future of AI Agents – Baaz.nl (9 October 2026, 15:10 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.