Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Consulting firms need clear identities, permissions, and audit trails before AI agents handle proposals, research, and firm knowledge.

Who Controls Your Consulting AI Agents?
Insight ai

Who Controls Your Consulting AI Agents?

Sam McKay

AI agents need an owner, not just a login

Consulting firms are starting to put AI to work on tasks that sit close to revenue and client trust.

An agent may draft a proposal for a $250,000 engagement. It may research a target company before a partner meeting. It may search 10 years of project material and pull out a recommendation that shapes a client workshop.

That creates a basic management question. Who is in charge of the agent?

Not who clicked “run.” Not who set up the first workflow six months ago. Who owns its actions, controls what it can access, approves changes to its permissions, and can explain what it did after the fact?

For a consulting or advisory firm doing $1 million to $25 million in annual revenue, this isn’t a theoretical governance exercise. It affects your proposal quality, your utilisation, your intellectual property, and your risk with clients.

The firms that get value from agents don’t treat them as a shared chatbot with broad access to Google Drive, SharePoint, and CRM data. They treat each agent like a new member of the operating team. It has a defined role. It gets only the credentials needed for that role. Its activity is logged. A named person is accountable for its output.

That structure is what lets you use agents with confidence rather than keeping them stuck in personal experiments.

The manual work agents are starting to touch

Most consulting firms have no shortage of useful work for AI agents. The issue is that the work is usually spread across people, folders, systems, and informal habits.

Take proposals.

A major proposal can consume 20 to 40 hours from senior consultants, managers, and partners. Someone finds a past proposal that may be relevant. Someone else checks the latest case studies. A partner rewrites the positioning because the old version no longer reflects the firm’s offer. Finance or operations looks for pricing precedent. The team then spends hours reconciling different versions of the deck.

The work produces a document. It also exposes sensitive information. Past client names, commercial terms, delivery methods, margin assumptions, team bios, and internal pricing models can all appear in the source material.

A Proposal Generation Agent in Omni ops can reduce the gathering and first-draft burden. It can pull approved past proposals, current case studies, service descriptions, and pricing guidance into a tailored draft. But it shouldn’t have unrestricted access to every client folder or the authority to send a proposal from a partner’s inbox.

Research creates a similar problem.

Many engagements begin with a week or two of secondary research. Teams collect company filings, industry reports, news, competitor material, earnings calls, public strategy statements, and internal notes from previous work. A capable analyst may be able to do this well, but the same categories of research get repeated client after client.

A Research Agent can run a structured process at the start of each engagement. It can gather sources, prepare summaries, identify open questions, and produce a one-page brief. The firm gains speed, but only if the agent has clear boundaries around sources, client workspaces, and what it is allowed to conclude without human review.

Then there is the knowledge problem that almost every established consulting firm carries.

Every project creates IP. Decks, interview notes, workshop outputs, transcripts, spreadsheets, frameworks, and recommendations accumulate over time. Yet when a new engagement starts, teams often search their own memory first. They ask around on Teams or Slack. They rebuild something that already exists because the original project team can’t be found or the file names make the work impossible to locate.

A Knowledge Agent can read approved decks, documents, and meeting transcripts and answer questions across the firm’s corpus. That can make years of hard-won work more useful. It can also expose material from one client context in another if identity and access rules aren’t properly designed.

This is why agent identity control needs to come before broad deployment.

A shared AI account is not a control system

The easiest way to introduce AI is also the least controlled. A staff member opens an account, uploads a few files, connects a shared drive, and shares the link with colleagues.

That arrangement may work for a low-risk experiment. It breaks down when the agent starts handling client-facing or commercially sensitive work.

A shared account can’t answer key questions cleanly:

  • Which agent accessed the document set for this proposal?
  • Which person approved the agent’s connection to the CRM?
  • Did it use current pricing guidance or an outdated spreadsheet?
  • What source material informed this research brief?
  • Did the agent surface information from a restricted client engagement?
  • Who changed its instructions before it produced an inaccurate answer?
  • Can we revoke access immediately when a contractor or employee leaves?

When nobody can answer those questions, a firm has effectively made the agent a blind spot in its delivery model.

