Over ten days, from September 29 to October 8, 2026, the largest software vendors stopped arguing about whether AI agents work. They started arguing about where an agent should live. OpenAI put its agents in a personal background process. Infor put them inside ERP modules. SAP put them on top of its applications. Microsoft and Google gave theirs email accounts. Nobody coordinated this, and nobody gave the same answer.
If you run operations, this is the decision that matters for the next two years, and most operations leaders don't know it's being made. Any AI automation strategy for operations teams used to start with a process map and a list of tasks to automate. I think it now starts with a smaller question that sounds like admin: where does the agent's home address sit? The address decides what the agent can see and whom it reports to. It decides where its mistakes pile up and who sends you the bill. If you let a vendor choose it, the vendor's product lines become your process boundaries, and you won't notice until a shipment slips through the gap between two of them.
Ten days, five addresses
Here is what happened, in order.
September 29: the agent in your pocket
At DevDay in San Francisco, OpenAI introduced Dots. Coverage of the launch calls them an "always-on AI agent product". They keep working "rather than waiting for each new prompt." A user gives a Dot a goal and sets limits on what it may do alone, and the Dot comes back when it needs attention. In managed workspaces it starts switched off, and an administrator has to enable the beta.
A Dot belongs to a person. It sits next to that person's ChatGPT account and carries that person's goals. That suits a founder chasing a dozen loose threads. For an operations team it raises an awkward question, because a process that runs through one employee's personal agent leaves the building whenever that employee does.
October 6: the agent in the module
Infor shipped its 2026.10 release a week later. Benton Li's release post opens with "Most enterprise artificial intelligence (AI) stops at the recommendation." The release then lists industry agents tied to specific modules. There is an Invoice Match agent, a Bank Reconciliation agent and a Period Close agent. The warehouse system gets Slotting and Wave agents. Supply Chain Planning gets a Shift Report agent. I counted 40 named agents on that page.
Each of those agents lives in a room the vendor already built. Bank Reconciliation knows the bank reconciliation screens and the data under them. It sees the world the way the module sees it, and that's the strength of this model. The agent writes to the system of record with permissions someone has already reviewed. Infor's pricing also makes a point. Its Velocity Suite "includes unlimited usage because insight should not carry a meter."
October 6: the agent on top of the apps
The same day, at SAP Connect, SAP said its Autonomous Enterprise architecture would become generally available in October, alongside Joule Work and Joule Desktop. Manoj Swaminathan, president and chief product officer of SAP's Autonomous Suite, told SiliconANGLE that the "First principle is it's AI on apps as opposed to AI in apps." He added that "Joule is no longer a natural language chat client for us; it is a full-screen experience."
That is a different address from Infor's. SAP wants its agent to sit above the applications, its own and other vendors', and draw context from what the article calls SAP's structured enterprise knowledge graph. Swaminathan's example was total corporate spend, with Joule pulling from ERP, travel and expense, and procurement, then combining the results into one answer. Billing runs on AI units, mainly consumption-based. So SAP's agent lives one floor up from the apps, it bills by the unit, and it expects to be the screen your people look at all day.
October 6: the agent on a leash
Also on October 6, Cloud Wars reported that Microsoft is previewing Hooks in Copilot Studio. A hook pairs an event in the agent's lifecycle, such as a session starting, a tool running or an error, with a workflow that runs when that event happens. The article draws the distinction cleanly. With a tool, the agent decides whether to use it. With a hook, "the event automatically fires." You can use a hook to block a tool call that breaks a business rule, redact a result, or write an audit record.
The article also includes a caveat every operations leader should keep handy: "Hooks don't stop an agent when it fails." If the hook fails, the agent carries on as though the hook returned nothing. The leash exists, and it's thinner than it looks.
October 8: the agent with a mailbox
Two days later the address question became literal. At Gemini at Work 2026, Thomas Kurian announced a universal agent inside Gemini Enterprise that can take on tasks lasting hours or days. VentureBeat's report describes Google's example, an Event Planner Agent with its own Workspace account, email address, calendar, Drive storage and a listing in the company directory. It's in private preview. It can run Anthropic's Claude as well as Gemini. Project-level spending limits can pause agents when a budget runs out.
The same day, Jeff Teper, Microsoft's executive vice president for Apps and Agents, announced a Sales Development Agent that is managed in Teams and "uses its own Exchange account." He also announced a Service Agent that can create CRM cases from Outlook and Teams and escalate after hours. His post says it outright: "The traditional boundaries of business applications are disappearing." Keith Kirkpatrick of The Futurum Group summed it up the next day: "Microsoft is changing what Dynamics 365 is."
