Agentic AI in October 2026: Agents Now Need Owners (Dots, AMP, Fusion Claw, SAP)
In two weeks, OpenAI, Atlassian, Oracle and SAP each shipped agents with named owners, scoped permissions, approval rules and audit logs, and America.gov tested whether citizens will let AI act for them. Here's what launched, why only 23% of consumers trust agents with payments, and a working TypeScript agent envelope you can copy.
- Published
- Reading time
- 12 min read

On this page
TL;DR: Between September 29 and October 9, 2026, OpenAI, Atlassian, Oracle and SAP each shipped a major agent launch, and the US government put an AI front door on its services. Under the different names, all four companies shipped the same thing: an agent with a named owner, its own identity, scoped permissions, approval rules for risky actions, and an audit log. Model capability is no longer what holds agents back. Context, governance and trust are. Consumer data agrees: only 23% of US consumers trust GenAI to make payments for them (Visa Trust Index, September 2026). Below: what each company shipped, the pattern they share, a working TypeScript "agent envelope" you can copy, and how I'd build agents in 2027 as a result.

Why This Two-Week Window Matters
If you read Forbes' agentic AI coverage from the last two weeks, the headlines look scattered: Atlassian and enterprise context, SAP and governance, OpenAI's new always-on agents, agentic cybersecurity budgets, a consumer trust gap in agentic commerce, and America.gov testing whether citizens will let an agent act for them.
Read them together and they make one argument. 2025 was about whether agents could do the work. Late 2026 is about who answers for them when they do. Every vendor launch in this window put most of its effort into the same scaffolding around the model: identity, permissions, approvals, audit and context.
I build production AI systems for fashion commerce at Modelia, and I've written before about real-world agentic patterns and error recovery for agents. This post is the news-driven follow-up: what changed, and what to do about it if you ship agents.
Deep dives in this series:
- OpenAI Dots explained: always-on ChatGPT agents
- Atlassian AMP explained: the Agentic Multiplayer Protocol
- Oracle Fusion Claw explained: OpenClaw's idea, rebuilt for the enterprise
- The agentic commerce trust gap: 2026 consumer data
The Five Launches at a Glance
| Date | Who | What shipped | The governance piece |
|---|---|---|---|
| Sep 29 | OpenAI | Dots, always-on agents on GPT-6 Astra, plus ChatGPT Space | Custom Rules (allow / require approval / prohibit), Activity View, auto-review of consequential actions |
| Sep 29 | Oracle | Fusion Claw, a governed agent runtime with 25 new agentic apps | "Enterprise Operating Envelope": objectives, permissions, risk thresholds, approval rules |
| Sep 29 | US government | America.gov, an AI front door to federal services | Answers only at launch; transactions like passport renewal planned later |
| Oct 6–8 | SAP (SAP Connect) | Joule Work, more Joule agents, AI Agent Hub | Central agent inventory, ISO/IEC 42001-certified governance, customer-set autonomy |
| Oct 7 | Atlassian (Team '26 Europe) | AMP, the Agentic Multiplayer Protocol | Every agent has an owner and profile, inherits permissions, logs every action |
OpenAI Dots: Agents That Keep Working After You Log Off
At DevDay on September 29, OpenAI launched Dots, persistent agents built to "keep working after an employee closes the chat window" (VentureBeat). They run on GPT-6 Astra, connect to more than 4,000 apps through OpenAI's plugin ecosystem, and talk to you through ChatGPT, Slack and Microsoft Teams. The first Dot is included for Pro and Business Premium customers, and Enterprise, Edu and Healthcare get a beta once an admin turns it on.
The interesting part is the control surface, not the model:
- Custom Rules let an organization permit an action, require approval for it, or prohibit it.
- Activity View shows background work so a person can step in.
- Auto-review checks consequential actions before they run on their own.
Forbes' Ron Schmelzer asked the obvious question: do you need them? My answer: only for work with a clear owner and a narrow tool list. (Deep dive: OpenAI Dots explained.) An always-on agent with 4,000 possible connections and vague instructions keeps making changes in your accounts long after you've stopped checking.
