What an agent is allowed to touch decides where it can be deployed. The market resolved the question in four days.
01
02
The binding constraint on an agent in payroll is not how good it is. It is what it is allowed to touch. Those are orthogonal properties, and conflating them is how a governance conversation ends up measuring the wrong thing: an agent can be perfectly scoped and routinely wrong, or unrestricted and always right.
Through the first half of the year the answer looked settled in the other direction. The blueprint stated in April, after Gusto's launch, was to expose query and insight to the AI surface while gating transactions on infrastructure the vendor controls. It was written up as the template every regulated vendor would follow. It broke for its own exemplar inside four days, when Gusto was promoted to the Connectors Directory with 41 tools including run_payroll.
What replaced it took three positions before the market picked one. A shared service-account token gives an agent write capability but resolves authority to a token rather than a person, which is unanswerable when an auditor asks who changed a record. Read-only is the strongest possible governance because the agent cannot act at all, but it can never file the change of address, only look it up. Write-scope bounded by the authenticated user's own permissions gives you capability and an answer: every action is exactly one named human's authority, no more.
Three vendors shipped that third model inside four days of each other. It is now the mid-market default, and the implication for how these products get compared is direct: tool count becomes a vanity metric. Ninety-four tools scoped to the operating user beats a larger toolset on a shared token, because only one of them survives a procurement conversation about attestation.
The strongest evidence is what nobody shipped. Not one vendor released an autonomous swarm. Every launch in the window led with the constraint rather than the capability: a control plane, agents traceable to a named person, a hard human-approval gate. That is the same architecture one major vendor arrived at only after scrapping unbounded multi-agent orchestration twice, having found that it compounds error at every natural-language handoff.
What would change our mind. The read-only position is strictly safer and it is winning the layer that matters most, sitting beneath the agents as the deterministic engine rather than gating its own transactions. Two different resolutions are shipping at once. If a major vendor takes share on capability breadth with an unscoped write surface, this is wrong.
03
The binding constraint on an agent is not how good it is, it is what it is allowed to touch. An agent can be perfectly scoped and routinely wrong, or unrestricted and always right - permission and correctness are orthogonal axes. Three positions were live: a shared service-account token where authority resolves to a token rather than a person; read-only, which is safest but can never file the change of address; and write-scope bounded by the authenticated user's own RBAC. Omni, BambooHR and Workable all shipped the third inside four days.
04
If permission scoping is the constraint then capability comparisons stop discriminating and tool count becomes a vanity metric - 94 tools scoped to the user beats a bigger toolset on a shared token. Procurement changes shape: not what can your agent do, but whose authority does it act under and can you name the person. That favours whoever owns the identity layer and makes attestation the next contested column, which is why Agent Passport exists and why it covers third-party agents. It also explains the shape of every launch in the window - a control plane, agents traceable to a named person, a hard human-approval gate. Nobody shipped an autonomous swarm, because the buyer cannot accept one.
05
Given equal weight to the claim. Hiding the counter is how a prediction becomes an article of faith.
06
07
Specific public numbers we check on a schedule, so this claim can be tested without taking our word for it. Not checked means nobody looked. That counts as nothing, never as agreement.
| What we check | Status | Latest reading | Last checked |
|---|---|---|---|
| Auth model published per vendor MCP: service-account vs user-scoped OAuth vendor MCP docs and repos · scan | changing | Justworks (PEO) self-hosted MCP, read-only for admins, user-scoped OAuth on the individual's own credentials; benefits excluded in beta, write promised. Found at origin (help doc 31 Jul), not directory-listed. | 2026-09-21 |
| Vendors publishing agent attestation against named external standards vendor releases · event | not moving | Still Workday alone. Agent Passport (OWASP LLM Top 10 / NIST AI RMF / MITRE ATLAS, Cisco as attestor) remains the only HR&P agent attestation published against named external standards. Workday's own newsroom carries nothing further on agent governance after the 2 June release, and no mid-market HR&P vendor has published an equivalent in the 72 days since. | 2026-08-13 |
08
Cumulative linked signals, by direction. A line that only climbs in green is being read generously.
