<?xml version="1.0" encoding="UTF-8" ?><!-- generator=Zoho Sites --><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><atom:link href="https://assetsoft.biz/blogs/tag/responsibleai/feed" rel="self" type="application/rss+xml"/><title>Assetsoft - Blog #ResponsibleAI</title><description>Assetsoft - Blog #ResponsibleAI</description><link>https://assetsoft.biz/blogs/tag/responsibleai</link><lastBuildDate>Thu, 01 Oct 2026 13:36:50 -0700</lastBuildDate><generator>http://zoho.com/sites/</generator><item><title><![CDATA[AI Agent Governance for Yardi & MRI | Assetsoft]]></title><link>https://assetsoft.biz/blogs/post/ai-agent-governance-for-yardi-mri-assetsoft</link><description><![CDATA[<img align="left" hspace="5" src="https://assetsoft.biz/Your AI Agent Just Approved an Invoice. Who Authorized That - A Governance Playbook for Yardi a-1.jpg"/>AI agents now approve invoices and run month-end in Yardi and MRI. A governance playbook for property finance teams: role mapping, approval thresholds, segregation of duties, audit trails, and what test automation and process mining can prove.]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_trS5llS-RIyNn7fNJd19ag" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_Jiqca6R8QkeV-sWjhw9JhQ" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm_F6_2M1xMTu2vQPAsz_BtLA" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_mPpscCO9kNh6JERF6ctRhQ" data-element-type="image" class="zpelement zpelem-image " data-animation-name="bounceInDown"><style> @media (min-width: 992px) { [data-element-id="elm_mPpscCO9kNh6JERF6ctRhQ"] .zpimage-container figure img { width: 1340px ; height: 287.26px ; } } </style><div data-caption-color="" data-size-tablet="" data-size-mobile="" data-align="center" data-tablet-image-separate="false" data-mobile-image-separate="false" class="zpimage-container zpimage-align-center zpimage-tablet-align-center zpimage-mobile-align-center zpimage-size-fit zpimage-tablet-fallback-fit zpimage-mobile-fallback-fit hb-lightbox " data-lightbox-options="
                type:fullscreen,
                theme:dark"><figure role="none" class="zpimage-data-ref"><span class="zpimage-anchor" role="link" tabindex="0" aria-label="Open Lightbox" style="cursor:pointer;"><picture><img class="zpimage zpimage-style-none zpimage-space-none " src="/Your%20AI%20Agent%20Just%20Approved%20an%20Invoice.%20Who%20Authorized%20That%20-%20A%20Governance%20Playbook%20for%20Yardi%20a.jpg" size="fit" data-lightbox="true"/></picture></span></figure></div>
</div><div data-element-id="elm_Bp0RvfMLTDu5pSGZKkW54w" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-center zptext-align-mobile-center zptext-align-tablet-center " data-editor="true"><p>You can edit text on your website by double clicking on a text box on your website. Alternatively, when you select a text box a settings menu will appear. your website by double clicking on a text box on your website. Alternatively, when you select a text box.</p></div>
</div><div data-element-id="elm_XFigU_xD53byGCEgSWbq6Q" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">T</span>he invoice nobody approved</b></b></b></span><span style="font-size:20px;"><b></b></span></h2></div>
<div data-element-id="elm_GNjABG7YDjCFVNGh4sLI_A" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>Somewhere this morning, a $3,800 landscaping invoice for a suburban retail center was approved, coded to the right GL account, matched to a purchase order, and queued for payment. Nobody in accounts payable looked at it. Nobody in property management looked at it. An agent did, with a second agent checking its work, and both cleared a confidence threshold someone set in a configuration screen six months ago.</span></p><p><span>That is not a hypothetical. Yardi's Smart Approval agent, part of Virtuoso, evaluates eligible invoices against learned rules and approves those that qualify; one agent decides, and a second confirms or challenges it. MRI's Agora Orchestrator, launched in June 2026, <a href="https://www.mrisoftware.com/ca/?p=58561" style="text-decoration-line:underline;color:rgb(48, 4, 234);">moves workflows from recommendation to automated execution</a> across commercial, multifamily, and residential portfolios. Both are good products. Both answer a question most property finance teams have not asked yet: when an agent acts, who authorized that?