An agent with its own email address can be cc'd and forwarded to. Suppliers can reply to it. It sits where most operational mess actually arrives.
The address decides four things
I used to think of agent placement as a deployment detail, like choosing a server region. I don't anymore. Where an agent lives settles four questions that operations leaders usually treat as separate decisions.
The first is what the agent can see. An agent inside the Invoice Match module sees invoices, purchase orders and receipts in clean fields. It doesn't see the email in which the supplier's accounts clerk explains that the quantity is short because a pallet got crushed in Rotterdam. An agent with its own mailbox sees that email but has no native view of the three-way match. Each address gives the agent a different view of the facts, and each view is partial.
The second is whom the agent answers to. A Dot answers to the person who set its goal. A module agent answers to whoever owns the module configuration, usually a finance systems team or an implementation partner. A mailbox agent answers to whoever administers the directory. In most companies those are three different people who don't attend the same meetings.
The third is where its mistakes pile up. Module agents fail inside the module, where existing exception queues catch them. Mailbox agents fail in threads, and threads have no queue. Microsoft's own Hooks documentation, as Cloud Wars reported it, warns that inputs should be validated because "Prompts, tool results, and error messages can contain content the agent didn't produce." That warning matters most for an agent whose whole job is reading mail from strangers.
The fourth is who meters it. Infor bundles usage. SAP charges AI units. Microsoft's Sales Development Agent "will start consuming Copilot credits on November 16, 2026." Google says its agent comes at no extra charge where Gemini Enterprise is available, but VentureBeat notes that Google hasn't said whether persistent coworker agents need separate licenses. Every address comes with a different meter, and once the agent has lived there for a quarter, the meter is very hard to move.
An AI automation strategy for operations teams starts with the exception map
The standard advice is to map your processes, find the repetitive steps, and automate them. That advice made sense for robotic process automation in 2018, because bots could only follow a path that was already drawn. It makes less sense now. Agents handle the drawn path well. The money in operations has always been in the undrawn part, in the exceptions.
Follow the exception
Say a supplier emails a PDF saying a shipment will land four days late. In most mid-sized companies, that one fact has to reach the planner, who reruns the schedule, and the warehouse, which reshuffles the wave. Customer service needs it to warn the three customers whose orders are affected, and accounts payable needs it because the late shipment may carry a penalty clause. None of those people works in the system where the fact arrived, which is someone's inbox.
Draw that path for your ten most expensive exceptions. Don't draw the happy path. Draw where the bad news enters, and every hop it takes before the ledger reflects it. When I've done this with operations teams, the same pattern shows up. The news almost never enters through the ERP. It comes in through an email, a phone call, a portal notification or a message in Teams. The ERP learns about it last, after a human has retyped it.
Look at the October announcements against that map. Infor's 40 agents and SAP's autonomous domains are strongest at the end of the path, where the fact has already become structured. Google's and Microsoft's mailbox agents are strongest at the start, where the fact is still a sentence in an email. OpenAI's Dots are strongest wherever one person's attention happens to be. No single vendor covers the whole path, and each one's marketing invites you to believe it does.
Home, hands and leash
So here is the position I'd defend in front of any board. Give each operational agent three separate placements, and don't let any vendor merge them for you.
The home is where the agent picks up its work. Put it where the exceptions enter. For most operations teams in late 2026 that means a shared mailbox or a channel with a real address, owned by the team rather than a person. Google's and Microsoft's mailbox agents make this possible without custom plumbing for the first time. That's the most important thing that happened in these ten days, and it was announced as a sales and event-planning feature.
The hands are where the agent is allowed to write. Keep them in the system of record, through the narrowest permissions the module offers. This is where Infor's and SAP's approach earns its price. A module agent that can post a journal entry only within reconciliation rules is safer than a general agent with a service account and good intentions. Let the module agents act. Don't let them be the place where work starts, because they never see the email.
The leash is the layer that decides which actions fire automatically, which ones wait for a human, and what gets logged. Own it yourself. Copilot Studio's Hooks show the shape: an event, an action, and a rule that fires every time instead of when the model feels like it. Even Microsoft's version can fail open, though, so the leash needs its own monitoring. Put it in a layer your team controls and can move. If the leash lives inside one vendor's agent builder, your governance moves with that vendor's roadmap.
