
Opinion
Nobody installed the software that now runs your office
"The programs on a company's approved list haven't changed in years," writes Shlomi Salem, co-founder of Neo. "What runs inside them changes every week, and it has started making decisions."
Every company has a list. It might live in a spreadsheet or in the head of an IT manager, but it exists: the software employees are allowed to use. Excel is on it. Chrome is on it. Getting something added to that list is a ritual anyone who has worked in an office will recognize. A form, a wait, a review, an approval.
For thirty years the list worked, because software arrived in a recognizable shape. You downloaded a program, it installed itself on your computer, and from then on it did roughly what the box said. Security was built around that shape. Check what is installed, watch what it does, remove what doesn't belong.
That shape is gone. Almost nothing gets installed anymore. It gets extended.
Excel now has an AI assistant inside it. Your browser hosts add-ons that can read every page you visit. The tools engineers use to write code run plugins downloaded from public marketplaces. These applications have quietly become platforms, and the software that actually does things now lives inside them. None of it appears on the list, because the list only has room for the name of the host. Excel is approved. What happens inside Excel is nobody's decision.
Add-ons have complicated this picture for years, and companies have mostly lived with it. What changed recently is that the software inside the software started to act. An AI agent does not wait for a click. It reads a goal, picks its tools, and works through the steps on its own, using whatever access it has been given. Switching one on is no longer like turning on spell-check. It is a decision to hand over authority, and it is being made thousands of times a day by whoever clicks "allow" first.
Here is what keeps security teams up at night. When one of these agents does something, whether opening a customer database or sending a file to an outside service, it does so as you. It works inside your login, with your permissions, through an application your company approved. Every safeguard the organization has ever built asks the same question: is this user allowed to do this? The answer is yes. The agent is wearing your badge. Nothing in the record shows that a piece of software made the decision, or whether you ever meant for it to.
I spent more than a decade at SentinelOne helping build the technology that watches how programs behave on company computers. The lesson of that era was hard-won and simple: you cannot control what a program does from a distance. You have to be on the machine, watching where the action happens.
But the tools built on that lesson were designed to watch programs, not what runs inside them. They see Excel start. They see Chrome open. They see almost nothing of what happens one layer up, where the agents now live. The tools are not broken. They are watching the wrong floor of the building.
Not long ago, my team at Neo found a browser add-on running in a company's sales department. It was an AI sales assistant. It read the pipeline, drafted the follow-ups, updated the customer records. By all accounts it was helpful. It was also never approved for business use, had wide access to customer data, and, buried in its terms, permission to train its AI on whatever passed through it. No one had decided any of this. All it took was an install button and a sales rep with a quota.
The obvious answer is to review more carefully. That instinct does not survive contact with how fast this software moves. Early on, we spent days studying the inner workings of one popular AI platform so we could check whether its settings were safe. Days later it pushed an update and everything we had mapped was gone. That is not an exception. It is the normal pace now. An approval based on what a tool could do last month describes software that no longer exists. Approvals now have a shelf life, and it is measured in days.
None of this is an argument against the technology. The people reaching for these tools have good reasons. The analyst wants the spreadsheet finished. The sales rep wants to hit the number. Ban the tools and employees will use them anyway, on personal accounts, where the company sees nothing at all. Prohibition is the one response guaranteed to make things worse.
The task is to make the new software governable. That means being ableto answer three questions about anything running inside a company's applications. Is it here? Is it set up sensibly, or is it acting without anyone checking and reaching more data than its job needs? And what is it allowed to do? An assistant might be permitted to read customer records but not send them outside the company. A coding tool might read the code but not change anything that is live. Those distinctions let a company keep a useful capability without accepting everything the software is capable of. And the limits have to be enforced at the moment they matter, before the data leaves, not in a report afterwards.
The old list asked one question: what is installed? It was a good question for a long time. The question that matters now is different. What is running inside the things we installed, what can it do, and on whose behalf is it doing it? Very few companies can answer that today. Their software changed. Their idea of approval hasn't caught up.
Shlomi Salem is co-founder and chief product officer at Neo.














