Agentic AI in October 2026: Agents Now Need Owners (Dots, AMP, Fusion Claw, SAP)

    In two weeks, OpenAI, Atlassian, Oracle and SAP each shipped agents with named owners, scoped permissions, approval rules and audit logs, and America.gov tested whether citizens will let AI act for them. Here's what launched, why only 23% of consumers trust agents with payments, and a working TypeScript agent envelope you can copy.

    Published
    Reading time
    12 min read
    Agentic AI in October 2026: an agent inside a governed boundary of owner, scope, approval and audit
    On this page

    TL;DR: Between September 29 and October 9, 2026, OpenAI, Atlassian, Oracle and SAP each shipped a major agent launch, and the US government put an AI front door on its services. Under the different names, all four companies shipped the same thing: an agent with a named owner, its own identity, scoped permissions, approval rules for risky actions, and an audit log. Model capability is no longer what holds agents back. Context, governance and trust are. Consumer data agrees: only 23% of US consumers trust GenAI to make payments for them (Visa Trust Index, September 2026). Below: what each company shipped, the pattern they share, a working TypeScript "agent envelope" you can copy, and how I'd build agents in 2027 as a result.

    Agentic AI in October 2026: agents now need owners, scopes, approvals and audit trails
    Agentic AI in October 2026: agents now need owners, scopes, approvals and audit trails

    Why This Two-Week Window Matters

    If you read Forbes' agentic AI coverage from the last two weeks, the headlines look scattered: Atlassian and enterprise context, SAP and governance, OpenAI's new always-on agents, agentic cybersecurity budgets, a consumer trust gap in agentic commerce, and America.gov testing whether citizens will let an agent act for them.

    Read them together and they make one argument. 2025 was about whether agents could do the work. Late 2026 is about who answers for them when they do. Every vendor launch in this window put most of its effort into the same scaffolding around the model: identity, permissions, approvals, audit and context.

    I build production AI systems for fashion commerce at Modelia, and I've written before about real-world agentic patterns and error recovery for agents. This post is the news-driven follow-up: what changed, and what to do about it if you ship agents.

    Deep dives in this series:

    The Five Launches at a Glance

    DateWhoWhat shippedThe governance piece
    Sep 29OpenAIDots, always-on agents on GPT-6 Astra, plus ChatGPT SpaceCustom Rules (allow / require approval / prohibit), Activity View, auto-review of consequential actions
    Sep 29OracleFusion Claw, a governed agent runtime with 25 new agentic apps"Enterprise Operating Envelope": objectives, permissions, risk thresholds, approval rules
    Sep 29US governmentAmerica.gov, an AI front door to federal servicesAnswers only at launch; transactions like passport renewal planned later
    Oct 6–8SAP (SAP Connect)Joule Work, more Joule agents, AI Agent HubCentral agent inventory, ISO/IEC 42001-certified governance, customer-set autonomy
    Oct 7Atlassian (Team '26 Europe)AMP, the Agentic Multiplayer ProtocolEvery agent has an owner and profile, inherits permissions, logs every action

    OpenAI Dots: Agents That Keep Working After You Log Off

    At DevDay on September 29, OpenAI launched Dots, persistent agents built to "keep working after an employee closes the chat window" (VentureBeat). They run on GPT-6 Astra, connect to more than 4,000 apps through OpenAI's plugin ecosystem, and talk to you through ChatGPT, Slack and Microsoft Teams. The first Dot is included for Pro and Business Premium customers, and Enterprise, Edu and Healthcare get a beta once an admin turns it on.

    The interesting part is the control surface, not the model:

    • Custom Rules let an organization permit an action, require approval for it, or prohibit it.
    • Activity View shows background work so a person can step in.
    • Auto-review checks consequential actions before they run on their own.

    Forbes' Ron Schmelzer asked the obvious question: do you need them? My answer: only for work with a clear owner and a narrow tool list. (Deep dive: OpenAI Dots explained.) An always-on agent with 4,000 possible connections and vague instructions keeps making changes in your accounts long after you've stopped checking.

