Stop Buying Agents. Buy the Control Plane. (2026)
Gemini agent is a governance layer that controls context, permissions, spending, and logs across Salesforce, Slack, and 10+ other systems. Anthropic already cut model prices 75%. Keep workflows in n8n or Zapier so you can swap models without rebuilding. Buy the controls first.
Stop Buying Agents. Buy the Control Plane.
Google says Gemini can work across Salesforce, ServiceNow, Snowflake, Slack, Microsoft 365, and Google Workspace.
The control plane is the interesting part. It manages what agents know, which tools they can use, what they can spend, and what gets recorded.
Sales and marketing leaders should buy or build that layer.
Google Isn't Really Selling a Chatbot
Google Cloud announced Gemini agent at its October 8 Gemini at Work event.
Google CEO Thomas Kurian described the pitch as "objectives, not instructions." You assign an outcome. Gemini plans the work and selects tools.
The agent can work inside Gmail, Drive, Docs, Sheets, Slides, Chat, and Calendar. It can also connect with Salesforce, ServiceNow, Confluence, Teams, Slack, Snowflake, and Databricks.
Google also supports Model Context Protocol servers. Teams can use them to connect private tools through a common standard.
Connectors are common now.
Zapier lists thousands of app connections. n8n supports API calls, databases, webhooks, custom code, and AI model nodes.
Governance is harder.
Google gives agents separate identities and least-privilege access-policy-before-it-costs-you-930k). Each action can be tied to the agent that performed it.
Tasks run inside an Agent Sandbox. Network traffic passes through Google's Agent Gateway, an AI firewall.
Admins can restrict models, set project spending limits, and stop work when budgets run out. Policies can block agents from opening protected documents.
According to Constellation Research, Gemini agent launched in private beta. Google kept consumption pricing rather than adding a separate SKU.
Gemini Enterprise agent governance is the actual product.
The chat window is just the front door.
Task Agents Are the Wrong Thing to Buy
Most agent vendors sell a job title.
They sell an "AI SDR," "AI marketer," or "AI support rep." Underneath, you usually get prompts, API calls, and a dashboard.
That bundle becomes a problem when the model market changes.
Anthropic says Claude Haiku 5.5 costs about 75% less than Haiku 4.5. Anthropic also cut Sonnet 5.5 cache-read pricing by 50%.
OpenAI's Decisions API claims responses are 10 times faster than its Responses API. It returns probabilities and typed choices instead of paragraphs.
Your model choice could change next month.
Keep your permission rules stable.
There's a useful history lesson here. Amazon launched EC2 in 2006 and AWS Identity and Access Management in 2010.
Early cloud buyers focused on servers. Later buyers focused on identity, permissions, billing, and logs.
AI is following the same path.
The valuable layer controls every agent.
That layer should answer five questions:
1. What context can this agent read? 2. Which tools can it call? 3. Which records can it change? 4. How much can it spend? 5. Who can review its actions?
If your vendor can't answer those questions, don't give its agent Salesforce access.
A clever prompt won't protect your pipeline.
Keep the Workflow in n8n, Zapier, or Pipedream
Your governance layer and workflow orchestrator should be separate.
The governance layer controls identity, context, permissions, policies, costs, and records. The orchestrator controls steps, triggers, retries, branches, and system updates.
StoryPros uses n8n for this work. It gives us more control than Zapier over branching, APIs, data handling, and model selection.
Zapier is fine for simple workflows. Pipedream is strong when your team wants code-level control.
This is what AI automation using n8n looks like:
1. A new lead enters HubSpot. 2. n8n checks for duplicates. 3. A model classifies fit and buying intent. 4. The governance layer checks approved data and tools. 5. The agent drafts outreach. 6. A policy decides whether human approval is required. 7. n8n sends the approved message. 8. Every action and cost gets recorded.
The agent decides within limits. n8n runs the process.
That split matters.
If Claude gets cheaper, you can switch models. If OpenAI ships a faster classifier, you can route scoring there.
Your CRM steps stay intact.
Your approval rules stay intact.
Your logs stay intact.
Don't let one agent vendor own your prompts, workflow, memory, permissions, and reporting. That's lock-in with an AI name tag.
The orchestrator n8n Zapier choice matters less. Pick the tool your team can maintain.
The architecture matters more than the logo.
Your Governance Checklist Needs Teeth
Most agent governance checklists are security theater.
They ask whether a vendor "supports controls." That tells you nothing.
Ask the vendor to show each control working.
| Control | What to demand |
|---|---|
| Agent identity | A separate identity for every agent and sub-agent |
| Context scope | User, team, project, and record-level restrictions |
| Read access | A list of fields and systems the agent can view |
| Write access | Separate approval for creating, editing, and deleting |
| Tool permissions | Allowlisted actions for every connected tool |
| Human approval | Gates for sensitive or irreversible actions |
| Cost controls | Per-run, daily, project, and model-level limits |
| Audit logs | Timestamp, agent identity, tool call, input, and result |
| Model routing | Rules for choosing cheap, fast, or advanced models |
| Failure handling | Retries, fallbacks, alerts, and forced shutdown |
| Data location | Regional processing and storage choices |
| Testing | A sandbox using fake or masked records |
"Tool permissions and audit logs" shouldn't mean one checkbox.
