Who Signs Off When the System Starts Making Decisions?

Home > Blog > Who Signs Off When the System Starts Making Decisions?
aa

Last edition, we asked a governance question many organisations struggle to answer:

Who signed off on the risk in your last D365 release?

Microsoft’s latest Dynamics 365 release wave doesn’t replace that question.

It expands it.

Across Finance & Operations, Microsoft is introducing more agentic capabilities—AI experiences that can coordinate work, initiate business tasks and assist users with progressively less manual intervention, depending on how organisations configure governance and approval policies.

For an ERP platform that underpins finance, procurement and operations, this isn’t simply another feature release.

It changes how decisions are made—and, more importantly, how those decisions are governed.


When Decision-Making Changes, Governance Has to Change Too

Think back to the three questions from Edition 13.

Now ask them again—but this time, imagine part of the workflow is initiated by an AI agent rather than a person.

What changed—in business terms?

A traditional release introduces planned functionality.

An agent-enabled process can introduce different operational outcomes depending on the context in which decisions are made.

Understanding what changed is no longer enough.

Organisations increasingly need to understand how decisions are reached.


Who owns the risk if something goes wrong?

When people make decisions, accountability is usually clear.

When an AI agent initiates an action, accountability depends entirely on the governance model surrounding it.

Who configured the agent?

Who defined its authority?

Who approved those boundaries?

Without clear ownership, “Who approved this?” can quickly become a difficult question to answer.


What evidence proves the business is protected?

Traditional regression testing tells you whether software behaved as expected.

It doesn’t explain why an autonomous agent chose a particular action—or whether that decision remained within the business rules your organisation intended.

As enterprise AI adoption grows, observability, traceability and auditability are becoming essential—not optional—for organisations operating regulated or business-critical processes.

Crestech Perspective

We don’t believe the answer is resisting agentic AI.

Microsoft is clearly investing in this direction, and the potential productivity benefits are significant.

The challenge is making sure governance evolves alongside capability.

That means extending release assurance into something broader.

Release Assurance must evolve into Decision Assurance.

Before an AI agent is trusted with a business-critical process, organisations should be able to answer three simple questions:

  • What decisions is the agent authorised to make?
  • What business rules govern those decisions?
  • What evidence exists to demonstrate that those rules were followed?

Those answers should exist before production—not after an incident.


Final Thought

Edition 13 asked whether your leadership team could explain what changed and why it was safe.

This edition asks a different question.

What if one of the most important business decisions wasn’t made by a person at all?

Would you still be able to explain what happened?

Would you know who approved it?

Would you have the evidence to prove it?

If those questions don’t yet have clear answers, now is the time to start the conversation.

Like the blog? Spread the word

Latest Insights

Go live is a date on the calendar release readiness is a decision you earn

Read More >>

Your p2p automation proves it runs not that the money is right

Read More >>

How to cut your d365 regression suite from 600 tests to 80 and actually improve coverage

Read More >>

Your regression suite is probably testing the wrong things

Read More >>