    Atlassian AMP: Agents as Named Teammates

    On October 7 in Amsterdam, Atlassian introduced AMP, the Agentic Multiplayer Protocol (Business Wire). Its core rule fits in one line: "Every agent under AMP has a clear owner and distinct profile." Agents show up in Jira and Confluence threads, in presence bars and cursors next to people, and they work from Atlassian's Teamwork Graph, which it says connects more than 250 billion objects and relationships. Every action goes into an audit trail. Atlassian says agents can run as a user or under service accounts, but dedicated agent accounts are still listed as "coming soon," so for now many agent actions run with the launching user's permissions.

    Atlassian's own usage numbers:

    • Humans and agents work together more than 10 million times a month
    • The Atlassian MCP server has nearly 2 million monthly active users
    • It handles over 15 million tool calls a day, up 15x in six months
    • The new version uses up to 25% fewer tokens for the same Jira and Confluence work (Atlassian's internal benchmark on Claude models)

    That last number matters more than it looks. Agents waste most of their tokens finding context. Whoever holds the context can make agents cheaper and more accurate, which is exactly the point of Steve McDowell's Forbes piece, Atlassian's Move To Own The Context Powering Enterprise Agentic AI. He also notes that Atlassian hasn't published a specification other vendors can implement on their own, so for now AMP is a "protocol" only inside Atlassian's products. (Deep dive: Atlassian AMP explained.)

    Oracle Fusion Claw: Keep the Model Away From the Database

    Oracle announced Fusion Claw on September 29 (Oracle). It is a governed runtime inspired by the open-source OpenClaw approach, though Oracle says it built its own. It shipped with 25 Claw-powered applications across finance, HR, supply chain and sales, bringing its Fusion Agentic Applications to 75 (Futurum).

    Two design choices are worth copying:

    1. 01An "Enterprise Operating Envelope." Customers set objectives, permissions, risk thresholds and approval rules, and can require a person to review the plan before it runs (SiliconANGLE).
    2. 02Isolation. The runtime sits in an isolated environment that stops the language model from directly changing Fusion business records (Forkast). The model proposes actions, and deterministic code applies them.

    The second choice is the one most teams skip. If your agent's tool is "run this SQL," the model effectively has write access to your database. If its tool is "issue refund for order X, up to $Y," your code still controls what can change. (Deep dive: Oracle Fusion Claw explained.)

    SAP: Governance Is the Product

    At SAP Connect, SAP's pitch was less about what its agents can do and more about how they are controlled. Steve Banker's Forbes headline sums it up: SAP Seeks To Differentiate Itself With AI Governance. From SAP's own announcement (SAP News):

    • The SAP AI Agent Hub in SAP LeanIX provides "a central inventory of enterprise agents"
    • Its governance architecture is independently ISO/IEC 42001-certified
    • Agents act "using established data, authorizations and audit trails," and customers control the level of autonomy
    • Joule Work is already live with 110,000 employees, and SAP reports 20% productivity gains across finance, HR and procurement (vendor-reported)

    An agent inventory sounds dull until you try to answer a simple question in a large company: how many agents do we run, who owns each one, and what can each one touch? Most companies can't answer it today. Agentic AI is also lifting identity vendors: Forbes reported in July that agentic AI demand made Okta's CEO a billionaire again. Non-human identity is now a market of its own.

    America.gov: The Public Trust Test

    America.gov launched on September 29 as an AI chatbot that answers questions using federal websites. For now, it can tell you which form to use to renew a passport, but it can't renew it for you. The White House says passport renewal and Medicare enrollment will come later, and reported timelines run from late 2026 to early 2027.

    Sandy Carter's Forbes piece frames it well: America.gov tests whether Americans will trust AI agents to act. Going from answering to acting is the hardest step in agent design, and the government is taking it in public, in that order, which is the right order.

