
VTechFusion Team
VTechFusion Technologies
Ask most enterprises how many AI agents are currently operating in their systems, what each is authorized to do, and who is accountable if one makes a bad decision — and you'll usually get an honest "we're not entirely sure." Workday's new Agent Passport is a direct response to exactly that gap, and the pattern it uses is worth understanding regardless of which ERP or CRM platform you run.
What Standards-Based Attestation Actually Buys You
Agent Passport ties every agent attestation to a recognized public standard — OWASP's LLM Top 10, NIST's AI Risk Management Framework, MITRE ATLAS — rather than a proprietary, vendor-only checklist. That distinction matters more than it sounds: a proprietary checklist tells you an agent passed one vendor's internal bar, with no way to compare that bar to anything external. A standards-based attestation tells you which specific, externally-defined risks were actually assessed, which is the difference between "trust us" and something your own security team can independently evaluate.
Building the Same Discipline Without Waiting on Your Vendor
- Maintain a live inventory of every AI agent operating in your ERP/CRM stack — first-party, third-party, and internally built — not just the ones your platform vendor surfaces by default
- For each agent, document what data it can access, what actions it can take autonomously versus what requires human approval, and which standard (if any) its risk assessment maps to
- Treat verification as continuous, not a one-time launch review — an agent's behavior can drift as the underlying model updates, even if its permissions haven't changed
Why This Is Becoming Table Stakes, Not a Nice-to-Have
Salesforce's 2026 Connectivity Benchmark found 89% of UK organizations now deploy AI agents, but only 54% have a centralized governance framework — and half of deployed agents run in isolated silos with no coordinated oversight. Whatever platform you're on, an agent inventory mapped to real external standards is the concrete first step toward closing that exact gap, not a theoretical compliance exercise.
Frequently Asked Questions
Do I need to be a Workday customer to use this verification approach?
No — the underlying pattern (mapping every AI agent's risk assessment to a public standard like OWASP's LLM Top 10 or NIST's AI RMF, rather than a proprietary checklist) can be built into any ERP or CRM governance process, independent of which vendor's Agent Passport-equivalent feature you have access to.
What's the difference between a proprietary agent certification and a standards-based one?
A proprietary certification tells you an agent passed one vendor's internal bar with no external reference point. A standards-based attestation, tied to a framework like NIST's AI RMF, tells you which specific, externally-defined risks were actually assessed — something your own security team can independently verify and compare across vendors.
Enjoyed this article?
Get new articles delivered to your inbox — no spam, unsubscribe anytime.
Ready to Build Something Great?
Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.