9 counted: 4 diverges · 5 supports · 2 predate the claim and are not counted
| Date | Signal | Bearing | On which part of the mechanism |
|---|---|---|---|
| 2026-08-05 | signal-check-preview-superseded | Before the claim (not counted) | User-scoped write is the mid-market default; no significant vendor ships a shared-service-account write surface as a new product, and vendors with one migrate off it. |
| 2026-08-04 | signal-indeed-pauses-auto-apply | Before the claim (not counted) | The binding constraint on an agent is what it is allowed to touch, not how good it is. |
| 2026-08-13 | signal-juicebox-mcp-permission-inherit | supports | The binding constraint on an agent is what it is allowed to touch, not how good it is. |
| 2026-08-13 | signal-oracle-thirteen-talent-agents | supports | Permission and correctness are orthogonal, and vendors describe only permission. |
| 2026-08-13 | signal-check-sandbox-only-retry | supports | The binding constraint on an agent is what it is allowed to touch, not how good it is. |
| 2026-08-20 | signal-rippling-agent-identity-narrower | diverges | User-scoped write is the mid-market default; no significant vendor ships a shared-service-account write surface as a new product, and vendors with one migrate off it. |
| 2026-08-26 | signal-asure-luna-agentic-execution | diverges | User-scoped write is the mid-market default; no significant vendor ships a shared-service-account write surface as a new product, and vendors with one migrate off it. |
| 2026-08-25 | signal-rippling-mcp-code-mode | diverges | The binding constraint on an agent is what it is allowed to touch, not how good it is. |
| 2026-09-01 | signal-rippling-helpdesk-admin-gate | diverges | User-scoped write is the mid-market default; no significant vendor ships a shared-service-account write surface as a new product, and vendors with one migrate off it. |
| 2026-09-08 | signal-sap-klein-200-agents-september | supports | Permission and correctness are orthogonal, and vendors describe only permission. |
| 2026-08-31 | signal-personio-mcp-write-off-by-default | supports | User-scoped write is the mid-market default; no significant vendor ships a shared-service-account write surface as a new product, and vendors with one migrate off it. |
09
Whether this is new ground or a continuation. A cold-start system reads continuations as births unless the history is stated.
NOT a fresh three-week observation. MCP exposure is tracked continuously in the corpus from March 2026 (L234) through the April auth inflection (L257-L259) to the July write convergence (L374, L417). The three-week window is the INFLECTION, not the evidence base. Recorded because a cold-start prediction system has no priors, so a continuation reads as a birth unless the lineage is stated.
10
Independent vendors clustering is valid evidence. A cluster with no stated driver is an unasked question.
Omni (20 Jul), BambooHR (21 Jul) and Workable (23 Jul) shipped user-scoped write inside four days. Three disconnected vendors, three independent signals -- not one event re-reported. Two plausible drivers, and they are not exclusive: the MCP release candidate finalising 28 July hardened the auth and versioning model every user-scoped surface inherits, so shipping ahead of it is a rational cadence; and SHRM26 in June set the buyer expectation these releases answer. Recorded because a cluster with no stated driver is an unasked question, not evidence.
11
The market moved along a different path than the one drawn. The prediction keeps its identity and its history. A narrative that changed is itself evidence.
Was: Regulated vendors expose query and insight to agents while gating transaction on their own infrastructure. Stated on 2026-04-08 as 'the blueprint for how a regulated vendor ships onto an AI marketplace' after Gusto's launch, and treated as the template the category would follow.
Became: User-scoped write remains the mid-market default. No significant mid-market HR&P vendor ships a shared-service-account write surface as a new product, and vendors that already have one migrate off it.
Why: The read-only consensus did not hold. It broke for its own exemplar within four days -- Gusto was promoted to the Connectors Directory on 2026-04-12 with 41 tools including run_payroll -- and for the segment by July, when Omni, BambooHR and Workable shipped write-scoped MCP inside four days of each other. The original claim's falsifier would no longer fire on the evidence that now matters: the question stopped being WHETHER an agent may write and became UNDER WHOSE AUTHORITY it writes. That is a different mechanism, not a stronger version of the same one, which is why this is a transformation rather than a fresh claim or a contradiction.
4 signals carried forward; 2 dropped as no longer bearing on the claim: falsified rather than transformed. No vendor adopted it as a lasting position; the one vendor still read-only (Symmetry) got there by a different route -- being the deterministic engine beneath the agents, not gating its own transactions.; Gusto abandoned it. Carrying it forward would inherit supporting evidence for a claim its own source no longer supports.
12
New. Split out of an earlier bundled correctness+governance thesis after the bundling audit found them to be orthogonal axes. Sourced entirely from the June-July digest material recovered on 2026-08-12.
This prediction carries no resolution date. We cannot predict when evidence will arrive, so the review cadence attaches to the instruments above rather than to the claim. It runs until the market proves it, moves it, or twelve months pass with no material signal against it.
How a signal becomes a prediction →