    The Trust Gap Is in the Data

    On consumer agents, the numbers are consistent:

    • 23% of US consumers trust GenAI to handle payment transactions for them (Visa Trust Index, Harris Poll, 2,065 US adults, fielded May 26–28, 2026)
    • Only 5% of consumers are comfortable with an agent making purchases on its own, even though 78% are open to AI shopping help (Cover Genius, September 2026)
    • 24% say they will never delegate a purchase to AI, and consumers' top requirements are spending caps, instant revocation and easy cancellation (Checkout.com, June 2026)

    Jordan McKee's Forbes column calls this agentic commerce's consumer trust problem: people are glad to let AI research and compare products, but far fewer will let it pay. I break down all the 2026 survey data, and the safeguards that change people's minds, in The Agentic Commerce Trust Gap. That matches what I see building AI for fashion e-commerce. Shoppers like AI that helps them decide, such as seeing a garment on a model that looks like them. Letting it spend their money is a much bigger step.

    The lesson for builders is not to give up on autonomous checkout. It's to earn autonomy step by step: read first, then write, then spend small amounts under a limit, with approval required above it.

    The Pattern: The Agent Envelope

    Put the five launches side by side and the same five parts show up every time. I call this the agent envelope:

    PartWhat it meansWho shipped it
    OwnerA named person accountable for every agentAtlassian AMP
    IdentityThe agent's own identity, not a shared API keyAtlassian (agent accounts, coming soon), SAP (agent inventory)
    ScopeAn explicit list of tools and data it may touchDots (app access), Fusion Claw (permissions)
    Approval rulesRisk-based allow / ask / deny decisionsDots Custom Rules, Fusion Claw thresholds
    AuditEvery action logged with who, what and whyAMP, SAP, Dots Activity View

    The sixth part sits under all of these: context. Atlassian's Teamwork Graph, SAP's knowledge graph and Steven Wolfe Pereira's Forbes argument that agents need ontologies to understand your business all make the same point. An agent can only be as good as the business context it can query.

    Build It: A Minimal Agent Envelope in TypeScript

    You don't need a vendor platform to get the pattern. Here's a small policy gate that sits between your agent's tool calls and their execution. It needs no dependencies and runs on Node 22+ with npx tsx agent-envelope.ts.

    typescript
    // agent-envelope.ts: run with `npx tsx agent-envelope.ts` (Node 22+)
    
    type Risk = "read" | "write" | "money" | "irreversible";
    type Decision = "allow" | "approve" | "deny";
    
    interface AgentIdentity {
      id: string;     // the agent's own identity, never a shared API key
      owner: string;  // the human accountable for it
      scopes: string[]; // tools it may call at all
    }
    
    interface ActionRequest {
      tool: string;
      risk: Risk;
      amountUsd?: number;
      args: Record<string, unknown>;
    }
    
    interface Envelope {
      autoApproveRisks: Risk[];  // run without asking
      spendLimitUsd: number;     // money actions above this need a human
      denyRisks: Risk[];         // never allowed, even with approval
    }
    
    interface AuditEntry {
      at: string;
      agent: string;
      owner: string;
      tool: string;
      decision: Decision;
      reason: string;
    }
    
    const auditLog: AuditEntry[] = [];
    
    function decide(agent: AgentIdentity, req: ActionRequest, env: Envelope): [Decision, string] {
      if (!agent.scopes.includes(req.tool)) return ["deny", `tool "${req.tool}" is outside the agent's scope`];
      if (env.denyRisks.includes(req.risk)) return ["deny", `${req.risk} actions are blocked for agents`];
      if (req.risk === "money") {
        if ((req.amountUsd ?? Infinity) > env.spendLimitUsd) {
          return ["approve", `${req.amountUsd} is over the ${env.spendLimitUsd} limit`];
        }
        return ["allow", `within the ${env.spendLimitUsd} limit`];
      }
      if (env.autoApproveRisks.includes(req.risk)) return ["allow", `${req.risk} is auto-approved`];
      return ["approve", `${req.risk} needs a human`];
    }
    
    function gate(agent: AgentIdentity, req: ActionRequest, env: Envelope): Decision {
      const [decision, reason] = decide(agent, req, env);
      auditLog.push({ at: new Date().toISOString(), agent: agent.id, owner: agent.owner, tool: req.tool, decision, reason });
      return decision;
    }
    