</span></p><p><span>The wider enterprise is asking it loudly. This week the US Federal Trade Commission opened a <a href="https://www.theneuron.ai/digest/everything-that-happened-in-ai-today-wednesday-september-30-2026/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">broad investigation into frontier-model risk</a>, after a run of incidents in which agents reached systems they were never meant to touch. Fortune reported that the CIOs of <a href="https://fortune.com/2026/09/16/ai-agents-are-going-rogue-cios-are-racing-to-put-guardrails-around-them/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">Cisco, Intuit, Workday and ServiceNow</a> are building oversight layers around agents, with Cisco's operations chief refusing to authorize any third-party vendor agent at all to avoid &quot;agent sprawl.&quot;</span></p><p><span>The number that should stop a CFO mid-sentence comes from a 2026 survey of 235 large-enterprise security leaders, cited by the Cloud Security Alliance: <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-agent-governance-framework-gap-20260403/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">71% say AI systems already have access to core ERP, CRM, and financial platforms, and only 16% govern that access effectively</a>. In property management, where the ERP is Yardi or MRI and the &quot;financial platform&quot; is the rent roll, the gap is the same, and the controls are thinner.</span></p><p><span>This is a playbook for closing it before you switch on native platform agents, not after.</span></p></div><p></p></div>
</div><div data-element-id="elm_CC7Ncrh01WqZIDWsRBIRFQ" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="color:rgb(29, 128, 226);"><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">W</span>hat an agent actually does inside Yardi and MRI</b></b></b></span></b><b></b></span></h2></div>
<div data-element-id="elm_JoBu_b9Aiu8YziC0kFzuWQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>The word &quot;agent&quot; covers a lot of ground, and governance only works if you know which kind you are dealing with. Inside the two dominant property platforms, agents now sit at three levels of autonomy.</span></p><p><b><span style="color:rgb(29, 128, 226);">Level 1</span><span style="color:rgb(22, 56, 90);">: It answers</span>.</b><span> Yardi Chat IQ handles prospect and resident conversations across chat, email, text, and voice, grounded in live Voyager data. MRI Agora Intelligence watches the portfolio and recommends actions. These agents read a great deal of data but post nothing to the ledger. The governance risk is disclosure and accuracy, not transactions.</span></p><p><b style="color:rgb(29, 128, 226);">Level 2:</b><b style="color:rgb(22, 56, 90);"> It acts within rules.</b><span> Yardi Smart Approval, paired with Smart AP, captures, codes, and approves invoices that meet amount, vendor, property, and GL criteria you define, using <a href="https://www.yardi.com/resources/smart-approval-brochure/pdf/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">12 months of your approval history</a> to generate vendor-specific rules. MRI Agora Orchestrator lets teams deploy agents from a pre-built catalog, configure them, and, in MRI's words, let them run. These agents post transactions. They are, functionally, approvers with system access.</span></p><p><b style="color:rgb(29, 128, 226);">Level 3:</b><b style="color:rgb(22, 56, 90);"> It builds other agents.</b><span> Yardi Virtuoso Composer and MRI's agent configuration tools let operators create custom agents without code. A property accountant can now build an agent that reconciles a bank feed, chases tenants, or prepares a month-end journal. Nobody in IT needs to be involved, which is the point- and the problem.</span></p><p><span>The shift that matters is from Level 1 to Level 2. Once an agent can approve, post, or pay, it has stepped into the control environment that external auditors, lenders, and investors rely on; in most property firms, that environment was designed in the era of named users, wet signatures, and dollar-threshold approval matrices. Agents do not fit it, and the platforms do not retrofit it for you. <a href="https://www.mannpublications.com/mannreport/2026/06/25/mri-software-launches-agora-intelligence-and-agora-orchestrator/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">MRI's own announcement</a> frames Orchestrator as keeping every decision with the person responsible for it; Yardi lets you set amount and confidence thresholds. Both leave the design of that responsibility to you.</span></p></div><p></p></div>
