New: what governed autonomous procurement actually means
Explainer

Autonomous agents: how it works and what to require

In short

Proconomy agents execute authorised multi-step procurement work rather than producing drafts for someone else to action. Each agent has a defined job, a permission boundary and an escalation path. Within that authority they progress requests, sourcing, supplier and purchasing work; outside it they stop and route the decision to a person.

See Autonomous agents

Coordination, not judgement. That is where the week goes.

What currently consumes a buyer week, and what an agent takes off it.

Request handling

  • Interpret a free-text request into structured data
  • Ask the requester for what is missing
  • Select the buying route from policy
  • Detect duplicate requests across plants
  • Assemble context for the buyer
  • Update the requester on progress

Sourcing coordination

  • Build an event from a category template
  • Assemble the eligible supplier list
  • Issue invitations and reminders
  • Answer routine clarification questions
  • Normalise responses into a comparison
  • Model award scenarios for a person to decide

Supplier and quality

  • Chase outstanding onboarding documents
  • Request certificate renewal before expiry
  • Issue a corrective action with its stages
  • Chase overdue corrective-action evidence
  • Escalate an unanswered supplier request
  • Prepare a scorecard pack for a review

Purchasing and follow-through

  • Route, remind and escalate approvals
  • Write an approved outcome to the ERP
  • Monitor write-back and raise failures
  • Chase order acknowledgements
  • Match invoices inside tolerance
  • Escalate variance outside tolerance to a person

Autonomy your security team can sign. Because the boundary is enumerable.

Eight properties. A platform missing any of them will not pass review.

MechanismWhat it has to do
A defined jobEach agent has one purpose. There is no general-purpose agent with open authority, because a general-purpose agent cannot be reasoned about by a security reviewer.
An explicit permitted-action setWhat it may do, at what value, in which entity, with which data. Anything outside the set is not attempted and not possible.
A value ceilingAbove the threshold your policy defines, the agent prepares and a person decides.
A named escalation pathWhere it goes when the situation falls outside what it may handle, with the context attached.
Segregation of dutiesThe agent that prepares an award package does not hold authority to approve it. The principle applies to agents exactly as it applies to people.
Attributed actionsEvery action is recorded against the agent that took it and the permission that allowed it.
Human overrideA person can stop, reverse or override an agent action, and the override is itself recorded with its author.
Widening under evidenceAuthority is extended on the basis of accumulated action history reviewed with security and audit, rather than granted up front.

A description of what the practice requires, not a feature list.

Same permission model. Tighter ceilings by sector.

Where the boundary sits, by industry.

Aerospace and defence

Agents coordinate and prepare; every departure from the approved supplier list stops for named authority.

Medical devices

Anything touching qualification scope or a quality agreement obligation returns to a person.

Automotive

Agents run launch and corrective-action coordination; containment and root-cause acceptance never auto-pass.

Industrial equipment

Broader agent authority on MRO and repeat categories, tighter on project sourcing.

Five questions. Starting with the permitted-action set.

If it cannot be written out, it is not bounded.

  1. Ask to see the permitted-action set for one agent, written out. If it cannot be shown, it is not bounded.
  2. Ask an agent to do something outside its authority during the session and watch what happens.
  3. Confirm segregation of duties applies to agents, not only to users.
  4. Ask what the agents did overnight, unattended, and see the record.
  5. Ask how authority is widened over time and who signs that off.

Definitions. Asked and answered.

A copilot helps a person do the work: it drafts, summarises and suggests. A Proconomy agent performs the authorised work itself within a defined permission boundary, and escalates what it is not permitted to decide.

Its permission set. Each agent has defined permitted actions, a data scope, value limits and entity coverage. Anything outside that boundary is blocked and escalated with the reason recorded.

Yes. Customers commonly begin with one high-friction workflow — intake, sourcing coordination or supplier follow-up — and widen the permitted action set as confidence builds. Proconomy does not promise an implementation duration without evidence.

It stops, records what it observed and why it could not proceed, and routes the decision to the person your escalation path names. The exception carries the context needed to resolve it.

Yes, where their authority permits it. The override, the person and the justification are retained, which is what makes the model reviewable by audit.

No, and Proconomy does not describe them that way. People define policies, permissions, thresholds and approvals. Agents operate inside that authority. Consequential decisions always return to people.

Agentic AI describes software that carries out multi-step work towards a goal rather than responding to a single prompt. In procurement that means preparing events, chasing suppliers and approvers, normalising responses and updating systems — within an explicitly defined boundary of permitted actions.

A copilot assists a person who is doing the work; the person remains in every step. An agent performs the steps itself within a permitted boundary and returns to a person for decisions that carry consequence. A copilot makes an hour faster; an agent removes the hour.

It is safe to the extent that authority is bounded, consequential decisions return to named people, actions are attributed, and every action can be reconstructed afterwards. Autonomy without those four properties is not a governance question but a liability.

Anything carrying commercial, legal, quality or safety consequence: supplier awards, contractual acceptance, supplier status changes, quality containment and root-cause acceptance, and any departure from policy. These are judgement with accountability attached, which is precisely what should not be delegated.

See it on your own workflow. Not a prepared scenario.

Reference material explains the model. A demonstration on one of your own processes is what settles the internal argument.

Someone from client success replies, not a sales sequence. If we are not a fit we will say so on the first call.