    // --- example: a shopping agent acting for a customer ---
    const agent: AgentIdentity = {
      id: "agent:reorder-bot",
      owner: "harsh@example.com",
      scopes: ["catalog.search", "cart.add", "checkout.pay"],
    };
    
    const envelope: Envelope = {
      autoApproveRisks: ["read", "write"],
      spendLimitUsd: 50,
      denyRisks: ["irreversible"],
    };
    
    const requests: ActionRequest[] = [
      { tool: "catalog.search", risk: "read", args: { q: "white sneakers size 9" } },
      { tool: "cart.add", risk: "write", args: { sku: "SNK-9-WHT" } },
      { tool: "checkout.pay", risk: "money", amountUsd: 120, args: { cart: "c_123" } },
      { tool: "account.delete", risk: "irreversible", args: {} },
    ];
    
    for (const req of requests) gate(agent, req, envelope);
    console.table(auditLog.map(({ tool, decision, reason }) => ({ tool, decision, reason })));

    Output:

    text
    ┌─────────┬──────────────────┬───────────┬──────────────────────────────────────────────────────┐
    │ (index) │ tool             │ decision  │ reason                                               │
    ├─────────┼──────────────────┼───────────┼──────────────────────────────────────────────────────┤
    │ 0       │ 'catalog.search' │ 'allow'   │ 'read is auto-approved'                              │
    │ 1       │ 'cart.add'       │ 'allow'   │ 'write is auto-approved'                             │
    │ 2       │ 'checkout.pay'   │ 'approve' │ '$120 is over the $50 limit'                         │
    │ 3       │ 'account.delete' │ 'deny'    │ `tool "account.delete" is outside the agent's scope` │
    └─────────┴──────────────────┴───────────┴──────────────────────────────────────────────────────┘

    A few notes on the design:

    • Scope is checked before risk. account.delete is denied because the agent was never given that tool, not because the model chose not to call it. Never rely on the prompt for a boundary you can enforce in code.
    • "Approve" is a real state, not an error. In production it should pause the run, notify the owner (Slack, email, an in-app card) and resume with the decision. Durable workflow engines handle this well.
    • The model never sees the envelope. It asks to call a tool, and your code decides. That's the Fusion Claw principle at a small scale.
    • The audit log records the owner on every row. When something goes wrong, you know who to ask and why the action was allowed.

    To use this with a real agent, wrap your tool executor so every tool call from the Claude API, OpenAI or MCP goes through gate() first. My Model Context Protocol guide covers where that hook sits in an MCP server, and the agentic error recovery skill gives you a checklist for hardening the rest of the loop.

    What I'd Do Differently in 2027

    Based on these two weeks of launches, here is how I'd plan agent work going into 2027:

    1. 01Start from the envelope, not the prompt. Before writing a system prompt, write down the owner, the tool list, the risk tier of each tool, and the approval rule. If you can't fill that in, the agent isn't ready to ship.
    2. 02Give agents their own identities. Shared API keys make every audit question unanswerable. Service accounts per agent are cheap now.
    3. 03Make tools narrow and typed. "Refund order X up to $Y" beats "call the payments API." Narrow tools are also what make the cheap models work: a small model like Claude Haiku 5.5 handles a narrow, well-typed tool reliably at a fraction of the cost.
    4. 04Invest in context before autonomy. Atlassian's 25% token saving came from better context, not a better model. A clean, queryable view of your business data improves every agent you build on top of it.
    5. 05Let users earn autonomy step by step. Start with read-only, then writes, then spending under a limit, and raise limits based on each user's track record. The 23% trust number is where you start, not a ceiling.
    6. 06Measure ROI per agent. Forbes' CIO guide to agentic AI is about moving from experiments to returns. You can only measure returns per agent if each agent has an identity and a log.