</div><div data-element-id="elm_hC--oU6dlBSILYVWuO25OQ" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">A</span>gent sprawl: why property finance is more exposed than the average enterprise</b></b></b></span><span style="font-size:20px;"><b></b></span></h2></div>
<div data-element-id="elm_mrW-QPJ86ExUeUrXgDWucg" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>Cisco's answer to agent sprawl was to <a href="https://fortune.com/2026/09/16/ai-agents-are-going-rogue-cios-are-racing-to-put-guardrails-around-them/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">centralize every authorized model, agent and dataset on one internal platform</a> and refuse third-party agents entirely. Few property companies can do that, and most should not. But the reasons Cisco worries apply with more force to a real estate operator than to a software company.</span></p><p><b><span style="color:rgb(22, 56, 90);">Agents arrive inside the platform, not through IT</span>.</b><span> A Yardi or MRI release note enables them. A regional controller switches one on for a trial. A marketplace agent gets added to a module during an upgrade. There is no procurement event, no security review, no change ticket. Intuit's CIO describes the resulting risk as <a href="https://www.informationweek.com/cyber-resilience/intuit-smartsheet-ets-cisos-on-ensuring-enterprise-resilience-before-ai-orphans-emerge" style="text-decoration-line:underline;color:rgb(48, 4, 234);">agents that get orphaned and become an attack vector</a> when their creator leaves. In property management, where turnover in site and regional accounting roles is high, orphaned agents will be common within a year.</span></p><p><b style="color:rgb(22, 56, 90);">The control environment is shared with third parties.</b><span> Owners, managers, lenders, joint-venture partners, and outsourced accounting teams all touch the same Yardi or MRI database. An agent enabled by a third-party manager can approve invoices on an owner's property. Whose approval matrix applies? Whose auditor signs off? Management agreements written in 2022 do not say.</span></p><p><b><span style="color:rgb(22, 56, 90);">Month-end is a chain of dependent steps</span>.</b><span> Bank reconciliation, accruals, CAM reconciliation, intercompany, investor reporting. An agent that executes one step well can push an error into every step after it, and the error surfaces three weeks later in a distribution calculation. Agents fail fast; property accounting discovers slowly.</span></p><p><b style="color:rgb(22, 56, 90);">The volume case is strongest where the controls are weakest.</b><span> Yardi reports that <a href="https://www.yardi.com/blog/?p=54648" style="text-decoration-line:underline;color:rgb(48, 4, 234);">80% of client invoices are under $5,000 and take at least six days to approve</a>. Those are exactly the invoices nobody scrutinizes today, which is why automating them is attractive, and why the fraud and duplicate-payment risk concentrates there.</span></p><p><span>None of this argues against agents. It argues for treating the day you enable a Level 2 agent as a control-environment change, with the same rigor you would apply to giving a new employee approval authority.</span></p></div><p></p></div>
</div><div data-element-id="elm_4pHQodeehTy1zhEtjSSgFA" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="color:rgb(29, 128, 226);"><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">T</span>he five questions your auditor will ask</b></b></b></span></b><b></b></span></h2></div>
<div data-element-id="elm_K4GYv9rgGJf9w6j0DFbnyw" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>External auditors have not yet published an agent-specific standard for real estate, but the questions are predictable because they are the questions already asked of any automated control. Expect these five in your next audit planning meeting and expect them from lenders and institutional LPs soon after.</span></p></div><p></p></div>