Each vendor's announcement this month offered all three in one package. Google's agent has a mailbox, connects to Salesforce and ServiceNow, and comes with a gateway that enforces company rules on agent traffic. SAP's Joule wants to be the screen, the knowledge graph and the meter. That bundle is convenient in a pilot. In production it means your exception path, your write permissions and your controls all live with one company, whose pricing page you don't control.
The bill follows the address
Operations leaders tend to treat AI pricing as a procurement problem. It's an architecture problem. Look at what happened to the meters in these ten days.
Infor says usage is unlimited inside its suite. That's generous for agents that live in Infor modules, and it also pulls agents toward living in Infor modules. SAP's AI units reward routing questions through Joule. Microsoft's credits start running on November 16 for the Sales Development Agent, so every extra hop through Teams has a price. Google offers spending caps that pause agents when the budget is gone, which is a sensible control and also a reminder that someone has to decide what an agent's pause costs a warehouse at 2 a.m.
Suppose you let each vendor host its own agent along the exception path. One fact, the late shipment, might wake a mailbox agent on one meter, a planning agent on a second and a finance agent on a third, with your leash written in a fourth tool. You'd pay three times for one piece of bad news, and no single dashboard would show you the total. Picking the address yourself is how you keep the meter readable.
There's a quieter cost too. Futurum's survey, cited in the same note, found that 48.6% of decision makers planned to deploy agentic AI in customer experience within 18 months. Customer experience is downstream of operations. If the front office puts agents in its CRM and the back office puts agents in its ERP, the late-shipment email will meet two sets of agents with different addresses, different leashes and different meters, all trying to tell the same customer the same thing. Operations owns the facts. It should also own the address where those facts first land.
What I'd do this quarter
None of this needs a new platform. It needs a few decisions made deliberately before the November billing dates and the general-availability announcements make them for you.
Start with the exception map. Pick the ten exceptions that cost you the most in expedite fees, penalties, write-offs or overtime, and trace where each one enters the company. Write down the entry point as an address, an inbox, a portal or a phone number. That list is your agent housing plan.
Then create shared, team-owned identities for agents, not personal ones. If OpenAI's Dots are going to spread through your company, and Pro and Business Premium users can already get one, decide now that operational goals don't live in an individual's Dot. A process should outlast the employee who first automated it.
Keep write access narrow and module-specific. If your ERP vendor ships an agent for invoice matching, let that agent be the only thing that matches invoices. Feed it from the mailbox agent upstream. Don't hand the mailbox agent a service account with matching rights because the demo looked smooth.
Write the leash as rules that live outside any single agent builder. Use Hooks or their equivalents to enforce them, and monitor the hooks themselves, since Microsoft has told you they can fail open. Log every write to the system of record against the exception that triggered it, so you can trace a posted entry back to the email that started it.
Finally, put the four meters on one sheet. Infor's bundle, SAP's units, Microsoft's credits and Google's spending caps measure different things. Turn them into a cost per exception resolved, because that's the unit your operations P&L actually feels.
Architecture or inheritance
You can buy every product announced in those ten days and still end up with a worse operation than you have now. The tools aren't bad. Each one was built by a company that wants to be the place your work lives, and five such places can't share one exception without someone deciding the seams. If you don't decide them, they'll be decided by whichever product your teams try first, and you'll inherit an architecture nobody chose.
This is design work. Someone has to map where your bad news enters and decide which agent picks it up and which system it may write to. Someone has to write the rules that fire whether or not the model agrees, and turn four pricing schemes into one number. Your ERP vendor won't do it, because the answer sometimes points away from its modules. Your collaboration vendor won't do it either, because the answer sometimes keeps the agent out of its inbox. Agor AI Advisory does this work for operations teams. We start from your exceptions and your ledger, and we have no stake in which vendor's address wins.
The vendors made their choices between September 29 and October 8. Yours is still open, and it closes quietly, one pilot at a time.
Sources
- VentureBeat, Google Cloud unveils persistent Gemini agents, October 8, 2026
- Microsoft, Bringing CRM into the flow of work and agents into business process, October 8, 2026
- The Futurum Group, Microsoft Turns Dynamics 365 Into an Ambient CRM Layer, October 9, 2026
- SiliconANGLE, SAP expands Joule into an agentic work layer, October 6, 2026
- Infor, Built to execute: AI in the 2026.10 release, October 6, 2026
- Cloud Wars, Microsoft has a hook for that, October 6, 2026
- Let's Data Science, OpenAI Introduces Dots at DevDay 2026, September 29, 2026
