Card on AI productivity gates: permissions, evidence and human checks before action
Image: Work Stack Lab

Outlook

Part of Reading productivity software signals with a label on each, from products to economic data

Where AI fits in productivity software, and the gate to pass before it acts

Map practical AI applications in productivity software, then set permissions, evidence and human checks before enabling actions in an English organisation.

An AI feature becomes operationally important when it can change the work system, not merely suggest some words. For an organisation in England, the safest way to assess business productivity software AI applications is to examine the work system it changes. No product was tested for this review, and all capability claims come from provider pages.

This desk review was completed on 5 September 2026. Provider pages do not prove accuracy, suitability or a business benefit.

What to take away

  • An AI feature matters operationally when it changes the work system, not just when it suggests words.
  • Assess AI by the action, information and consequence, and check whether a person can inspect and reverse it.
  • Provider pages describe what suppliers claim, but they do not prove accuracy, suitability or business benefit.
  • Customer-facing AI carries consumer-law responsibility even when another company supplies the agent.
  • If any enablement question is unknown, narrow the application or keep it in a test environment.

Classify and route incoming work

A service desk can use AI to read an incoming request, apply a category and propose an owner. Asana's current AI Studio page describes workflows for intake, classification, routing, checking and reporting. That is a first-party capability statement. A typical test set for routing has 50 to 100 historical requests, including ambiguous and misdirected items.

Steps for AI classification and routing of service desk requests (Where AI fits in productivity software, and the gate to pass before it acts)
How AI can classify and route incoming work, and the test set to validate it. Image: Work Stack Lab

Before use, build a test set containing ordinary requests, ambiguous wording, sensitive information and deliberately misdirected items. Compare proposed routing with an agreed answer and record false assignments. A human should handle categories where delay or disclosure would cause material harm.

Create and maintain a project plan

Microsoft announced in June 2026 that Planner Agent was generally available to Microsoft 365 Copilot customers. The provider says it can create and update tasks through natural-language instructions. The announcement gives examples such as adding a task to a plan and setting a due date. Availability and behaviour require confirmation for the buyer's subscription and tenant.

Sandbox plan before live deployment

  1. Use a sandbox plan first
  2. Limit who can invoke the agent
  3. Inspect every bulk change
  4. Test history for unwanted updates
  5. Confirm availability for subscription and tenant

Use a sandbox plan first. Limit who can invoke the agent, inspect every bulk change and test whether history makes an unwanted update understandable. A convenient plan is still a poor control if ownership or deadlines can change without notice.

Work across connected knowledge and task systems

Atlassian documents Rovo agents that can interact with Jira and Confluence content according to configuration and access. Atlassian's documentation lists OAuth scopes such as read:jira-work and read:confluence-content.all that a Rovo agent may request. That may reduce copying between a knowledge base and a work queue. It can also extend the effect of an excessive permission.

Map the connector, service account and content boundary before the first trial. Ask what the agent can read, create and edit, how activity is logged, and what happens when a person's role changes. Do not give broad access merely to avoid designing a narrower process.

Support customer enquiries or recommendations

Customer-facing use carries a different consequence from an internal summary. The Competition and Markets Authority's AI agent guidance says businesses remain responsible for consumer-law compliance even when the agent is supplied by another company. It highlights disclosure where needed, testing, monitoring, human oversight and responding to problems. The guidance sits alongside the Consumer Protection from Unfair Trading Regulations 2008.

Treat refunds, personalised recommendations and contractual information as separate use cases. Define when a person must intervene and preserve the evidence a reviewer would need. Obtain qualified UK legal advice before deployment.

Summarise and report with traceable inputs

The ONS found that improving existing operations was the most commonly reported purpose among UK businesses using AI in its June 2026 evidence. The ONS analysis draws on the Business Insights and Conditions Survey (BICS). The published analysis does not establish that any named application improved a result.

For summaries, retain links to the underlying records and sample omissions as well as obvious errors. For reports, separate generated narrative from measured fields. Do not let a fluent explanation replace the source data or the metric definition.

A proportionate enablement gate

The National Cyber Security Centre's secure AI development guidance covers supply chains, documentation, logging, monitoring and secure operation. A customer can adapt those principles into six questions: Is the purpose specific? Are permissions minimal? Are inputs permitted? Can a person approve or stop the action? Is there a reliable log? Can the organisation recover?

If any answer is unknown, narrow the application or keep it in a test environment.

For instance, if the question 'Can a person approve or stop the action?' is unknown, narrow the scope to summary-only or keep the agent in a sandbox.

The aim is not to prohibit useful automation. It is to ensure that a person can inspect and reverse an action that has an owner, an observable result and a route back when the system behaves differently from the plan.

Before you act

  • Start with the action, information and consequence.
  • Build a test set with ordinary, ambiguous and sensitive items.
  • Use a sandbox plan before any live deployment.
  • Map the connector, service account and content boundary first.
  • Retain links to underlying records and sample omissions.
  • Confirm availability for your own subscription and tenant.

Common questions

How should an organisation judge whether an AI feature is worth using?

Judge it by the work system it changes. The gate section lists the checks, including permissions, logging and recovery.

What must be checked before letting an agent act on connected knowledge and task systems?

Map the connector, service account and content boundary. Check the agent's read, create and edit permissions, and the log of its activity. Review access when roles change.

What evidence does the article offer on whether AI has improved business results?

The ONS reports improving existing operations as the most common purpose, but the analysis does not link any named application to a result. Benefit claims remain unproven.

More in Outlook