Nolan Garrett, CEO of TorchLight (formerly Intrinium): A premier security-first managed services and risk management partner since 2007.
The moment an AI agent becomes useful, it stops being a technology experiment and becomes a management problem. Small businesses do not need more excitement in their systems; they need work to get done without creating a mess or unexpected result.
An agent can find a policy, draft a client email, update a ticket, prepare a board summary, check a vendor portal or remind a manager about a stale follow-up. If nobody can answer who allowed it, what data it touched and how to undo it, the business has created a new unmanaged worker.
Small Business Relevancy
This is already happening at small-business scale. The U.S. Chamber of Commerce’s 2025 “Empowering Small Business” report found that 58% of small businesses say they use generative AI, up from 40% in 2024 and more than double the adoption rate in 2023. The Small Business Administration’s 2024 FAQ says small businesses make up 99.9% of U.S. businesses and employ about 59 million people. This is no longer an enterprise conversation.
The mistake is treating agentic AI like a smarter chatbot. A chatbot answers but an agent takes steps. It can move across systems, call tools, schedule work, draft messages, route requests and trigger workflows. A bad answer in a chat window is one problem. A bad action inside accounting, HR, security, client email or the help desk is a different class of problem which requires different tools to address.
Ideal Agents
We have been building and operating agents internally before recommending them to clients. That experience has made me less interested in the demo and more interested in the operating model behind it.
The ideal internal assistant helps with cross-system research, drafting, planning, recurring checks, reporting and coordinating. It can work across different tools, but risky writes are gated. Some actions require explicit approval. Some are blocked entirely.
Businesses will also benefit from service-operations agents for repetitive professional services automation, reporting, notification and follow-up work. Tasks that used to live in someone’s memory becomes visible, reviewable and supportable.
For practical application, controls must be built in around the agents: tenant boundaries, role access, transcripts, audit logs, connector visibility and a way to disable or roll back changes where the underlying systems allow it. These should be complemented by repeatable templates for an agent’s role, approved data, tools, policies, tests and approval steps.
Timelines
The first agent in a company is usually a demo, but by the time there are two or three, the business needs an operating model. Without templates, owners, approvals and logs, every new agent becomes a custom exception, increasingly difficult to manage.
Security starts with identity and the first question is not, “What can the agent do?” The first question is, “Who is the agent, and who answers for it?”
NIST’s zero trust guidance says there should be no implicit trust based only on physical location, network location or asset ownership, and that authentication and authorization happen before access is granted. Microsoft is moving the same direction for agents using Entra Agent ID, talking about identity-based security for human and nonhuman identities, and says agent access should be intentional, auditable and time-bound. Its Agent 365 product aims to be a control plane for IT and security leaders to observe, secure and govern agents.
You do not have to be a Microsoft-only business for that principle to matter. If an agent can touch business data, it needs a real identity, a named human owner and a narrow job. That may sound heavy for a 40-person company but it is the same approach disciplined businesses already use with employees, contractors and service accounts.
Maximizing Your Agent
Give the agent a job description. Limit access to the systems and data needed for that job. Make access expire when the project ends. Keep a record of what it did. Require approval before it sends, pays, deletes, grants access, changes a record or closes a ticket. Know who can turn it off.
The identity issue is not academic. Verizon’s 2025 Data Breach Investigations Report release says credential abuse accounted for 22% of breaches as a leading initial access vector. An orphaned agent identity is just a new version of an orphaned service account.
NIST’s AI Risk Management Framework gives owners a useful plain-English test: govern, map, measure and manage. For a small business, I would translate that into four questions:
1. Who owns this agent?
2. What job does it do, and what data does it touch?
3. How do we know whether it is helping or creating noise?
4. What happens when it is wrong?
This is not a 90-page AI governance policy; it’s just thinking through the actionable steps that can be taken to mitigate risk.
Two Paths
This distills down to two paths for most small business owners:
First, if your company already lives in Microsoft 365 and has the licensing, data hygiene and administrative maturity, start there. Use the controls your platform provides, and put real governance around them.
Second, if your environment is smaller, messier or more specialized, start narrower. Pick one assistant with one job. Connect it to approved data. Keep it read-only first. Add drafts and routing. Add human approval gates. Measure whether it saves time or reduces dropped work.
The common objection is that approval gates slow AI down. They can, if you wrap them around everything. The better approach is to gate the verbs that can hurt the business: send, approve, delete, pay, grant, disable, close, hire, fire. Think about the security ramifications and the risks of the access given to the agent.
Agentic AI can help small businesses. I am convinced of that because we use it ourselves. The goal is not to make service appear autonomous, but to make useful work more accountable, faster and more focused on the human connection.
Start with read-only. Prove value. Add action slowly.
For most small businesses, that is the path that survives contact with real operations and will produce the most value long term.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?