Atlassian AMP: Agents as Named Teammates
On October 7 in Amsterdam, Atlassian introduced AMP, the Agentic Multiplayer Protocol (Business Wire). Its core rule fits in one line: "Every agent under AMP has a clear owner and distinct profile." Agents show up in Jira and Confluence threads, in presence bars and cursors next to people, and they work from Atlassian's Teamwork Graph, which it says connects more than 250 billion objects and relationships. Every action goes into an audit trail. Atlassian says agents can run as a user or under service accounts, but dedicated agent accounts are still listed as "coming soon," so for now many agent actions run with the launching user's permissions.
Atlassian's own usage numbers:
- Humans and agents work together more than 10 million times a month
- The Atlassian MCP server has nearly 2 million monthly active users
- It handles over 15 million tool calls a day, up 15x in six months
- The new version uses up to 25% fewer tokens for the same Jira and Confluence work (Atlassian's internal benchmark on Claude models)
That last number matters more than it looks. Agents waste most of their tokens finding context. Whoever holds the context can make agents cheaper and more accurate, which is exactly the point of Steve McDowell's Forbes piece, Atlassian's Move To Own The Context Powering Enterprise Agentic AI. He also notes that Atlassian hasn't published a specification other vendors can implement on their own, so for now AMP is a "protocol" only inside Atlassian's products. (Deep dive: Atlassian AMP explained.)
Oracle Fusion Claw: Keep the Model Away From the Database
Oracle announced Fusion Claw on September 29 (Oracle). It is a governed runtime inspired by the open-source OpenClaw approach, though Oracle says it built its own. It shipped with 25 Claw-powered applications across finance, HR, supply chain and sales, bringing its Fusion Agentic Applications to 75 (Futurum).
Two design choices are worth copying:
- 01An "Enterprise Operating Envelope." Customers set objectives, permissions, risk thresholds and approval rules, and can require a person to review the plan before it runs (SiliconANGLE).
- 02Isolation. The runtime sits in an isolated environment that stops the language model from directly changing Fusion business records (Forkast). The model proposes actions, and deterministic code applies them.
The second choice is the one most teams skip. If your agent's tool is "run this SQL," the model effectively has write access to your database. If its tool is "issue refund for order X, up to $Y," your code still controls what can change. (Deep dive: Oracle Fusion Claw explained.)
SAP: Governance Is the Product
At SAP Connect, SAP's pitch was less about what its agents can do and more about how they are controlled. Steve Banker's Forbes headline sums it up: SAP Seeks To Differentiate Itself With AI Governance. From SAP's own announcement (SAP News):
- The SAP AI Agent Hub in SAP LeanIX provides "a central inventory of enterprise agents"
- Its governance architecture is independently ISO/IEC 42001-certified
- Agents act "using established data, authorizations and audit trails," and customers control the level of autonomy
- Joule Work is already live with 110,000 employees, and SAP reports 20% productivity gains across finance, HR and procurement (vendor-reported)
An agent inventory sounds dull until you try to answer a simple question in a large company: how many agents do we run, who owns each one, and what can each one touch? Most companies can't answer it today. Agentic AI is also lifting identity vendors: Forbes reported in July that agentic AI demand made Okta's CEO a billionaire again. Non-human identity is now a market of its own.
America.gov: The Public Trust Test
America.gov launched on September 29 as an AI chatbot that answers questions using federal websites. For now, it can tell you which form to use to renew a passport, but it can't renew it for you. The White House says passport renewal and Medicare enrollment will come later, and reported timelines run from late 2026 to early 2027.
Sandy Carter's Forbes piece frames it well: America.gov tests whether Americans will trust AI agents to act. Going from answering to acting is the hardest step in agent design, and the government is taking it in public, in that order, which is the right order.
The Trust Gap Is in the Data
On consumer agents, the numbers are consistent:
- 23% of US consumers trust GenAI to handle payment transactions for them (Visa Trust Index, Harris Poll, 2,065 US adults, fielded May 26–28, 2026)
- Only 5% of consumers are comfortable with an agent making purchases on its own, even though 78% are open to AI shopping help (Cover Genius, September 2026)
- 24% say they will never delegate a purchase to AI, and consumers' top requirements are spending caps, instant revocation and easy cancellation (Checkout.com, June 2026)
Jordan McKee's Forbes column calls this agentic commerce's consumer trust problem: people are glad to let AI research and compare products, but far fewer will let it pay. I break down all the 2026 survey data, and the safeguards that change people's minds, in The Agentic Commerce Trust Gap. That matches what I see building AI for fashion e-commerce. Shoppers like AI that helps them decide, such as seeing a garment on a model that looks like them. Letting it spend their money is a much bigger step.
