From Workflows to Agents

Watch the Webinar On-Demand

GRC Data & AI Summit 2026

Field report · Brittany Davis, Compliance Program Manager, 360insights · Kathleen Oliveira, Solutions Engineer, Anecdotes 

A workflow is “do a thing”, a person steps in, “do a thing”, a person steps in. Brittany Davis runs a compliance program that way and has been steadily handing the mechanical parts over. She has agents reviewing Jira tickets to flag what her engineering teams still owe before an auditor asks. What she will not hand over is the judgment, and she is direct about why she trusts what she trusts: understanding how an agent reached a conclusion, not the conclusion itself. She is equally direct about the failure mode. Agents do not create something net new. Point one at an incomplete asset inventory and a stale risk register and it will show you, fast, exactly how incomplete they are. Kathleen Oliveira then walks a quarterly risk review end to end to make the split concrete.

What you'll take away

  • Where the line sits between what an agent does and what a person signs
  • What makes agent output trustworthy: the reasoning path you can follow, not the conclusion you are handed
  • Why agents amplify the governance you already have, in both directions, and what to fix first
  • How the research phase works in practice: correlating the risk register, prior findings, open exceptions, ownership, and remediation history
  • A quarterly risk review walked end to end, with the agent doing the legwork and the analyst making the call

Mobile App