    My Take

    The agentic AI story of October 2026 isn't a model launch. It's every major platform admitting the same thing: an agent nobody owns is a liability. The vendors that win enterprise agents will be the ones with the best context and the most trusted controls, and Atlassian, SAP and Oracle are all betting on exactly that.

    For engineers this is good news, because the envelope is ordinary software engineering. Identity, permissions, typed APIs, approval flows and audit logs are problems we already know how to solve. The model handles the reasoning, and the envelope is the part we build and own.

    If you're building agents, start with my guides on Claude agentic workflows in production and agentic error recovery and observability. For a running feed of launches like these, see AI Pulse.


    References

    1. 01Forbes, Agentic AI topic page. forbes.com/topics/agentic-ai
    2. 02Atlassian via Business Wire, "Atlassian Introduces AMP: The Agentic Multiplayer Protocol to Power Human-AI Collaboration," October 7, 2026. financialcontent.com
    3. 03Steve McDowell, "Atlassian's Move To Own The Context Powering Enterprise Agentic AI," Forbes, October 9, 2026. forbes.com
    4. 04VentureBeat, "OpenAI launches Dots, always-on AI agent coworkers, and ChatGPT Space," September 29, 2026. venturebeat.com
    5. 05Ron Schmelzer, "What Are OpenAI Dots And Do You Need Them?", Forbes, October 5, 2026. forbes.com
    6. 06Oracle, "Oracle Extends Fusion Agentic Applications with Introduction of Fusion Claw," September 29, 2026. oracle.com
    7. 07Futurum Group, "Oracle Fusion Claw: From AI Assistance to Governed Autonomous Execution." futurumgroup.com
    8. 08SiliconANGLE, "Oracle expands AI agent features with Fusion Claw," September 29, 2026. siliconangle.com
    9. 09Forkast, "The Application Layer Is Absorbing Agent Infrastructure." forkast.news
    10. 10SAP News, "SAP Puts the Autonomous Enterprise to Work," October 2026. news.sap.com
    11. 11Steve Banker, "SAP Seeks To Differentiate Itself With AI Governance," Forbes, October 8, 2026. forbes.com
    12. 12Kirk Ogunrinde, "Agentic AI Demand Makes Okta CEO A Billionaire Again," Forbes, July 2, 2026. forbes.com
    13. 13The Rundown, "America.gov launches with AI answers and plans for federal applications." therundown.ai
    14. 14Sandy Carter, "America.gov Tests Whether Americans Will Trust AI Agents To Act," Forbes, October 7, 2026. forbes.com
    15. 15Visa, "Visa Trust Index explores agentic commerce adoption," September 9, 2026. corporate.visa.com
    16. 16Cover Genius, "Do Consumers Trust AI Shopping Agents With Checkout?", September 25, 2026. covergenius.com
    17. 17Checkout.com, "Consumer demand for AI shopping is forming fast but trust for agentic commerce is still catching up," June 9, 2026. checkout.com
    18. 18Jordan McKee, "Agentic Commerce Has A Consumer Trust Problem," Forbes, October 1, 2026. forbes.com
    19. 19Steven Wolfe Pereira, "Your AI Agents Can Write Code. Can They Understand Your Business?", Forbes, October 2, 2026. forbes.com
    20. 20Megan Poinski, "The CIO's Guide To Agentic AI: How To Move From Experiments To ROI," Forbes, April 23, 2026. forbes.com

    Harsh Rastogi is an AI Product Engineer at Modelia, building production generative-AI systems for fashion commerce, and the creator of carcode. He writes about AI systems, developer tooling and production engineering at harshrastogi.tech.

    Frequently asked questions

    What is agentic AI?

    Agentic AI is AI that takes actions toward a goal instead of only answering questions. An agent plans steps, calls tools such as APIs, apps and browsers, checks the results and continues until the task is done, often with a person approving risky steps.

    What are OpenAI Dots?