The lesson for builders is not to give up on autonomous checkout. It's to earn autonomy step by step: read first, then write, then spend small amounts under a limit, with approval required above it.
The Pattern: The Agent Envelope
Put the five launches side by side and the same five parts show up every time. I call this the agent envelope:
| Part | What it means | Who shipped it |
|---|---|---|
| Owner | A named person accountable for every agent | Atlassian AMP |
| Identity | The agent's own identity, not a shared API key | Atlassian (agent accounts, coming soon), SAP (agent inventory) |
| Scope | An explicit list of tools and data it may touch | Dots (app access), Fusion Claw (permissions) |
| Approval rules | Risk-based allow / ask / deny decisions | Dots Custom Rules, Fusion Claw thresholds |
| Audit | Every action logged with who, what and why | AMP, SAP, Dots Activity View |
The sixth part sits under all of these: context. Atlassian's Teamwork Graph, SAP's knowledge graph and Steven Wolfe Pereira's Forbes argument that agents need ontologies to understand your business all make the same point. An agent can only be as good as the business context it can query.
Build It: A Minimal Agent Envelope in TypeScript
You don't need a vendor platform to get the pattern. Here's a small policy gate that sits between your agent's tool calls and their execution. It needs no dependencies and runs on Node 22+ with npx tsx agent-envelope.ts.
// agent-envelope.ts: run with `npx tsx agent-envelope.ts` (Node 22+)
type Risk = "read" | "write" | "money" | "irreversible";
type Decision = "allow" | "approve" | "deny";
interface AgentIdentity {
id: string; // the agent's own identity, never a shared API key
owner: string; // the human accountable for it
scopes: string[]; // tools it may call at all
}
interface ActionRequest {
tool: string;
risk: Risk;
amountUsd?: number;
args: Record<string, unknown>;
}
interface Envelope {
autoApproveRisks: Risk[]; // run without asking
spendLimitUsd: number; // money actions above this need a human
denyRisks: Risk[]; // never allowed, even with approval
}
interface AuditEntry {
at: string;
agent: string;
owner: string;
tool: string;
decision: Decision;
reason: string;
}
const auditLog: AuditEntry[] = [];
function decide(agent: AgentIdentity, req: ActionRequest, env: Envelope): [Decision, string] {
if (!agent.scopes.includes(req.tool)) return ["deny", `tool "${req.tool}" is outside the agent's scope`];
if (env.denyRisks.includes(req.risk)) return ["deny", `${req.risk} actions are blocked for agents`];
if (req.risk === "money") {
if ((req.amountUsd ?? Infinity) > env.spendLimitUsd) {
return ["approve", `${req.amountUsd} is over the ${env.spendLimitUsd} limit`];
}
return ["allow", `within the ${env.spendLimitUsd} limit`];
}
if (env.autoApproveRisks.includes(req.risk)) return ["allow", `${req.risk} is auto-approved`];
return ["approve", `${req.risk} needs a human`];
}
function gate(agent: AgentIdentity, req: ActionRequest, env: Envelope): Decision {
const [decision, reason] = decide(agent, req, env);
auditLog.push({ at: new Date().toISOString(), agent: agent.id, owner: agent.owner, tool: req.tool, decision, reason });
return decision;
}
// --- example: a shopping agent acting for a customer ---
const agent: AgentIdentity = {
id: "agent:reorder-bot",
owner: "harsh@example.com",
scopes: ["catalog.search", "cart.add", "checkout.pay"],
};
const envelope: Envelope = {
autoApproveRisks: ["read", "write"],
spendLimitUsd: 50,
denyRisks: ["irreversible"],
};
const requests: ActionRequest[] = [
{ tool: "catalog.search", risk: "read", args: { q: "white sneakers size 9" } },
{ tool: "cart.add", risk: "write", args: { sku: "SNK-9-WHT" } },
{ tool: "checkout.pay", risk: "money", amountUsd: 120, args: { cart: "c_123" } },
{ tool: "account.delete", risk: "irreversible", args: {} },
];
for (const req of requests) gate(agent, req, envelope);
console.table(auditLog.map(({ tool, decision, reason }) => ({ tool, decision, reason })));Output:
┌─────────┬──────────────────┬───────────┬──────────────────────────────────────────────────────┐
│ (index) │ tool │ decision │ reason │
├─────────┼──────────────────┼───────────┼──────────────────────────────────────────────────────┤
│ 0 │ 'catalog.search' │ 'allow' │ 'read is auto-approved' │
│ 1 │ 'cart.add' │ 'allow' │ 'write is auto-approved' │
│ 2 │ 'checkout.pay' │ 'approve' │ '$120 is over the $50 limit' │
│ 3 │ 'account.delete' │ 'deny' │ `tool "account.delete" is outside the agent's scope` │
└─────────┴──────────────────┴───────────┴──────────────────────────────────────────────────────┘A few notes on the design:
- Scope is checked before risk.