</div><div data-element-id="elm_Lj_tDPzDM2jSR3KtrlipJA" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span></span></p><div><table border="1" cellspacing="0" cellpadding="0"><thead><tr><td><p><span>#</span></p></td><td><p><span>Question</span></p></td><td><p><span>What a good answer looks like</span></p></td></tr></thead><tbody><tr><td><p><span>1</span></p></td><td><p><b>Identity.</b><span> Which agents exist, who owns each one, and what can it do?</span></p></td><td><p><span>A register listing every enabled agent, its platform, its owner, its permissions, and its enablement date</span></p></td></tr><tr><td><p><span>2</span></p></td><td><p><b>Thresholds.</b><span> What limits apply, and who approved them?</span></p></td><td><p><span>Dollar, vendor, property, and confidence thresholds documented and signed off by the same authority that approves the human delegation matrix</span></p></td></tr><tr><td><p><span>3</span></p></td><td><p><b>Evidence.</b><span> Can you show what the agent did and why, for any transaction?</span></p></td><td><p><span>An immutable log of each agent action, the inputs it saw, the rule or reasoning it applied, and the outcome.</span></p></td></tr><tr><td><p><span>4</span></p></td><td><p><b>Segregation.</b><span> Can one agent, or one person via an agent, initiate and approve the same transaction?</span></p></td><td><p><span>A mapping of agent roles against the SoD matrix, with compensating controls where conflicts exist</span></p></td></tr><tr><td><p><span>5</span></p></td><td><p><b>Kill switch.</b><span> How fast can you stop an agent, and what happens to in-flight work?</span></p></td><td><p><span>A tested procedure, a named owner, and a non-AI fallback for the affected workflow</span></p></td></tr></tbody></table></div><p></p></div><p></p></div>
</div><div data-element-id="elm_mVabzdGHN2RdvpHMotoO2w" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span></span></p><div><p><span>Most property firms can answer question 3 partially, because the platforms log agent actions. Almost none can answer 1, 2, and 4 today, because the answers live in nobody's job description. Question 5 is the one that ServiceNow built an entire product around after an agent at one company <a href="https://fortune.com/2026/05/06/servicenow-kill-switch-ai-agents-bill-mcdermott/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">deleted a production database and its backups in nine seconds</a>. Your exposure is smaller, but your fallback plan for &quot;the invoice-approval agent is misbehaving, and it is the 28th of the month&quot; should still exist on paper.</span></p></div><p></p></div><p></p></div>
</div><div data-element-id="elm_Wr2MotHYTpkYsPR2EvC73g" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">R</span>ole mapping: give every agent a job description</b></b></b></span><span style="font-size:20px;"><b></b></span></h2></div>
<div data-element-id="elm_lbWTPPyQtKTbgQG8kclkJQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>The single most useful mental shift is to stop thinking of an agent as a feature and start thinking of it as a new hire. New hires get a role, a manager, a set of system permissions tied to that role, an approval limit, and a review date. Agents should get the same.</span></p><p><b style="color:rgb(22, 56, 90);">A role, not a toggle.</b><span> In Yardi, create a dedicated security role for each agent rather than letting it inherit the permissions of whoever enabled it. In MRI, do the same with the agent's service identity. The role should allow only the tables, properties, and transaction types the agent needs. The CSA's guidance is that <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-agent-governance-framework-gap-20260403/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">agents should not hold standing access to production systems</a> and should get time-bound, task-scoped credentials where the platform supports it. Few property platforms do yet; where they do not, a narrow dedicated role is the compensating control.</span></p><p><b style="color:rgb(22, 56, 90);">A manager.</b><span> Every agent needs a named human owner who is accountable for its thresholds, reviews its exception log, and is the first call when it misbehaves. This is normally the controller or AP manager for finance agents and the regional property manager for operational ones. Record the owner in the agent register. When that person leaves, reassign or disable the agent the same day as their user account.</span></p><p><b style="color:rgb(22, 56, 90);">Thresholds that mirror the delegation matrix.