Every large company we talk to has the same story. A team built an agent. It worked in the demo. Then it sat there.
The demo was not the hard part. Any team with an SDK and a weekend can get a model to read an invoice and draft a reply. The hard part starts when the agent has to touch a real system, with real permissions, and someone in security asks what it can do.
Where the time goes
Three questions stop most projects, and none of them is about the model.
What can it reach? An agent with a service account can usually reach everything that account can. Security teams notice. The fix is to run the agent with the permissions of the person who started it, and nothing more. That is a platform decision, not a prompt.
What did it do? A summary of the run is not a record of the run. The controller wants to know what the agent read, what it wrote, and what each step cost. Without that, every run is a conversation about trust.
Who changes it? The process changes in March. The agent was built in January by someone who has moved on. If the agent lives in code, it waits for an engineer. If the people who run the process can edit it, in plain English, with each version kept, it changes the same day.
What gets past the gate
The projects that reach production share a shape. The agent is built by the team that owns the process. It runs inside the company's own cloud. Every action is inside someone's permissions and on the record. And the first one is small: one process, one department, one month of real cases to test against.
The fifth agent a team builds takes days. The first one took weeks. The difference is not the model. It is having a place to build where the questions above are already answered.