GovernanceSeptember 28, 2026·George Schildge·5 min read

Passing the security review: what RevOps should bring to IT before any agent touches the CRM

Eight security questions grouped into four areas: where data is processed, what each agent may do, what is recorded, and which attestations apply.

Security reviews of AI agents focus on four areas: where data is processed, what each agent is permitted to do, what is recorded, and which compliance attestations actually apply. RevOps can speed approval by arriving with eight answers prepared, so the review does not become a months-long discovery process that ends with the deployment stalled.

Why the security review is where revenue AI goes to wait

RevOps usually finds the tool, builds the business case, and wins the CRO’s support. Then the deployment meets the security review, and it stalls. The questions are reasonable: where does our customer data go, what can this system write, and how would we know what it did? But the vendor’s answers often arrive piecemeal, weeks apart.

The research firms treat this as a core risk, not a paperwork step. Gartner lists inadequate risk controls among the three causes behind its prediction that more than 40% of agentic AI projects will be canceled by the end of 2027 (Gartner, June 25, 2025). It also names specific agent threats, including manipulated inputs, poisoned data, and hijacked credentials (Gartner, June 11, 2025). Forrester predicts that ungoverned generative AI will cost B2B companies more than $10 billion in enterprise value (Forrester, October 28, 2025).

RevOps can’t run the security review. It can make sure the review starts with answers, not questions.

The eight answers to bring

1. Where is our data processed? In which environment, and who operates it? This single answer often decides the length of the review.

2. What data leaves our systems? Which data, to where, and under what written terms for retention, deletion, and model training?

3. What identity does each agent use? Shared service accounts are a red flag. Each agent should have its own identity.

4. What is each agent permitted to do, and what is it unable to do? Least privilege should be enforced by permissions, not by instructions in a prompt.

5. How are runtime inputs and outputs handled? What protects against manipulated inputs while the system runs? The three incidents in Poisoned pipelines show what this looks like in a revenue stack.

6. What is recorded for every action, and can it be altered? Actor, rationale, before-and-after state, and evidence of tampering.

7. Who can stop it? Who can intervene in or revoke an agent’s authority, and how fast?

8. Which compliance attestations are the vendor’s own, and which are inherited from the cloud platform? Precision here builds trust. Overstatement ends reviews.

George Schildge’s view

How PrescientIQ™ answers the eight questions

Question 7 depends on the two governance modes, so they are defined first:

Human-in-the-loop (HITL). The action is drafted and held. It does not execute until a named person on your team approves it.

Human-on-the-loop (HOTL). The action executes under a standing policy your team sets. A named person supervises and keeps intervention, override, and revocation authority.

Your team chooses the mode for each action class, based on its risk tolerance, and can change it at any time.

Every action, in either mode, is recorded to the audit ledger with its rationale, before-and-after state, and the approver or policy behind it.

Every action class starts in human-in-the-loop until your team changes it.

The eight security questions and how PrescientIQ answers each.
Security questionPrescientIQ answer
Where is data processed?PrescientIQ is hosted and operated by MatrixLabX on Google Cloud. It is a multi-tenant service.
What data leaves our systems?The CRM data that agents work on is processed in the environment MatrixLabX operates. Ask us for retention, deletion, and model-training terms in writing. They belong in an agreement your counsel reads, not on a web page.
Agent identityEach agent runs under its own least-privilege identity, not a shared service account or a borrowed human credential.
PermissionsEnforced by each agent’s identity, not by prompt instructions. External systems are reached only through typed, scoped integrations.
Runtime inputsEvery inbound surface (web pages, email replies, CRM fields other people write into) is treated as untrusted input and defended accordingly.
What is recordedEvery action, in either mode, is recorded to the audit ledger with its rationale, before-and-after state, and the approver or policy behind it.
Who can stop itYour team chooses the mode for each action class, based on its risk tolerance, and can change it at any time. In either mode a named person on your team holds the authority.
Compliance attestationsPrescientIQ is hosted and operated by MatrixLabX on Google Cloud. SOC 2, ISO 27001, and PCI DSS attestations are held by Google Cloud, which operates the underlying infrastructure. They are not MatrixLabX certifications. MatrixLabX application-layer SOC 2 is in progress.

That last row is the whole statement. We do not hold the attestations that belong to Google Cloud, and we do not describe work in progress as finished. The AI trust and governance page lists what we do not claim.

Action items for RevOps this quarter

  1. Send the eight questions to every AI vendor before the business case goes to the CRO, not after.
  2. Book a 30-minute pre-review with your security lead to confirm these are the right questions for your organization.
  3. Build a one-page security summary for each shortlisted vendor, and attach it to the business case.
  4. Flag any vendor that describes inherited cloud attestations as its own. It’s a signal about how the rest of the review will go.

For the reviewer’s side of the table, see what an AI agent security review actually checks.

Check the math before you spend anything

The free AAR Benchmark builds a P&L projection on your own pipeline data in a read-only working session. Every figure in it is labeled as modeled.

Get your free AAR Benchmark →

Frequently asked questions

Why do AI agents stall in security reviews?
Reviews stall when vendors can’t clearly answer where data is processed, what each agent can do, and what is recorded, or when the answers arrive weeks apart. Gartner lists inadequate risk controls as one of three causes behind its prediction that over 40% of agentic AI projects will be canceled.
What will security ask about AI revenue agents?
Expect questions about where data is processed, what data leaves your systems, what identity and permissions each agent holds, how runtime inputs are handled, what is recorded for each action, who can stop the system, and which compliance attestations belong to the vendor.
What is least-privilege access for AI agents?
Least privilege means each agent holds only the permissions its job requires, enforced by its identity and not by prompt instructions. A research agent, for example, should be unable to send email. This limits the damage from errors or manipulation and makes each agent’s boundaries inspectable.
What is the difference between inherited and vendor compliance?
Inherited compliance comes from the cloud platform a product runs on, such as a provider’s attested infrastructure. Vendor compliance covers the vendor’s own application layer. Both matter, and a trustworthy vendor states clearly which attestations belong to whom and which are still in progress.
How can RevOps speed up an AI security review?
Send the key security questions to vendors before the business case reaches leadership, meet with your security lead early to confirm the questions, and attach a one-page security summary per vendor to the business case. Reviews move faster when they begin with answers.
Where does PrescientIQ run, and whose certifications apply?
PrescientIQ is hosted and operated by MatrixLabX on Google Cloud. SOC 2, ISO 27001, and PCI DSS attestations are held by Google Cloud, which operates the underlying infrastructure. They are not MatrixLabX certifications. MatrixLabX application-layer SOC 2 is in progress.

Sources

  1. Gartner, “Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027,” June 25, 2025. Link
  2. Gartner, “Gartner Predicts that Guardian Agents will Capture 10-15% of the Agentic AI Market by 2030,” June 11, 2025. Link
  3. Forrester, “2026 B2B Marketing, Sales, And Product Predictions,” October 28, 2025. Link

Research findings are paraphrased and carry their original publication dates. Predictions are the research firms’, not ours. Recommendations and checklists are the author’s and are offered as a starting point, not as benchmarks.

Where PrescientIQ runs

PrescientIQ is hosted and operated by MatrixLabX on Google Cloud. SOC 2, ISO 27001, and PCI DSS attestations are held by Google Cloud, which operates the underlying infrastructure. They are not MatrixLabX certifications. MatrixLabX application-layer SOC 2 is in progress.