The sales number and the control layer are different things
Workday's fiscal 2027 second-quarter release, published on August 27, 2026, says AI drove more than 25 percent of new annual contract value and that more than 5,500 customers now use at least one of Workday's organic agents, both figures from Aneel Bhusri's quote. The same release says the Financial Audit Agent is now generally available and introduces Agent Passport, which Workday says tests and verifies agents before they reach production. Agents are being sold and shipped.
None of that changes what happens when a compensation change above a manager's limit tries to complete in your tenant. A condition rule fires, the business process routes to a second approver, and the change waits. That rule has no model in it. We'd argue it is the most important part of any Workday agent strategy, because it decides what an agent's output is allowed to become.
Business processes are where the rules already live
Workday tenants are unusual among the platforms we cover in that the deterministic layer is already built. Business process definitions, condition rules, validations, and security groups govern every hire, every journal, and every pay input today. An agent that proposes a change does not get a separate door. It initiates or updates a business process, and the process treats the proposal the same way it treats one typed by a person.
That is the design decision to protect. When an account team demos an agent that drafts a job requisition, the question for the platform lead is which business process the output enters and which steps of that process the agent can complete on its own. If the answer is that the agent runs under a security group with approval rights, someone has quietly moved a control out of the tenant and into a prompt. Our sibling piece on the product list under the Q2 revenue line covers what shipped. This piece is about what should stay put.
An audit agent needs a stated rule to audit against
The Financial Audit Agent is the item in the release we'd use to make the case. The release says little about how it works. Our read is that its usefulness depends on the controls already configured in Financial Management. A flag that says a journal looks unusual sends a controller to go and look. A flag that says a journal over the posting threshold was created and approved by the same person, against a rule that forbids it, is evidence the controller can act on and an auditor can accept.
The rule generates the finding. The agent can rank the findings, summarise them, and draft the follow-up, and that is real work during a close. But the rule has to exist in the tenant, written down, with an owner, before the agent has anything to check against. We'd inventory the segregation of duties rules and approval thresholds before the audit agent toggle goes on, rather than after the first flag lands in a queue nobody owns.
Agent Passport verifies the agent, your rules govern the tenant
Agent Passport reads as Workday's answer to whether an agent behaves as described. The release says it tests and verifies agents before they reach production and then monitors them continuously. The release doesn't say whether customers can see the results, or whether Passport covers agents built with the Developer Agent. We'd ask both.
Even if it covers everything, Passport answers a different question from the one your internal audit team asks. Passport can say the agent behaves consistently. It cannot say that a consistent agent is allowed to complete a retroactive pay change in your tenant, because only your business process definition decides that. The two controls stack. A review that accepts Passport in place of tenant rules has confused a vendor test with a customer control.
The mistake is putting the policy in the prompt
The failure we expect to see first is a team that describes a policy to an agent instead of configuring it. The agent is told that expense claims over a certain amount need a director's approval, and for a while it routes them correctly. Then someone edits the instruction, or the model changes under a release, and a claim goes through without the second signature. Nobody notices because the agent reported success. Our piece on designing the human review step describes the same failure on another platform.
An auditor who asks to see the control cannot be shown a paragraph of instructions. They can be shown a condition rule with an effective date and a change history. That difference is why the deterministic layer stays in the strategy, and why our governance coverage keeps returning to evidence that survives an audit.
Run the test that proves the rule still fires
For each agent you enable, write down the business processes it can initiate, the security group it runs under, and the condition rules that apply to the objects it writes. Then run one sandbox test. Have the agent propose a value the rule forbids, and confirm the process stops it and records who was asked to approve. If the change completes, the agent holds a permission the rule was meant to withhold.
The pause control matters as much as the rule, and our note on why agents need a pause button someone can reach applies here unchanged. Before the account review, read our sibling piece on what the 5,500 count leaves out and the Workday release itself. The 25 percent of new ACV tells you what customers bought. The condition rule that fired in your sandbox tells you what the agent can do, and that is the result to bring to the meeting.