Human employees don’t get unlimited access simply because they work for the firm. A new analyst may access the project they are staffed on, a knowledge base appropriate to their role, and certain internal systems. They don’t automatically access partner compensation, every client folder, or every commercial record.

AI agents deserve the same discipline. In fact, they often need more of it because they can search and synthesise information at a scale no individual employee can match.

If you’re considering agents for proposals, research, or knowledge retrieval, start by reviewing the AI audit for consulting firms. It gives you a practical way to identify the workflows worth automating and the controls required before you connect them to core firm data.

Give every agent a specific identity

The right operating model is straightforward. Every agent gets its own identity. Don’t make it operate as “Sam’s assistant” or under a generic firm-wide login.

An agent identity should include five elements.

1. A named business purpose

Write down the job in one sentence.

For example, the Proposal Generation Agent may be authorised to create internal proposal drafts using approved content and current commercial templates. It is not authorised to negotiate pricing, send documents externally, or promise delivery outcomes.

The Research Agent may compile public information and create a cited engagement brief. It is not authorised to access restricted project workspaces unless the engagement lead explicitly grants access.

The Knowledge Agent may answer questions from a defined set of approved firm knowledge collections. It is not authorised to retrieve documents from restricted client repositories.

A clear purpose prevents agents from becoming catch-all tools. It also makes it easier to decide which integrations are necessary.

2. A human owner

Every agent needs a named owner with authority to make decisions.

For a proposal agent, that may be the commercial lead or head of growth. For a research agent, it may be the consulting operations lead. For a knowledge agent, it might be the person responsible for knowledge management, quality, or practice development.

The owner isn’t expected to inspect every output personally. Their role is to approve the agent’s remit, review its permissions, oversee changes to its instructions, and make sure the agent is meeting a real business need.

You may also need a technical custodian who manages the platform connection and a content owner responsible for source material. Those roles can be different people. What matters is that the firm knows who has accountability when an issue arises.

This is one area where Omni advisory can help. The technology is rarely the hardest part. The hard part is deciding how ownership, decision rights, and operating rules fit into the way your firm already sells and delivers work.

3. Permissions based on the actual task

An agent should have the minimum access needed to do useful work.

For a Proposal Generation Agent, that might mean read-only access to an approved proposal library, case study repository, service catalogue, and selected CRM opportunity fields. It may need access to current rate cards, but not historic margin reports or all finance records.

For a Research Agent, public web access and an engagement-specific workspace may be enough. If it needs internal research from a prior project, grant access to the relevant collection rather than the entire archive.

For a Knowledge Agent, use defined knowledge collections. Segment content by practice, geography, client confidentiality level, or project type where needed. A firm-wide search sounds useful until a restricted board presentation appears in an answer for someone who had no business seeing it.

This is least-privilege access applied to consulting work. Start small and expand only when there is a clear operational reason.

4. Approval points for high-impact actions

Some actions should always require human approval.

A proposal agent can draft. A partner or commercial lead should approve the final scope, commercial position, client references, and commitments before anything leaves the firm.

A research agent can collect and summarise sources. An engagement leader should validate key claims before they enter a client-facing document.

A knowledge agent can retrieve information. A consultant should still assess whether the material applies to the current client context and whether it needs updating.

The goal isn’t to create a bottleneck around every prompt. The goal is to place review where an error creates commercial, legal, or reputational cost.

5. An audit log that people can actually use

Audit logs matter when something goes wrong, but they’re also useful for improving the agent.

A practical log records:

  • The agent identity that ran the task
  • The user who requested it
  • The date and time
  • The systems and knowledge collections accessed
  • The source documents used
  • The instruction version used
  • Outputs created or actions proposed
  • Approval or rejection by a human reviewer
  • Permission changes and the person who made them

You don’t need an enterprise theatre production to get started. You need enough evidence to trace an outcome from request to source material to reviewer.

That traceability helps you find bad source data, outdated instructions, recurring failure points, and unproductive uses of the agent. It also gives a partner confidence when a client asks how a piece of work was created.

