16 min read
The Week the Question Became Who the Agent Is
For most of this year the interesting question about agents in a marketing stack has been what they are allowed to do. How many tools does the server expose, how many of them write, is there an approval step. Six days in late August and early September moved the question somewhere more awkward: who the agent is while it does any of it.
Two vendors answered that in opposite directions, five days apart, and both answers are defensible. That is the problem.
TL;DR
- Optimizely gave each AI coworker its own identity, and Salesforce and Anthropic gave theirs the seller’s, five days apart. Virtual Teammates carry individually scoped permissions and an activity trail tied to the teammate. Claudeforce ships with explicitly no new permissions model to build and no re-auditing account by account.
- Salesforce is turning the Agentforce Platform on by default, automatically for new Winter ‘27 orgs and on a rolling basis for existing ones from September 2026. Every other agent item this week describes what happens once someone enables an agent.
- Treasure AI and X published the boundaries the rest of the market omits. A read-only connector with role inheritance and a named refusal list, and a roughly two-hour token with rotating refresh and one grant per application and user pair, from the vendor with ten live write tools.
- The FTC and 22 state attorneys general sued Amazon over its advertising auctions, alleging an undisclosed surcharge from 2019 that had advertisers paying their own bid roughly 80% of the time by 2024. Every measurement model fitted on that cost inherits whatever the mechanism actually did.
The agent got a name of its own
On 31 August, at Opticon, Optimizely launched Virtual Teammates. The framing is familiar enough: role-specific digital coworkers, hired from a directory rather than assembled from workflows, with a starting roster of Chief of Staff, SEO and AI Search Analyst, Marketing Analyst, Personalization Strategist and CRO Manager. They keep organisational context across conversations and projects, and they can be given recurring responsibilities triggered by schedules or events.
None of that is new. What is new sits in one paragraph near the end of the release: organisations remain in control through individually scoped permissions and built-in oversight, companies can set where human review is required, and each Virtual Teammate’s activity is tied to its own traceable identity.
Read that again with an audit hat on. The agent is not a delegation of a person’s session. It is a principal. Its grant was made to the teammate itself, at the moment it was hired. When it changes something, the change is attributable to the teammate rather than to the marketer who set it running three weeks earlier. The human review point is a configuration on the teammate.
I have been asking vendors for a session lifetime and a revocation path all year, and mostly getting silence. This is a different and better answer to a question I had not framed properly. Session lifetime matters because a borrowed credential outlives the intent it was borrowed for. Give the agent its own identity and the question changes shape: you are now managing a service account with a role, a problem enterprise IT has solved for decades.
It also creates work that nobody has costed yet. Five ready-made teammates in a directory means five new principals per tenant on day one, each connected to the systems it needs. Someone has to own the joiners, movers and leavers process for entities that never join, move or leave. Someone has to decide whether the Personalization Strategist’s grant survives the departure of the person who hired it. And the phrase “connect it to the systems needed to perform its work” is doing an enormous amount of quiet work in a stack where those systems are a CDP, an ESP, an ad platform and a warehouse.
Optimizely also published a useful number: in its study of more than 2,000 B2B marketing leaders, 81% personally switch between two or more disconnected AI tools each week, and 19% use four or more. That is the market it is selling into, and a fair description of why the identity question is about to get loud.
Or it borrowed yours, and nobody re-audited
Five days earlier, on 26 August, Salesforce and Anthropic announced Claudeforce. I missed it in the last edition and record it here as a late capture, on the vendor’s date; the aggregator had it a week out.
The product is Salesforce in Claude: a plugin with 37 prebuilt sales skills, built jointly, running on what Salesforce calls AIforce, its harness for exposing data and workflows to any agent through MCP servers, APIs and CLI tools. Actions route through Salesforce so that business rules are enforced when an action is taken. That last part is the right design.
The sentence that matters is the setup one. An admin connects Salesforce in Claude a single time, with authentication and permissions managed centrally, and every seller gets access from day one. No per-user setup, no new permissions model to build, no re-auditing account by account.
Every clause there is a genuine benefit, and every clause there is also a control that has been removed. The agent operates inside the existing permission model, which means it can do what the seller can do, which means the blast radius of a bad instruction is the blast radius of that seller’s role. The absence of a new permissions model is what makes rollout fast. It is also what means there is no place to express the idea that the agent should be allowed less than the human it works for.
