Turning it on
The agentic tools are here. Your organisation has probably not properly switched them on. A roadmap for closing the gap, for the person whose job it is to close it.
Work in progress. This page is being shared privately for feedback and is not yet announced. Product details were checked on 28th July 2026; these products change weekly.
In a recent coaching session with a senior leader, nearly every question had the same answer. Can it review my team's work overnight and tell me what moved in the morning? In theory, yes: not turned on by your org. Can it read my inbox and save draft responses? In theory, yes: not turned on. Can it save its work into the project folder where the team works? Not turned on. They had read what the tools could do. Their firm's configuration let them do almost none of it.
We describe AI in three generations: Chat, Agent, Employee (the full framework is here). Generation One answers questions. Generation Two does work: it holds a task across many steps, reads and writes real files, uses tools, runs to a schedule, and reacts to events rather than waiting to be asked. Generation Three, coming into view, feels like a colleague: a persistent identity you can email, message on Teams, and hand work to.
Generation One didn't really have this problem. A chat window needs almost no configuration: you switch it on, people type, the battle is adoption, and that battle has largely been won. Generation Two is different, because it has so many more capabilities, it has so many more switches. An agent is only useful for what it can reach: your files, your inbox, your calendar, your systems. Every one of those is a permission, and the natural way for a careful organisation to admit something this complicated is to turn every switch off. Which is what many have done. But agentic AI with everything off is a brilliant colleague locked in an empty room: technically present, practically useless. So expectations run ahead, set by demonstrations from people using these tools untethered, while what people are allowed to touch at work lags a year behind what they have seen. The first battle was adoption. The new battle is configuration, and that gap is where enthusiasm goes to die.
This page is a roadmap for closing it. It is written for the person who runs AI inside a firm, for the security and IT teams who hold the switches, and for the executive who has to sponsor them both. We have helped several firms through this journey; the pattern below is what survived contact with all of them.
Generation Two no longer needs engineers
A year ago, agentic AI meant a developer plugging systems together. Today it ships as a product from every major vendor: Claude Cowork from Anthropic, ChatGPT Work from OpenAI (launched 9th July 2026), the agent features in Microsoft Copilot. Setting one to work on your files is no harder than attaching a document to a chat. The technical barrier has gone; only the permission barrier remains.
Three other things about these products are widely misunderstood, including by the firms that have bought them.
First, where the agent runs and where your work lives have to match, and today most users can see neither. An agent can run in two places. On your device, it can work directly in the folders where your files actually are, but the machine must be on with the app open for as long as it works: you can assign it a task from your phone at the school gate (Claude Cowork calls this Dispatch), yet the job still runs on your desk. In the vendor's cloud, the opposite trade: the agent keeps working with your laptop shut and is reachable from anywhere, but it can only touch work that lives somewhere the cloud can reach. A code repository, yes. Email, calendar and documents, only once those systems are connected. A folder that exists solely on your machine, never. Users are rarely shown this geography, so they discover it as mysterious failure: the overnight task that died when the lid closed, or the cloud agent that cannot see the one folder the project lives in. The overnight briefing every executive wants exists today, but only when two switches align: an agent allowed to run somewhere that is always on, and inputs that live where it can reach them.
Which means something firms have not yet noticed: where you choose to store your work is now an AI capability decision.
Second, the safety controls are now first-class product features, not bolt-ons. Both leading products let an administrator control each connected system down to the individual action, and both arrive cautious by default: new capabilities disabled until approved, write actions gated behind per-task confirmation, plans surfaced for approval before work begins. The vendors have, in effect, pre-built the governance your security team thinks it has to invent.
Third, this is where the compounding starts. Generation One saves minutes per question. Generation Two saves the whole loop: the Monday briefing that assembles itself, the inbox triaged before you sit down, the report drafted from the same sources every month. One good run becomes a process that runs again. This is the tier where AI starts making work better, quicker and happier at the level of the firm rather than the individual.
Why it is switched off
Three honest reasons, and none of them is stupidity.
Security teams are being asked to approve categories that did not exist a year ago. Policies written for the old world do their job: an experimental feature gets blocked while it is in beta. Then the feature reaches general availability, the vendor hardens it, and the block quietly outlives the reason for it. Nobody is against it; nobody has re-decided it.
The benefits are diffuse and the risks are vivid. The upside of agentic AI is a thousand small wins spread across every desk, none of which shows up as a line in the profit and loss. The downside is easy to picture in one sentence in a board pack. Diffuse good news loses to vivid bad news in any committee, unless someone makes the good news concrete.
Nobody owns the middle. The settings sit in a no-man's-land between IT, security and the business. The business assumes IT has decided; IT assumes the business has not asked; security is waiting for a request that never formally arrives. We have sat in training sessions where a firm discovered, live in the room, that web search had been off for everyone all year: switched off on the strength of one article, never revisited, never missed loudly enough for anyone to ask. When it was finally discussed, with the right person present, it was turned on before the session ended.
That last story is the whole diagnosis. The blockers are rarely decisions. They are defaults that nobody has had the conversation about.
The conversation, done properly
The fix is not bravado, and it is not going around your security team. It is firming instincts up into a list, because the blockers rarely survive being written down.
- Benefits first. Before any discussion of risk, agree what the organisation would gain, concretely: which teams, which work, roughly what it is worth. This points everyone in the same direction and makes the diffuse upside as vivid as the imagined downside.
- Then the concerns, as a written list, each examined on its own. Some are real and deserve real work. The best example: an agent can read everything its user technically can, so years of stale sharing links and over-broad drive permissions suddenly matter. That is a genuine project, with a genuine payoff beyond AI. Most of the rest turn out to be inherited: a beta policy outliving the beta, an article about an attack the vendor has since addressed, a worry about a feature that is not actually the feature being requested.