account.deleteis denied because the agent was never given that tool, not because the model chose not to call it. Never rely on the prompt for a boundary you can enforce in code. - "Approve" is a real state, not an error. In production it should pause the run, notify the owner (Slack, email, an in-app card) and resume with the decision. Durable workflow engines handle this well.
- The model never sees the envelope. It asks to call a tool, and your code decides. That's the Fusion Claw principle at a small scale.
- The audit log records the owner on every row. When something goes wrong, you know who to ask and why the action was allowed.
To use this with a real agent, wrap your tool executor so every tool call from the Claude API, OpenAI or MCP goes through gate() first. My Model Context Protocol guide covers where that hook sits in an MCP server, and the agentic error recovery skill gives you a checklist for hardening the rest of the loop.
What I'd Do Differently in 2027
Based on these two weeks of launches, here is how I'd plan agent work going into 2027:
- 01Start from the envelope, not the prompt. Before writing a system prompt, write down the owner, the tool list, the risk tier of each tool, and the approval rule. If you can't fill that in, the agent isn't ready to ship.
- 02Give agents their own identities. Shared API keys make every audit question unanswerable. Service accounts per agent are cheap now.
- 03Make tools narrow and typed. "Refund order X up to $Y" beats "call the payments API." Narrow tools are also what make the cheap models work: a small model like Claude Haiku 5.5 handles a narrow, well-typed tool reliably at a fraction of the cost.
- 04Invest in context before autonomy. Atlassian's 25% token saving came from better context, not a better model. A clean, queryable view of your business data improves every agent you build on top of it.
- 05Let users earn autonomy step by step. Start with read-only, then writes, then spending under a limit, and raise limits based on each user's track record. The 23% trust number is where you start, not a ceiling.
- 06Measure ROI per agent. Forbes' CIO guide to agentic AI is about moving from experiments to returns. You can only measure returns per agent if each agent has an identity and a log.
My Take
The agentic AI story of October 2026 isn't a model launch. It's every major platform admitting the same thing: an agent nobody owns is a liability. The vendors that win enterprise agents will be the ones with the best context and the most trusted controls, and Atlassian, SAP and Oracle are all betting on exactly that.
For engineers this is good news, because the envelope is ordinary software engineering. Identity, permissions, typed APIs, approval flows and audit logs are problems we already know how to solve. The model handles the reasoning, and the envelope is the part we build and own.
If you're building agents, start with my guides on Claude agentic workflows in production and agentic error recovery and observability. For a running feed of launches like these, see AI Pulse.
