Tuesday, September 15, 2026 AboutContact
Entrepreneurs

The Agent Startups Worth Backing Are Building the Permissions Layer Nobody Demos

Reasoning and interface have taken the attention this year, while the identity and audit layer underneath them is the thing every enterprise buyer will actually be blocked on.

By Erin Delacroix· September 11, 2026· 3 min read
The Agent Startups Worth Backing Are Building the Permissions Layer Nobody Demos
Photo Courtesy: Getty Images · source

The conversation about agentic AI in 2026 has been almost entirely about model capability: the reasoning layer, the interface, the task performed.

Saeed Amidi, founder and chief executive of Plug and Play, argues the layer beneath that has gone largely undiscussed, and is where the buying decisions will be made. Identity, permissions and audit capacity.

Every decision an agent takes needs a traceable path a reviewer can follow: the query log, the data sources touched, the reasoning it followed and what it produced. That governance layer is required by every company deploying agents at scale, whatever model they chose.

The blocker is integration, and it is measurable

The appetite is not in doubt. PwC found that 79 per cent of organisations have adopted agents, and 66 per cent of those report increased productivity.

The obstacle is the plumbing. Forty-six per cent of enterprises cite integration with existing systems as a primary obstacle, meaning the digital handshakes required to connect an agent to customer relationship management, IT service ticketing and internal APIs.

An agent is an application connecting to critical systems, and it has to respect the access rules already in force, checking permissions against the identity infrastructure the company already runs. Getting that wrong is not a product flaw. It is a compliance and data-exposure problem that gets flagged in an audit.

Provision the agent the way you would provision a new hire

Four questions a buyer will ask

Amidi frames what leadership has to be able to answer before an agent goes anywhere near production.

Who, or what system, authorises the agent to take an action. How that authorisation is revoked. What gets logged when something goes wrong. And how a human is inserted into the loop.

A startup that cannot answer those is not selling into a regulated industry, regardless of how good the reasoning is.

The playbook for regulated buyers

For founders selling to banks, insurers, hospitals or anywhere compliance is heavy, Amidi sets out what the architecture has to do.

Inherit the buyer's access rules rather than asserting your own. An agent should never ask a customer to trust its judgment about what it is allowed to see. It should plug into the identity provider, the existing role structure and the interconnecting systems already in place. Provision it the way a new hire is provisioned, not by granting it a separate set of rights.

Log the path, not just the outcome. A reviewer needs to see what the agent queried, which systems it touched, the steps it took to reach an answer and what it did with it. This is far cheaper to build into version one than to retrofit when a compliance office asks for it mid-audit.

Attach a named person to every agent. Someone who defines what it can access and why, and who can monitor it in operation. A startup that builds this into onboarding removes a step the buyer's compliance team would otherwise have to construct themselves.

Scope every permission to a task. A support agent that can read tickets should not automatically be able to export payment data because both sit under the same account.

Why this is the defensible position

Agentic operations accelerate the business and raise compliance risk at the same time, and the second half is where deals stall.

A founder who can state precisely which requirement their architecture satisfies, whether that is a payments handling standard, a financial risk-assessment rule or a data residency obligation, moves through legal and risk review faster than one who cannot.

That is the actual competitive advantage available right now. The reasoning layer is being commoditised by the model providers at a speed no startup can match. The permissions layer is unglamorous, specific to how enterprises really work, and every company shipping an agentic product is going to need somebody else to have built it.