</b><span> Most owners already have a delegation-of-authority matrix: a site manager approves up to $2,500, a regional manager up to $10,000, a VP up to $50,000. An agent's approval limit should be a line in that matrix, approved by the same governance body, not a number typed into a configuration screen. Consider three dimensions, not one:</span></p><p><span style="color:rgb(29, 128, 226);"><span>•&nbsp;</span><b>Amount per transaction</b></span><span> (Yardi's beta clients ran Smart Approval at <a href="https://www.yardi.com/blog/?p=54648" style="text-decoration-line:underline;color:rgb(48, 4, 234);">up to $2,500</a>, a sensible starting point)</span></p><p><span style="color:rgb(29, 128, 226);"><span>•&nbsp;</span><b>Cumulative amount per vendor per period</b></span><span><span style="color:rgb(29, 128, 226);">,</span> which catches split invoices</span></p><p><span style="color:rgb(29, 128, 226);"><span>•&nbsp;</span><b>Confidence threshold</b></span><span><span style="color:rgb(29, 128, 226);">, </span>set conservatively at launch and loosened only on evidence</span></p><p><b style="color:rgb(22, 56, 90);">A review date.</b><span> Agents learn from history, and their rules drift. Schedule a quarterly review of each Level 2 agent's thresholds, exception rate, and false-approval rate, and minute the results. Treat a change to an agent's limits as a change to the delegation matrix, requiring the same sign-off.</span></p><p><span>This is unglamorous work. It is also exactly what distinguishes a firm that can show an auditor a control from one that can show them a screenshot.</span></p></div><p></p></div>
</div><div data-element-id="elm_PB-uph9avGEMRscaa4yQIA" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="color:rgb(29, 128, 226);"><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">S</span>egregation of duties when the agent is preparer, reviewer, and poster</b></b></b></span></b><b></b></span></h2></div>
<div data-element-id="elm_omVDPTZor2fZxZqz7FF9vw" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>Segregation of duties is the oldest control in accounting: the person who creates a vendor should not approve its invoices, and the person who approves invoices should not release payments. Agents break this in two easy-to-miss ways.</span></p><p><b><span style="color:rgb(22, 56, 90);">The agent collapses the chain</span>.</b><span> Smart AP captures and codes the invoice; Smart Approval approves it; a payment run releases it. If all three are agents configured by the same AP manager, that manager has, in effect, end-to-end control of cash disbursement through a tool that never pushes back. Yardi's two-agent design, where a second agent must confirm the first, is genuine control, but it is a control within the vendor's logic, not within your SoD matrix. Your matrix needs to say which human reviews the agent's exceptions and which human can change its rules, and those should be different people.</span></p><p><b style="color:rgb(22, 56, 90);">The agent inherits a person's conflicts.</b><span> An agent built in Virtuoso Composer by a property accountant typically runs with that accountant's permission. If the accountant can both post journals and approve them in a small-team configuration, so can the agent, at scale and without the accountant noticing. Agents built on over-privileged human roles are the most common finding in the governance reviews we have seen this year.</span></p><p><span>The practical fix is a three-column exercise. List every agent. For each, record the duties it performs using the same categories as your human SoD matrix: initiate, approve, record, reconcile, custody. Then overlay the human owners and configurations. Where one person, directly or through agents, touches two conflicting duties for the same transaction stream, you have a finding. Resolve it by splitting the agent's role, moving ownership, or adding a documented compensating review.</span></p><p><span>Two further SoD points for property firms specifically. First, in a third-party management arrangement, make the owner's finance team, not the manager's, the approver of agent thresholds on owner-funded bank accounts. Second, treat agent rules as privileged access: log them, review them monthly, and keep the ability to change rules away from the people whose work the agent approves.</span></p></div><p></p></div>
</div><div data-element-id="elm_WK52Obb15lH2pU25htEP1Q" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">A</span>udit trails and evidence: what test automation and process mining can prove</b></b></b></span><span style="font-size:20px;"><b></b></span></h2></div>