References
- 01Forbes, Agentic AI topic page. forbes.com/topics/agentic-ai
- 02Atlassian via Business Wire, "Atlassian Introduces AMP: The Agentic Multiplayer Protocol to Power Human-AI Collaboration," October 7, 2026. financialcontent.com
- 03Steve McDowell, "Atlassian's Move To Own The Context Powering Enterprise Agentic AI," Forbes, October 9, 2026. forbes.com
- 04VentureBeat, "OpenAI launches Dots, always-on AI agent coworkers, and ChatGPT Space," September 29, 2026. venturebeat.com
- 05Ron Schmelzer, "What Are OpenAI Dots And Do You Need Them?", Forbes, October 5, 2026. forbes.com
- 06Oracle, "Oracle Extends Fusion Agentic Applications with Introduction of Fusion Claw," September 29, 2026. oracle.com
- 07Futurum Group, "Oracle Fusion Claw: From AI Assistance to Governed Autonomous Execution." futurumgroup.com
- 08SiliconANGLE, "Oracle expands AI agent features with Fusion Claw," September 29, 2026. siliconangle.com
- 09Forkast, "The Application Layer Is Absorbing Agent Infrastructure." forkast.news
- 10SAP News, "SAP Puts the Autonomous Enterprise to Work," October 2026. news.sap.com
- 11Steve Banker, "SAP Seeks To Differentiate Itself With AI Governance," Forbes, October 8, 2026. forbes.com
- 12Kirk Ogunrinde, "Agentic AI Demand Makes Okta CEO A Billionaire Again," Forbes, July 2, 2026. forbes.com
- 13The Rundown, "America.gov launches with AI answers and plans for federal applications." therundown.ai
- 14Sandy Carter, "America.gov Tests Whether Americans Will Trust AI Agents To Act," Forbes, October 7, 2026. forbes.com
- 15Visa, "Visa Trust Index explores agentic commerce adoption," September 9, 2026. corporate.visa.com
- 16Cover Genius, "Do Consumers Trust AI Shopping Agents With Checkout?", September 25, 2026. covergenius.com
- 17Checkout.com, "Consumer demand for AI shopping is forming fast but trust for agentic commerce is still catching up," June 9, 2026. checkout.com
- 18Jordan McKee, "Agentic Commerce Has A Consumer Trust Problem," Forbes, October 1, 2026. forbes.com
- 19Steven Wolfe Pereira, "Your AI Agents Can Write Code. Can They Understand Your Business?", Forbes, October 2, 2026. forbes.com
- 20Megan Poinski, "The CIO's Guide To Agentic AI: How To Move From Experiments To ROI," Forbes, April 23, 2026. forbes.com
Harsh Rastogi is an AI Product Engineer at Modelia, building production generative-AI systems for fashion commerce, and the creator of carcode. He writes about AI systems, developer tooling and production engineering at harshrastogi.tech.
Frequently asked questions
What is agentic AI?
Agentic AI is AI that takes actions toward a goal instead of only answering questions. An agent plans steps, calls tools such as APIs, apps and browsers, checks the results and continues until the task is done, often with a person approving risky steps.
What are OpenAI Dots?
Dots are persistent, always-on agents OpenAI launched at DevDay on September 29, 2026. They run on GPT-6 Astra, keep working after you close the chat, connect to more than 4,000 apps, and use Custom Rules that allow an action, require approval or prohibit it.
What is Atlassian AMP?
AMP, the Agentic Multiplayer Protocol, was announced by Atlassian on October 7, 2026 at Team '26 Europe. It makes AI agents named teammates in Jira and Confluence: every agent has a clear owner and profile, works from the Teamwork Graph, inherits permissions and logs every action to an audit trail.
What is Oracle Fusion Claw?
Fusion Claw is a governed agent runtime Oracle announced on September 29, 2026, inspired by the OpenClaw approach. Customers define an Enterprise Operating Envelope of objectives, permissions, risk thresholds and approval rules, and the runtime is isolated so the language model cannot directly change Fusion business records.
Do consumers trust AI agents to make purchases?
Not yet. The September 2026 Visa Trust Index found only 23% of US consumers trust GenAI to handle payment transactions for them, and Cover Genius found only 5% are comfortable with an agent buying on its own.
What is an agent envelope?
An agent envelope is the set of controls around an AI agent: a named owner, its own identity, a scoped list of tools, risk-based approval rules and an audit log. The September and October 2026 launches from OpenAI, Atlassian, Oracle and SAP all ship a version of it.
How do I add governance to my own AI agent?
Put a policy gate between the model and tool execution. Give each agent its own identity and owner, list the tools it may call, assign each tool a risk tier, auto-approve low-risk actions, require human approval above a threshold, deny irreversible actions, and log every decision with its reason.
- Agentic AI
- AI Agents
- AI Governance
- OpenAI
- Enterprise AI
- Agentic Commerce
Written by Harsh Rastogi, AI Product Engineer and Business AI Head at Modelia. More on AI products, agents and production engineering on LinkedIn.