An AI agent can read information. Make recommendations. Prepare work. Use tools. Update systems. Send communications. And, with the right access, take actions without waiting for somebody each time.
The important question is not simply: "What can the AI do?" It is: "What should this AI be allowed to do?"
We design AI sales workflows with permissions, approval, limits and escalation built into the process.
AI is often described as either: Something that waits for instructions. Or: Something autonomous that gets on with the job. Real business workflows need more nuance.
An AI system might be trusted to read a sales enquiry but not respond to it. It might prepare a CRM update but not make the change. It might send one type of routine communication automatically but require approval for another. It might handle normal situations independently and immediately escalate anything unusual.
Different actions deserve different levels of authority. That is why we use an authority ladder.
Start with the lowest level that makes the system useful.
The AI can access agreed information. It can understand what is happening and use that information as context. It cannot change anything.
The AI can analyse the information and suggest a next action. It still cannot carry that action out.
The AI can prepare the work required for the next step.
The AI can carry out an action once a person explicitly approves it.
The AI can carry out specific actions independently when agreed conditions are met.
When the situation falls outside the rules, the agent stops. It gathers the relevant information and passes the situation to a person.
This matters. You do not necessarily decide: "This agent is Level 4." You decide what authority it has for each action.
For example, an enquiry agent might be allowed to:
One agent. Different authority for different actions. That is much more useful than a single switch marked:
When businesses experiment with AI agents, it can be tempting to connect everything first. Email. CRM. Calendar. Files. Internal documents. Customer information. Then work out what the agent can do with it.
We prefer the opposite approach. Define the job. Then ask what access that job actually requires.
If the agent only needs information from three CRM fields, why give it unrestricted access to the entire system? If it only needs to prepare emails, why give it permission to send them? If it only needs to read a calendar, why give it permission to change meetings? See how this plays out with CRM permissions.
Capability does not automatically justify permission.
An agent that only reads information can still potentially access sensitive or commercially important data. So read permissions should be considered deliberately.
The principle remains the same: Give the workflow the information required for its job, not everything that happens to be available.
It is easy to add: Approve / Reject to an AI workflow. But approval only works if the person approving has enough information to make the decision.
If somebody is expected to approve fifty AI actions without understanding why they were proposed, approval can become another repetitive task.
Good human review should provide useful context.
Where practical, the workflow should make the human decision easier rather than simply move responsibility to an approval button.
A well designed agent should encounter situations it is not allowed to handle. That is normal.
Perhaps:
The agent's job in those situations is not to improvise. It is to recognise the boundary, gather useful context and escalate. Knowing when to stop is a capability too.
Where possible, we identify escalation conditions during workflow design. That might include:
Not every exception can be predicted. But the more clearly the boundaries are defined, the less the agent has to invent its own interpretation of what is acceptable.
Suppose an AI agent is allowed to follow up with sales leads. That instruction is too broad. A more controlled workflow might define:
The useful part is not simply that the AI can send an email. It is the system around that action.
AI systems can misunderstand information. Generate something incorrect. Miss context. Choose the wrong permitted option. Encounter information they were not expecting.
Connected systems can fail too. APIs return errors. Data becomes stale. Records conflict. Automations trigger unexpectedly.
That is why we do not design workflows around the assumption that everything will always behave perfectly. Depending on the workflow, controls might include:
The appropriate controls depend on what the system is doing and the consequences if something goes wrong.
Adding an internal label to a lead is different from sending a contractual commitment. Preparing meeting notes is different from changing a commercial agreement. Suggesting an opportunity stage is different from deleting customer information.
That difference should affect how much authority the AI receives. A useful question is: "What happens if this action is wrong?"
If the answer is: "Someone corrects a low impact internal field." the workflow may tolerate more independence. If the answer involves a customer, money, commitments, sensitive information or significant consequences, stronger controls may be appropriate.
The authority ladder is not a maturity score. A workflow does not need to climb it.
Some AI systems may remain permanently at Recommend or Prepare because that is the right place for them. Others may handle narrow, predictable actions independently.
The goal is not to reach maximum autonomy. The goal is to find the level that makes the workflow useful without giving away unnecessary control.
Autonomy should earn its place. And sometimes it should stay exactly where it is.
If those questions do not have clear answers, the agent probably needs more design before it needs more authority. A sales process diagnostic is often the right place to start.
Policies matter. But controls become much more useful when they are reflected in how the system actually works.
The aim is to turn principles into behaviour.
A workflow where a person manually checks every tiny action may remove very little work. A workflow where AI can do anything it likes may create unacceptable uncertainty. The useful space is between those extremes.
That is controlled agentic selling.
What is the AI actually responsible for?
What does it genuinely need to access?
What can it read, recommend, prepare and change?
Which actions require approval and which can happen within limits?
When must the system stop and involve somebody?
What happens when information is incomplete, unusual or conflicting?
Start at an appropriate level and increase specific permissions only where there is a reason.
Look at what the agent actually does, where people intervene and whether authority needs to increase or decrease.
This is the methodology we use on every workflow.
The Agentic Selling knowledge hub explains the principles behind agent authority, human oversight and responsible AI in sales.
Explore Agentic Selling →Ask how autonomous it needs to be.
For this job. For this action. With this information. Under these conditions. With these consequences.
Then give it the authority that makes sense. No more.