What a controlled proposal agent looks like end to end

Picture a partner receiving an opportunity from an existing client. The request is for a transformation programme proposal due in four business days.

The partner opens the opportunity in the CRM and triggers the Proposal Generation Agent. The agent has read-only access to the opportunity summary, client industry, stated problem, proposal deadline, approved service descriptions, current credentials, and selected case studies.

It does not have access to every prior client engagement. It does not have permission to email the client. It cannot alter the rate card or add unapproved claims.

The agent first confirms what information is missing. It may ask for the estimated project duration, proposed team shape, and target outcome. Once that is supplied, it searches approved content collections, selects relevant case studies, and creates a draft outline.

The draft includes citations to the internal source material it used. It marks commercial assumptions as placeholders. It flags where it couldn’t find evidence for a specific claim.

A manager reviews the first draft. The commercial lead checks pricing and scope. The partner rewrites the strategic narrative and approves the final version. The audit record shows what the agent accessed, which template it used, what was edited by humans, and who approved release.

That is a very different model from asking a generic tool to “write a proposal using our previous work.”

The same design principles apply across Omni ops, where agents are built around defined operational jobs rather than deployed as open-ended assistants.

The dollar cost of weak controls and weak reuse

The annual leakage band we usually see for consulting firms of this size is around $80,000 to $300,000. That isn’t one neat line item in the P&L. It shows up in senior proposal time, repeated research, slow onboarding, inconsistent deliverables, missed reuse of existing IP, and avoidable rework.

Identity control doesn’t eliminate all of that leakage by itself. It enables you to put agents into the workflows where the leakage occurs without creating an uncontrolled data problem.

Consider a firm submitting 25 substantial proposals a year. If each proposal absorbs 20 to 40 hours of senior and manager time, that is 500 to 1,000 hours before counting design, administration, and follow-up. Saving part of the search, retrieval, and first-draft work can free meaningful capacity. But only if the agent can access the right approved material and staff trust its process.

The same is true for research. If project teams repeatedly spend several days collecting a similar baseline of market and company information, the firm is paying for the same thinking more than once. A controlled research workflow gives the team a starting point while retaining the analyst’s judgement where it matters.

If you want to identify where this applies in your own firm, Book a 60-min Omni Audit. In 60 minutes, we map the manual work, identify the highest-value agent opportunities, and outline the controls and next steps. You get three useful outputs, not a presentation deck.

Start with one agent and a control checklist

Don’t begin by connecting an AI platform to every internal folder. Pick one repeatable workflow where the value is clear, the boundaries can be defined, and a human can review the result.

For many firms, a proposal draft workflow is the practical first choice. For others, it is structured engagement research or a narrow practice-area knowledge collection.

Before you deploy, answer these questions:

  1. What business outcome is this agent responsible for improving?
  2. Who is the named agent owner?
  3. Which specific systems and content collections does it need?
  4. What information must it never access?
  5. Which outputs require human approval?
  6. How will you record its inputs, sources, outputs, and permission changes?
  7. Who reviews the agent’s performance every 30, 60, or 90 days?
  8. What is the process for disabling it quickly?

Our Deploy Your First Business Agent worksheet gives you a practical version of that planning process. You can download the checklist here and use it with the person who owns your first agent workflow.

You can also browse the broader AI insights library for examples of where firms are applying agents across operations, client delivery, and internal knowledge.

Make accountability part of the build

The question isn’t whether AI agents will enter consulting firms. They already are, often through individual tools and informal workarounds.

The real decision is whether you will give them defined jobs, controlled access, accountable owners, and usable audit trails before they become embedded in important work.

That approach may feel slower at the start. In practice, it gives you a stronger foundation to scale. Partners can approve real use cases. Teams know what they can trust. Clients get clearer answers about how their information is handled. And the firm can reuse more of the IP it has already paid to create.

See Omni for consulting firms to understand how we assess the workflows, data, permissions, and operating model behind practical agent deployment.

When you’re ready to turn this into a specific plan for your firm, Book a 60-min Omni Audit. We’ll focus on where the manual effort sits, which agent should come first, and who needs to be in charge.