    Dots are persistent, always-on agents OpenAI launched at DevDay on September 29, 2026. They run on GPT-6 Astra, keep working after you close the chat, connect to more than 4,000 apps, and use Custom Rules that allow an action, require approval or prohibit it.

    What is Atlassian AMP?

    AMP, the Agentic Multiplayer Protocol, was announced by Atlassian on October 7, 2026 at Team '26 Europe. It makes AI agents named teammates in Jira and Confluence: every agent has a clear owner and profile, works from the Teamwork Graph, inherits permissions and logs every action to an audit trail.

    What is Oracle Fusion Claw?

    Fusion Claw is a governed agent runtime Oracle announced on September 29, 2026, inspired by the OpenClaw approach. Customers define an Enterprise Operating Envelope of objectives, permissions, risk thresholds and approval rules, and the runtime is isolated so the language model cannot directly change Fusion business records.

    Do consumers trust AI agents to make purchases?

    Not yet. The September 2026 Visa Trust Index found only 23% of US consumers trust GenAI to handle payment transactions for them, and Cover Genius found only 5% are comfortable with an agent buying on its own.

    What is an agent envelope?

    An agent envelope is the set of controls around an AI agent: a named owner, its own identity, a scoped list of tools, risk-based approval rules and an audit log. The September and October 2026 launches from OpenAI, Atlassian, Oracle and SAP all ship a version of it.

    How do I add governance to my own AI agent?

    Put a policy gate between the model and tool execution. Give each agent its own identity and owner, list the tools it may call, assign each tool a risk tier, auto-approve low-risk actions, require human approval above a threshold, deny irreversible actions, and log every decision with its reason.

    • Agentic AI
    • AI Agents
    • AI Governance
    • OpenAI
    • Enterprise AI
    • Agentic Commerce

    Written by Harsh Rastogi, AI Product Engineer and Business AI Head at Modelia. More on AI products, agents and production engineering on LinkedIn.

    Share

    LinkedInX
    Portrait of Harsh Rastogi, AI Product Engineer

    Harsh Rastogi

    AI Product Engineer and Business AI Head at Modelia

    I build AI products and agents from the first sketch to production at Modelia, and I'm a Founding Engineer at SelfAgentic. Before that I built platforms at Asynq and Bharat Electronics Limited. I publish the agent skills I use every day, and you can see what I've shipped in my work.

    • Oracle Fusion Claw Explained: OpenClaw's Agent Idea, Rebuilt for the Enterprise

      Oracle announced Fusion Claw on September 29, 2026: a governed agent runtime inspired by OpenClaw, with an Enterprise Operating Envelope, an isolated runtime that keeps the model away from business records, and an Outcome Receipt for every task. Here's how it works, the 25 launch apps, the open questions, and a propose-validate-apply pattern you can copy.

      • Oracle
      • AI Agents
      • Agentic AI
      • Enterprise AI
      AI & Machine Learning9 min read
    • OpenAI Dots Explained: Always-On ChatGPT Agents, What They Can Do, and What They Can't

      OpenAI Dots are persistent ChatGPT agents launched at DevDay on September 29, 2026. Each one runs on GPT-6 Astra with its own cloud computer, connects to 4,000+ apps and keeps working after you log off. Here's how they work, what they cost, what they can't do yet, and an undo-ledger pattern for long-running agents.

      • OpenAI
      • OpenAI Dots
      • AI Agents
      • Agentic AI
      AI & Machine Learning9 min read
    • Atlassian AMP Explained: The Agentic Multiplayer Protocol and AI Agents as Teammates

      Atlassian announced AMP, the Agentic Multiplayer Protocol, at Team '26 Europe on October 7, 2026. Every agent gets an owner and profile, works from the 250-billion-object Teamwork Graph and logs its actions. Here's how it works, what's shipped vs coming soon, an admin checklist, and a permission model you can copy.

      • Atlassian
      • AI Agents
      • Agentic AI
      • MCP
      AI & Machine Learning10 min read

    Get the next article by email.

    New articles and AI Pulse editions. Nothing else.