AI Agents Are Ready to Act. Finance Should Decide Who Signs Off.

Articles
Todd McElhatton, COFO at Zuora
29 September 2026
2 MINS
Zuora AI
AI Agents Are Ready to Act. Finance Should Decide Who Signs Off.

Finance leaders should recognize that trade off immediately, because we make a version of it every time we automate a workflow. AI can already complete the task in question. The harder call is what it needs in order to try, and whether we are comfortable handing that access and information over.

This year gave us a preview of what that looks like unsupervised. In September, Google confirmed that its Gemini model broke into three real companies back in May, after a configuration error left it connected to the live internet during a security exercise instead of a sealed test environment. It used guessed and stolen credentials to get into all three before anyone caught it. At a much smaller scale, an Australian man asked his AI assistant to get him into a fully booked Pilates class. It found a gap in the gym’s booking system and canceled a stranger’s reservation to make room for him.

Both were doing what agents do: pursuing an objective with whatever tools were available, and continuing until something stopped them.

Where the Real Risk Sits

Finance has a version of this problem that is harder than the consumer examples making headlines. Both incidents trace back to the same gap: an agent with the authority to act on what it saw, without anyone approving the action first. That gap between access and authority is where the real exposure sits. An agent with read access to your quote-to-cash system can be genuinely useful. An agent with the authority to release revenue, adjust a contract, or issue a credit can be just as useful, but only when a person confirms the action first. Standing authority to take that same action unsupervised is a different category of risk, no matter how good the model is that quarter.

A workflow being automatable does not settle whether it should run unsupervised. Speed and trust are not the same thing, and judgment is the part finance cannot hand off.

Actionable Steps for Managing AI Risk in Finance

  • Separate recommendation from execution. Our revenue accounting team uses AI to trace a variance back to the contract change that caused it, or to explain why revenue wasn’t recognized on a particular contract. That’s investigation, and it’s the part we’re more comfortable automating. Deciding what the number should be, and signing off on it, still sits with the accountant.
  • Audit agent permissions the way you’d audit a person’s access. Approval Controls apply the same separation of duties you’d expect between the person proposing an action and the person approving it. Most finance teams already run the first review. Few have built the second.
  • Keep approval inside the workflow, not just in policy. Our reviews of AI-assisted revenue and billing work still happen in a team setting instead of moving to async sign-off, because the questions that matter most are about whether a result makes sense, not just whether the numbers tie out. A second set of eyes in the room catches that faster than a checkbox nobody has to explain. We built the same logic into Zuora AI’s Supervised Mode: an agent can propose a revenue release or a write-off, but nothing posts until a person confirms it.
  • Ask “should we” after “can we.” We learned this firsthand while embedding AI across our own quote-to-cash process. Where the underlying workflow wasn’t clearly defined yet, AI accelerated confusion instead of solving it. Automate the workflows you understand well enough to trust, and hold off on the ones you don’t.

 

The permissions audit can’t be a one-time setup. People can find ways around a control that gets in the way of a result, like splitting one large purchase into three smaller ones to stay under an approval threshold. An AI agent will find the same kind of gap, and it will likely find it faster than a person would. 

None of this requires a better model. It requires finance leaders who decide, deliberately, where an agent’s judgment stops and a person’s begins, and who build that line into the workflow instead of leaving it to chance. That decision, made ahead of time, is what earns trust in AI within finance.

Keep Exploring

User Guide: How Comcast Technology Solutions’ Finance Team Puts Zuora AI to work 

Finance leaders need to define where an AI agent’s role ends and human judgment begins. This guide to Comcast Technology Solutions offers a practical example: its finance team uses Zuora AI for defined tasks such as posting invoice batches, querying billing data, refining workflow logic, and building consolidated reports, while validating results and keeping people, permissions, and trusted data in the loop. 

From Product Launch to Recognized Revenue

AI governance matters at every stage of quote-to-cash, not only when an agent is ready to post a change. This on-demand journey from product launch to recognized revenue shows how finance and operations teams can use Zuora AI to investigate issues, understand financial impact, and take governed action across pricing, quoting, billing, collections, and revenue recognition. The demo makes the control model concrete: agents work with shared quote-to-cash context and existing permissions, while supervised writes and approval rules keep people responsible for what moves money.