Set the two releases side by side and you get the design choice of the autumn. Optimizely: new principal, new grant, new audit trail, more setup. Salesforce and Anthropic: existing principal, existing grant, existing audit trail, no setup. If you run both, and plenty of enterprises will, you will have two different answers to “who did this” inside the same quarter, and only one of them survives a question from an auditor who did not read the release notes.
And a third vendor decided the question for you
There is a ninth question I have been adding to the vendor list all year, the one nobody asks in a demo: who is allowed to change the setting that governs all of this. Salesforce answered it in a change-log entry added the week of 24 August that I would have walked past.
Agentforce Platform enabled by default. It applies automatically to new orgs created in Winter ‘27, and it is planned for existing orgs on a rolling basis starting in September 2026.
Every other item this week describes what happens after somebody decides to switch an agent on. This entry is the switching on, and the somebody is the vendor.
Nothing here is improper. Defaults change constantly, and this one is documented, dated and rolling out on a stated schedule. But an existing org is a live production tenant with a permission model somebody spent a quarter designing, and a rolling default takes effect there without a project, a change request or a go-live date that anyone on the client side chose. If your governance model assumes agent capability arrives when you enable it, that assumption expired this week.
The practical version is short. Find out which of your orgs are in the rolling window and when, what an administrator has to do to opt out, and whether opting out is a supported state or just an unset checkbox. Then decide, deliberately. The failure is finding out in November that the choice was made for you.
Salesforce also shipped simplified agent metadata types the same week, so agent definitions can move between orgs from preview sandboxes. Portable definitions and scoped identity pull against each other, and it is fair to ask a vendor which of the two wins when they meet.
Read-only became something worth writing down
This week a boundary started to look like a feature.
Treasure AI shipped an AI Voice Connector for AI Studio on 2 September, letting an agent read meeting recordings, summaries, action items and speaker-separated transcripts through the same connector model as Databricks, Snowflake and the CDP. The release note does not stop at what it can do. The connection is read-only and inherits your Treasure AI Voice role, a Regular User’s agent reads only that user’s own recordings, an Enterprise Admin’s reads the whole organisation, and no agent can delete a recording, edit its tags or start an export.
That is four separate governance facts in one sentence, published without being asked. Read scope, permission inheritance, the specific writes that are refused, and the fact that the refusal list is explicit at all.
X did the same thing at the other end of the risk scale. Its Ads MCP server, shipped 24 August and documented the following day, exposes 23 tools of which ten write to production ad accounts funded by real instruments. It also publishes what I have been asking for since June: campaigns created through the protocol arrive paused and activation is a separate explicit call, OAuth runs on the advertiser’s own token scoped to reads, writes and offline access, access tokens last roughly two hours with refresh tokens rotating on use, and only one grant is permitted per application and user pair so an agency cannot fan out parallel agents against one advertiser’s credentials.
Two hours. That is now the shortest published agent session lifetime on my board, against MoEngage’s thirty days with a seven day idle timeout and Optimove’s one day. The vendor with the most dangerous write scope has published the tightest credential window, which tells you the disclosure gap has never been a capability problem.
The documentation retracted a capability
A small item in the Salesforce Winter ‘27 change log, added the week of 31 August, is the most quietly instructive thing I read this week. Salesforce removed the release note claiming that the Setup agent can enable and disable the Dynamic Actions on Mobile setting, on the grounds that the capability is not available at this time.
A vendor documented an agent write capability, and then withdrew the documentation. The entry was corrected, which is a different thing from a feature being deprecated or delayed.
I read that as the first visible symptom of a real problem: agent capability surfaces are being described faster than they are being built, and the description is what your risk assessment is based on. If you wrote a control document in August that said the Setup agent could toggle mobile action settings, you documented a risk that did not exist. If you had written one that said it could not, you would have been contradicted by the vendor’s own notes.
In the same week Tealium fixed an issue where the connectors UI did not correctly enforce permissions for event and audience connectors. Seven days after shipping a Configuration MCP that lets an agent update the server-side profile configuration in natural language. The permission model in the surface the agent now writes to had a defect in it. The sequence is the lesson.
