DEV Community

Dynamics Monk
Dynamics Monk

Posted on

D365 + Agentic AI: What "Autonomous" Actually Means in an ERP

Originally published on LinkedIn (Inside Monk) on August 20, 2026.

A finance controller opens her laptop on a Monday morning. Before she's even logged into email, three purchase orders have been approved overnight, a vendor discrepancy has been flagged and routed to the right person, and a supply chain agent has already reordered stock that was about to run out.

Nobody clicked a button. Nothing was requested. It just happened.

This isn't a demo reel anymore. It's what's shipping inside Dynamics 365 right now, across finance, supply chain, sales, and customer service. Microsoft has rolled out more than twenty first-party AI agents since October 2025, and the 2026 Release Wave 1 pushed that further, embedding agentic capability into nearly every module. The word Microsoft keeps using to describe all of this is "autonomous." And it's a word most vendors, partners, and even a few CXOs are using a little too loosely.

The Word Doing All the Heavy Lifting

Ask ten people in enterprise tech what "autonomous AI" means and you'll get ten different answers. Some picture a system that runs the business without anyone watching. Others picture a slightly smarter version of Copilot that still waits for a prompt.

Neither is quite right, and the gap between those two pictures is exactly where most Dynamics 365 conversations are going wrong today.

Here's the distinction that actually matters: Copilot assists when you ask it to. Agents act when a condition is met, without waiting to be asked. That's the real shift in Wave 1. Sales agents research and engage leads on their own. Service agents resolve cases end to end. Finance agents reconcile, flag anomalies, and route approvals. Supply chain agents replenish stock based on live signals. None of them are waiting for a prompt. They're watching for a trigger.

That is genuinely new for ERP. For years, "AI in ERP" meant a chatbot that summarised your data when you asked it to. Now the system is initiating the work itself. But calling that "full autonomy" oversells what's actually happening and undersells the part that matters more.

What's Actually Running Under the Hood

Every agent Microsoft has shipped inside Dynamics 365 operates inside a boundary. It has a defined scope, a set of permissions, and in most cases, an approval checkpoint before anything with real financial or operational consequence goes through. Microsoft's own architecture reflects this: agents built through Copilot Studio sit closer to the semi-autonomous end of the spectrum, while multi-agent orchestration through Azure AI Foundry pushes toward fuller autonomy, but always inside a governed structure.

That structure now has a name. Microsoft Agent 365, which reached general availability earlier this year, is being positioned as the control plane for every agent running across Microsoft 365, Dynamics 365, Power Platform, and Azure. Agents get their own identity through Microsoft Entra, their own audit trail, and their own lifecycle, the same discipline that's applied to human employees with system access. That's the part of this story that deserves far more attention than it's getting.

The Conversation Most Leaders Are Skipping

While everyone's been debating how "smart" these agents are, a quieter problem has been building underneath the excitement.

Gartner expects 40% of enterprise applications to carry embedded, task-specific AI agents by the end of this year, up from under 5% just last year. That's not gradual adoption. That's a near-vertical curve. And Deloitte's 2026 State of AI in the Enterprise report found that only one in five organisations actually has a mature governance model to manage what they've deployed. Separate research from SAP puts the average Fortune 500 enterprise on track for well over 100,000 AI agents in production within a few years, with barely more than one in ten organisations confident they can govern that scale.

Inside an ERP, this isn't an abstract security concern. An agent with write access to your general ledger, your inventory, or your customer records is functionally a new employee with system permissions, minus the years of context, judgement, and accountability a human brings. If nobody owns the question of what that agent can touch, who approved its scope, and how its actions get reviewed, autonomy stops being an efficiency gain and starts being exposure sitting quietly on your balance sheet.

This is the conversation Dynamics 365 customers should be having right now, not "how autonomous can we make this," but "how governed does this need to be before we let it run."

What "Autonomous" Should Actually Mean for Your ERP

The honest definition, at least for where Dynamics 365 stands today, is this: autonomous means the system can plan and execute multi-step work without a person initiating every step, inside boundaries a person deliberately set and can audit at any time.

Not unsupervised. Not self-directed in the way the marketing language sometimes implies. Bounded, accountable, and reversible.

For a CTO or CFO evaluating what's next, the questions worth asking aren't about which agent does the flashiest demo. They're closer to this: Which processes genuinely benefit from an agent acting first and reporting later, versus ones that still need a human in the loop? Who in the organisation owns agent governance the way IT owns identity and access today? And is that governance structure being built before the rollout, or after something goes wrong?

Dynamics 365's shift toward agentic AI is real, and it's arriving faster than most transformation roadmaps anticipated. The organisations that get real value from it won't be the ones that deploy the most agents first. They'll be the ones that understood, early, that autonomy without governance isn't a feature. It's a liability wearing a feature's clothing.

That's the conversation worth having before the next release wave, not after.

We looked at exactly this inside the finance function, where "touchless close" runs into a governance question every finance leader eventually has to answer: how much authority is too much to hand to a system.

Check out our blog: https://dynamicsmonk.com/blog/finance-decision-orchestration-close-automation-dynamics-365

💬 Like what you read? Be the first to get our culture stories, tech insights, and innovation journeys. Subscribe to Inside Monk on LinkedIn.

Top comments (0)