A Salesforce agent might read lead status but never edit opportunity value. A marketing agent might draft campaigns but never publish them.
Deleting records should require approval.
Issuing refunds should require approval.
Changing prices should require approval.
Sending outbound messages needs more debate. StoryPros builds sales agents that book over 30 meetings weekly, but trust still comes first.
Cold sales depends on trust.
Bad automation can damage trust faster than a junior rep. It can also hit 10,000 contacts before lunch.
Use a simple rule.
The bigger the blast radius, the tighter the permission.
Buy the Controls. Build the Process.
Buy a governance layer when you have many agents, regulated data, or several business systems.
Google Cloud, Salesforce Agentforce, and Amazon Bedrock have identity, policy, logging, and spending controls. Salesforce says its Marshall agent provides an audit record for every action.
Build a lighter layer when your workflows are narrow.
A team running two n8n workflows may only need role-based credentials, approval steps, budget checks, and a central log.
Don't build a giant internal platform for three email workflows.
Use this decision test:
| Question | Buy | Build |
|---|---|---|
| More than five active agents? | Yes | Maybe |
| Sensitive customer or financial data? | Yes | Rarely |
| Several model vendors? | Yes | Possible |
| One narrow workflow? | No | Yes |
| Dedicated security administrator? | Yes | Optional |
| Custom approval logic? | Maybe | Yes |
| Need results within 30 days? | Maybe | Yes |
Measure value against both cost and risk.
Use this formula:
> Monthly agent value = labor saved + added gross profit − model costs − tool costs − maintenance
Then calculate risk:
> Expected monthly risk = failure probability × financial impact
Globe Telecom reported ₱1.2 billion in measurable AI benefits. That included ₱825 million in added revenue and ₱368 million in avoided costs.
Globe reported a 2.8-times return.
L'Oréal cut average case time from seven minutes to about 2.5 minutes. Its advisors still review drafted messages before sending them.
Controlled actions create measurable value.
Start With Three Policies
Your first governance policy doesn't need 80 pages.
It needs clear boundaries.
1. CRM write policy
> Agents may read approved lead and account fields. Creating activities is allowed. Changing opportunity value, stage, ownership, or close date requires approval.
2. Outbound communication policy
> Agents may research contacts and draft messages. Automatic sending is limited to approved campaigns, domains, templates, and daily volumes.
3. Cost policy
> Each workflow has per-run and daily spending limits. Expensive models require routing approval. Work stops when the project limit is reached.
Add one owner to every policy.
The system owner proposes write access. A security administrator approves it. Sales or marketing operations verifies the business rules.
Nobody should approve their own permissions.
Google's approach gets that part right. Agent identities, policy enforcement, sandboxes, and spending limits belong together.
Most teams are still shopping for smarter agents.
They should shop for better brakes.
FAQ
What is the Gemini Enterprise agent platform?
Google's Gemini agent is a work agent that plans tasks and connects with business systems. Its key controls include agent identities, permissions, sandboxes, audit trails, model routing, and project spending limits.
How do you govern AI agents?
Start with separate agent identities and least-privilege access. Add context restrictions, tool permissions, approval gates, cost caps, and complete action logs.
What is AI automation using n8n?
AI automation using n8n combines model calls with triggers, business rules, APIs, and approval steps. n8n runs the workflow while the model handles classification, reasoning, or content generation.
What actions should still require human approval?
Refunds, deletions, contract changes, price changes, and large outbound campaigns should require approval. Any action with a large financial or reputational impact needs a human gate.
Who decides whether an AI agent gets write access?
The business system owner should propose access, and a security administrator should approve it. Sales or marketing operations should confirm which fields and actions are allowed.
Related Reading
What controls does Google Gemini agent include for enterprise use?
Gemini agent gives each agent a separate identity and least-privilege access. Admins set project spending limits, restrict model choices, and block access to protected documents. Every action is tied to the agent that performed it, with full audit trails.
How much cheaper did Anthropic make Claude Haiku 3.5 compared to the previous version?
Anthropic cut Claude Haiku 3.5 pricing by roughly 75% compared to Haiku 4.5. Cache-read pricing for Sonnet 3.5 dropped 50%. Model costs can shift that fast, so your permission rules need to outlast any single vendor.
What real business results have companies reported from governed AI agents?
Globe Telecom reported 1.2 billion Philippine pesos in measurable AI benefits, including a 2.8x return. L'Oreal cut average case handling time from 7 minutes to 2.5 minutes. Both results came from agents that required human review before acting.