The auction that was not the auction
On 31 August the FTC and 22 state attorneys general sued Amazon over its advertising auctions. The allegation is that for over seven years Amazon told more than a million brands and sellers it ran a generalised second-price auction, while from 2019 adding an undisclosed surcharge described internally as a soft reserve price that effectively converted it to first price. The share of the time Sponsored Products advertisers paid their own bid is alleged to have risen from between 30 and 40 per cent in 2021 to roughly 80 per cent in 2024. Internal documents quoted in the complaint refer to an invented auction participant and a proxy second price that Amazon calculates.
Set the litigation aside, because it will take years and I am not a lawyer. The architectural consequence lands now.
If your bidding strategy on Amazon uses bid shading, it was tuned against a mechanism that behaves differently from the one you were told about. If your marketing mix model or your incrementality work uses Amazon Ads cost as an input, every coefficient touching that spend since 2019 was fitted on a price that the stated auction would not have produced. If your blended CPC benchmarks include Amazon, they are not comparable to platforms where the second-price description holds.
Nobody has to be wrong for this to matter. The point is that a measurement architecture inherits the truthfulness of the cost data it ingests, and that is not a property most teams have ever had to test.
The other FTC item of the window pairs with it. On 27 August the Commission finalised orders against Cox Media Group and two marketing firms, 930,000 dollars in total, over an “Active Listening” service that claimed to target ads from conversations captured by smart devices. It did not do that, and consumers had not opted in. The orders prohibit misrepresenting the geographic targeting capabilities of an advertising service. Two cases, four days apart, both about the same thing: the description of an advertising mechanism is itself a regulated object.
The hole in my own watchlist
I re-ran this week’s scan with one instruction changed: read the release notes of the platforms I actually work in first, and read them in full. Adobe Journey Optimizer, Adobe Campaign, Marketo, Bloomreach, Braze, Insider, Iterable, Marketing Cloud and Marketing Cloud Next. The nine I am certified across and select between for a living.
Two of them had never been scanned. Not once.
Adobe Campaign had no release-notes source on my list at all, so it had been quietly absent from every edition rather than reported as quiet. Insider was on the list as a newsroom and two SDK changelogs, which is not the same thing as a way into its documentation. Both platforms appeared zero times in last week’s record, including in the section that names every vendor scanned with nothing to report.
I would have preferred to report that neither had shipped. Insider had. On 28 August the Android SDK went to 17.0.0 and on 31 August iOS went to 16.0.0, both major increments, both adding App Frames: personalised content published inline in the app’s own native layout instead of over the top of it. Placements get defined once by engineering, campaigns run from the panel afterwards, ten per placement. And in Insider’s own words it does not depend on notification permissions.
Read that against the rest of the month. Quiet hours became a tenant default at three vendors, push opt-in keeps decaying, and one of the nine quietly shipped a mobile surface that sits outside the notification permission altogether. That is a channel-architecture decision, and I missed it because a list was wrong.
Braze taught me the same lesson more gently. It looked silent because its dated release pages returned nothing, when it ships every four weeks and the next one is due on 17 September. Silence and cadence are indistinguishable if you only check the URL.
The failure mode worth naming is not missing a release. It is that a monitoring list does not break. It degrades, and it never returns an error.
What I would put on a client agenda this week
Seven things, in the order I would raise them.
First, write down which agents in your stack have their own identity and which are running as a person. It is a two-column table and most organisations cannot fill it in today. Optimizely and Claudeforce are both going to be in enterprise stacks by December.
Second, adopt the published-boundary set as a procurement question rather than a hope. Treasure AI and X between them have now published read scope, permission inheritance, the explicit refusal list, the token lifetime, the rotation behaviour and the grant-uniqueness rule. Those six are answerable. Ask them of Klaviyo, whose 260-plus MCP tools are still governed by a single sentence three runs on, and of Braze, whose remote MCP server is in its fifth run with nothing published.
Third, treat vendor capability documentation as a dated claim. The Salesforce retraction is the proof. Version your control documents against the release note that justified them.
Fourth, if you buy Amazon Ads at any scale, ask your measurement team what happens to the model if the cost input has a systematic upward bias from 2019 onward. You do not need the case to conclude to run that sensitivity.
