GTM pain points

GTM pain points

Your Reps Already Brought Their Own Agents

Your Reps Already Brought Their Own Agents

Your Reps Already Brought Their Own Agents

RC

Rob Catalano - Co-founder -

Rob Catalano - Co-founder -

-

-

5 min read

5 min read

Somewhere in your pipeline this morning, an AE pasted a call transcript into a tool nobody in RevOps has heard of, got back a summary and three next steps, and typed the good parts into Salesforce by hand. Nobody logged it. Nobody approved it. It worked.

That is a shadow agent, and it is the most common AI deployment in go-to-market today. Not the platform your CIO evaluated for two quarters. The thing your best rep wired up on a Tuesday because it saved them forty minutes.

Most GTM leaders find out the same way: an odd line in a proposal, a competitor detail in an email nobody sourced, a customer asking why the follow-up referenced a conversation that never happened.

The problem is bigger than a policy violation

The security case is already documented. IBM's Cost of a Data Breach report found one in five organizations suffered a breach tied to shadow AI, adding roughly $670K to the average breach cost, and that 97% of organizations with an AI-related breach lacked proper AI access controls.

But the security team owns that argument, and it is not the argument that changes behaviour on a sales floor. The GTM argument is quieter and more expensive.

A shadow agent is ungrounded. It does not know your qualification criteria, your competitive counter to the incumbent in that deal, the fact that this account churned in 2024, or which of the six people on the buying committee actually signs. It knows what is in the prompt box.

A shadow agent is also unobserved. When it drafts a strong email that moves a deal, nothing about that gets captured. When it hallucinates a product capability into a proposal, nothing catches it. Either way the organization learns nothing. Every rep is running their own private pilot and none of the results are pooled.

Multiply that by a team of thirty and you have thirty inconsistent versions of your company talking to the market, none of them improving.

Banning it fails, predictably

The standard reflex is a policy: approved tools only, everything else blocked.

It fails for the same reason shadow IT always beat the corporate app catalogue. The unsanctioned path is faster than the sanctioned one, and the person choosing between them is measured on quota, not on compliance.

The data backs up how wide that gap already is. Gravitee's State of AI Agent Security 2026, a survey of 900-plus executives and practitioners, found 81% of teams have agents past the planning stage but only 14% ship them with full security and IT sign-off, while 88% report confirmed or suspected agent-related incidents. Adoption is running roughly six times ahead of approval. A ban does not close that gap. It just moves the activity somewhere you cannot see it.

There is a second failure mode: uniform lockdown. Gartner has been explicit that treating agent governance as binary, either fully locked or fully trusted, is itself a root cause of failure, and predicts 40% of enterprises will demote or decommission agents over governance gaps discovered only after a production incident. Read a research summary drafted for an internal deck and read a write to a closed-won record as the same risk, and you will either block the useful work or wave through the dangerous work. Usually both.

The paved road beats the roadblock

The most useful number we have seen on this comes from IBM's Institute for Business Value, June 2026: organizations with embedded, automated controls deploy 16 times more agents than organizations governing manually. The same study found enterprises average 54 agent incidents a year requiring human correction, 37% of which caused data exposure.

Read those together and the conclusion is not subtle. Governance is not what slows agent adoption down. Manual governance is. When the controls are in the path rather than bolted on as a review step, teams ship more, not less.

That is what a paved road looks like in practice, and it has four parts:

  • Shared grounding. The sanctioned path answers with your account history, your competitive positioning, and your qualification criteria already loaded. A generic chat window cannot compete with that on quality, which removes the main reason to go around it.

  • One door to the stack. Connections to the CRM, the call recorder, and the document store wired once, centrally, rather than each rep granting a new tool access to their own inbox and drive.

  • Graduated permission. Read is open. A draft is open. A write to a live opportunity goes through approval. The control scales with the consequence instead of applying uniformly to everything.

  • A record of what happened. Every action traceable, so that when an agent helps move a deal, that outcome feeds back and the next answer is better.

Miss the fourth one and you have compliance without compounding. You will be able to prove what your agents did, which matters: 78% of executives told Grant Thornton they lack confidence they could pass an independent AI governance audit within 90 days. But proving it is the floor, not the goal.

Bring your own agent, run it on shared ground

The realistic end state is not one approved agent. Your reps will keep bringing tools, your vendors will keep shipping agents into products you already own, and your engineers will build one or two of their own. That is fine. Heterogeneity is not the problem. Isolation is.

What has to be common is the layer underneath: the grounding every agent reads from, the rules every action passes through, and the feedback loop that turns outcomes into better answers next quarter.

This is what we are building at wysdym, the operating layer for agentic GTM. Not another agent. The layer your agents and your team run on, so that whichever agent a rep brings, it inherits the same grounding, acts inside the limits you set, and gets sharper from every deal you close. More agents will not grow revenue. Compounding intelligence will. You can see how the pillars fit together at wysdym.ai/platform, and the research behind this piece sits in our agentic AI statistics roundup.

We are building this with a small group of design partners right now. If you already know roughly how many unsanctioned agents are touching your pipeline, and it bothers you, that is the conversation we want to have.

Enjoyed the read? There’s no book on agentic GTM.

Enjoyed the read? There’s no book on agentic GTM.

Enjoyed the read? There’s no book on agentic GTM.

so we’re writing it weekly

so we’re writing it weekly

“pearls of wysdym”, weekly, 5 min read, free