- Then a roadmap with owners and dates. Name the switch, the quarter and the person who decides. A firm that knows where it is on the road stops relitigating the whole question every time someone asks for one setting.
- Then borrow shamelessly. Every firm in your industry is having this identical conversation in private. Where another firm has solved a concern, take the solution. There are no prizes for rediscovering the wheel with your own lawyers.
The roadmap: read, then draft, then schedule, then act
Trust is staged. Each stage keeps a human in exactly the right place, proves safe operation, and earns the next. And this is not our invention: the staging is now built into the products themselves. ChatGPT Work's admin controls define exactly three levels for every connected system (read-only, draft, write), and Claude Cowork ships with write actions gated behind per-task approval. The vendors have drawn the same map. The work is walking it deliberately.
- Stage nought: use what you already allow
Most firms have general-availability features switched off or unrequested: web search, file handling, the spreadsheet and presentation integrations. Turning these on creates no new category of risk. It is free value, and it clears the undergrowth so the real conversation is about the real question.
- Stage one: read
Connect email, calendar and documents for search and synthesis, respecting each person's existing permissions. The agent can see but cannot touch, and it sees live files where the work actually lives rather than stale copies uploaded by hand. This is the natural pilot: almost all of the risk conversation is about writing, and almost half of the value (finding, summarising, preparing, briefing) needs only reading.
- Stage two: draft
Allow the agent to produce work that ends in a human's hands: an email that lands in drafts rather than being sent, a document that arrives in review, code on a branch. The draft-not-send line is the best bargain in enterprise AI. It converts most of the write risk back into read risk, keeps a person accountable for everything that leaves the building, and unlocks the majority of the remaining value. The vendors agree: "draft" is now a named permission tier, sitting between read and write, in the products your firm already pays for.
- Stage three: schedule and trigger
The same permitted work, now running without being asked. This is where the geography from earlier becomes practical: the briefing can only be waiting at seven in the morning if the agent runs somewhere always on and its inputs (the inbox, the calendar, the documents) are connected to that somewhere. Get the two aligned and nothing new is permitted, yet everything changes: the value starts compounding, because the work happens whether or not anyone remembered to ask.
- Stage four: act
Real write access, for defined tasks: sending, filing, updating systems. This is where governance earns its keep: a named identity for each agent, permissions scoped to the task, an audit trail, and a human owner accountable for each one, exactly as they would be for a member of their team. Never everything at once. Task by task, each one boringly well understood before the next.
Most firms today are somewhere between stages nought and one, with expectations set at stage four. Naming the stage you are on, and the date you intend to reach the next one, dissolves most of the frustration on both sides.
The settings that matter
The short list we check first inside any organisation's setup, whichever vendor it runs.
- Frontier models on. Many firms pay for the good models and default users to the cheap ones. The difference is the difference.
- Web search on, with sensible controls. An AI that cannot read the world answers from memory alone.
- File tools on: upload, creation, and the spreadsheet and presentation features now in general availability.
- Connectors enabled at read scope: email, calendar, documents, respecting existing permissions. Scope deliberately: include the drives you mean, not everything you have.
- Drafts enabled, sending withheld. The stage-two bargain, available as a named setting in the products themselves.
- Cloud or always-on execution enabled, so scheduled work does not depend on someone's laptop lid. Often off by default on enterprise plans.
- The work stored where agents can reach it. An agent can only work on what it can see, so the choice of document store, and what is connected, now sets the ceiling on what AI can do for you. Storage used to be an IT preference; it is now a capability decision.
- Scheduled tasks and triggers on, for work already permitted live.
- An owner and a review cadence for the switches themselves. Vendors ship new capabilities disabled by default, which is the right instinct, but it means yesterday's configuration silently falls behind. Someone must re-decide it monthly.
- Skills and custom assistants curated, owned and open. Someone must own the central library, the duplicates and the quality bar. That is a real job; name the person.
- Usage data flowing to the enablement team. You cannot find your power users, seat them deliberately, or aim your training without it.
- Spend limits set deliberately: per-person defaults, group caps, a route to ask for more. These products are metered, and if nobody sets the limits, cost anxiety becomes the policy.
What this is not
This is not an argument for skipping governance. It is an argument for sequencing it. A firm that opens everything at once learns nothing and frightens itself; a firm that opens nothing learns nothing and falls behind. The staged road does neither: benefit matched to risk, a human in the right place at every stage, and each stage earning the next.
Generation Three is coming: AI with a persistent identity, on the Teams call, answering email, a post on the org chart rather than a person. Every uncomfortable question it raises is a harder version of a question Generation Two asks today.
Which is the real reason to start now. The firms that do well in the next phase will be the ones that learned, on the easy version of the problem, how to have the conversation: benefits first, concerns in writing, a roadmap with owners, trust extended in stages and verified at each one. Turn Generation Two on properly and you have built the machinery for everything that comes after it.
If this is the conversation your firm is stuck in, it is one we help with: the benefits case, the concern list, the roadmap, and the room where they get agreed.
David Boyle is a co-founder of Steadman, the AI strategy and transformation practice, and Director of Audience Strategies. He has run AI sessions and configuration conversations with leadership teams since February 2023, and writes David's Saturday AI Thoughts, a weekly email on working with AI.
Client examples on this page are anonymised. Product facts (Claude Cowork, including Dispatch and cloud sessions; ChatGPT Work and its connector action controls; Microsoft Copilot agent features) were checked against vendor documentation on 28th July 2026. These products change weekly; expect details to have moved.