Fifth, the Gmail non-HTTPS link warnings start at the end of October and the Garante compliance term for email open-tracking pixels is 29 October. Eight weeks. Twilio SendGrid shipped automatic SSL provisioning for branded links on 27 August precisely for the first of those, and it applies to every branded tracking domain at every ESP.
Sixth, audit your own monitoring list before you audit anything else. Ask which platforms in your stack you would notice going quiet, and then check that you are actually reading each one’s release notes rather than its newsroom.
Seventh, and this is Matthew Niederberger’s argument rather than mine, every agent product in this window is sold on the cost of switching between tools. He points out that unused capability costs nothing, while a second contract for a capability you already own costs exactly what the invoice says, and no utilisation survey will find it. Before you hire five Virtual Teammates, it is worth knowing whether you already own three of them.
The record for the week is in MarTech Watch, Week 36.
Two vendors answered the identity question in opposite directions inside five days, a third began switching the agent on without being asked, and the only vendor that published a credential lifetime was the one with ten tools writing to live ad accounts.
Sources
Optimizely
- Optimizely Introduces Virtual Teammates, Giving Marketers Role-Specific AI Coworkers. 31 August 2026, the roster, the identity and permissions language, and the 81% multi-tool figure.
Salesforce and Anthropic
- Salesforce and Anthropic Announce Claudeforce. 26 August 2026, the 37 sales skills, AIforce, business-rule enforcement, and the single-admin-connection setup language.
- Salesforce Winter ‘27 Release Note Changes. Headless 360 entries for the week of 31 August, including the headless Claude skill and the removal of the Dynamic Actions on Mobile claim.
Adobe
- Adobe Campaign Web User Interface release notes. August ‘26 release, 18 August 2026, the Approval workflow activity and the open-tracking toggle.
- Adobe Campaign v8 release notes. Release 8.9.3, 11 August 2026, the Adobe Analytics 2.0 API upgrade.
- Adobe Marketo Engage current release notes. The Coworker rename, the
campaignRunIdformatting change and the REST API deprecation dates.
Braze
- What’s new in Braze. The release index, source for the four-week cadence and the 20 August current release.
Insider
- Insider One Android SDK changelog. Version 17.0.0, release date 28 August 2026.
- Insider One iOS SDK changelog. Version 16.0.0, release date 31 August 2026.
- App Frames. The inline native placement, the one-time integration model, the ten-campaigns-per-placement limit and the notification-permission independence.
- Insider One Launches Zero Copy Segmentation for Snowflake-Powered Customer Activation. Vendor publication date 2 June 2026, against an aggregator listing of 27 August.
Treasure AI
- Treasure AI September 2026 release note. 2 September 2026, the AI Voice Connector read-only boundary and role inheritance.
X
- X Ads MCP gives AI agents write access to live campaigns. Technical documentation of the 23 tools, the paused-on-create behaviour, the OAuth scopes, the two-hour token lifetime and the one-grant rule.
Tealium
- Tealium release notes, 2026. 2 September 2026, the connectors permission-enforcement fix and the event spec validation Warn status.
Regulatory
- FTC, States Sue Amazon Over Secret Ad Surcharge Scheme. 31 August 2026, the soft reserve price allegation and the first-price share figures.
- FTC Finalizes Orders with Cox Media Group and Two Other Firms. 27 August 2026, the 930,000 dollar total and the prohibition on misrepresenting geographic targeting capabilities.
Email and deliverability
- Twilio changelog. 27 August 2026, SendGrid automatic SSL provisioning for branded links ahead of the Gmail non-HTTPS warnings.
Klaviyo and Braze, for the open governance questions
- Klaviyo What’s New. The 11 August MCP tools note, unchanged.
- Braze company news. No remote MCP server published as of 2 September 2026.
Ideas, attributed as opinion, not as evidence
- Martech Therapy, “The Martech Stack you bought twice”. Matthew Niederberger, 31 August 2026.
The digest behind each weekly article is produced through a structured AI-assisted scan of official release notes and product update sources. I review the output, verify the relevant signals and write the architectural interpretation.
This article draws from the Martech Weekly Digest scans run on September 2 and 3, 2026, covering 28 August to 3 September across several CEP platforms and vendors. The dated record behind it is in MarTech Watch, Week 36.
If you find errors or gaps in coverage, I want to know. The process improves when the output is challenged.