<div data-element-id="elm_3w6ZQbMU7LlU1IrjMFsN_g" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>A log is not evidence until someone can show it answers a question. Property platforms log agent actions, and MRI explicitly positions Orchestrator around <a href="https://commercialobserver.com/2026/06/mri-software-data-platform-ai-expansion/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">the governance and audit trail enterprise operators require</a>. But auditors want more than a list of what happened. They want assurance that the agent does what you say it does, every time, and that its behavior hasn't drifted. Two disciplines borrowed from enterprise automation answer that.</span></p><p><b style="color:rgb(22, 56, 90);">Test automation proves the agent behaves as configured.</b><span> Treat an agent's rules the way you would treat a Yardi or MRI configuration change: write test cases and run them before go-live and after every platform upgrade. A regression suite built in a tool such as UiPath Test Suite can push a controlled set of invoices through the AP workflow (a duplicate, a split invoice, an over-budget line, a new vendor, an invoice at the threshold, one just above it) and confirm that the agent approves, holds, or escalates each one correctly. The output is a dated, repeatable test report that says: on this date, with these rules, the agent made these decisions. That is control evidence. Re-run it quarterly and after every Yardi or MRI release, and you have a continuous-assurance record instead of a one-time sign-off.</span></p><p><b style="color:rgb(22, 56, 90);">Process mining proves what actually happened in production.</b><span> Test cases cover what you thought to test. Process mining reads event logs from Yardi, MRI, and surrounding systems and reconstructs how invoices, work orders, or journals actually flowed, including paths nobody designed. It answers the questions auditors and CFOs ask after the fact: What share of invoices did the agent approve versus route to a human? How often did a human override it? Did any approval bypass the purchase-order match? Did the agent's approval rate for a particular vendor jump in a particular month? Those patterns are invisible in a transaction log and obvious in a process map.</span></p><p><span>Together, the two give you something most firms lack: a before-and-after baseline. Mine the AP process for six months before enabling Smart Approval or an Orchestrator workflow. Record cycle time, touch count, exception rate, and error rate. Enable the agent. Mine again. Now the ROI claim in the board paper is measured, the control claim in the audit file is evidenced, and drift is detectable because you know what normal looked like.</span></p><p><span>One caution. Both techniques depend on clean, consistent event data from the platform. Firms whose Yardi or MRI instance carries years of inconsistent coding, custom tables, and workarounds often find that the first governance project is data clean-up, not a control design.</span></p></div><p></p></div>
</div><div data-element-id="elm_z0vlnbodyFmCoq7VuN0GQw" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="color:rgb(29, 128, 226);"><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">T</span>he pre-switch-on checklist for native platform agents</b></b></b></span></b><b></b></span></h2></div>
<div data-element-id="elm_HEspmL0bQZKlt6foih3aQQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>Run this before enabling any agent that can approve, post, pay, or change master data. It takes a competent controller and a platform administrator for two to four weeks for a first agent and a few days for each one after.</span></p><p><b style="color:rgb(22, 56, 90);">Before enablement</b></p><p><span>• Add the agent to the agent register: platform, purpose, owner, enablement date, autonomy level</span></p><p><span>• Create a dedicated security role with least privilege of access; do not inherit a human user's permissions</span></p><p><span>• Set amount, cumulative-vendor and confidence thresholds, and add them as a line in the delegation-of-authority matrix with the same sign-off</span></p><p><span>• Map the agent's duties against the SoD matrix and resolve or document any conflict</span></p><p><span>• Capture a process-mining baseline of the workflow it will touch</span></p><p><span>• Build and run a regression test set covering normal, boundary, and adversarial cases</span></p><p><span>• Confirm where the agent's reasoning and actions are logged, how long logs are retained, and who can read them</span></p><p><span>• Write the kill-switch procedure: who turns it off, how, and what the manual fallback is for month-end</span></p><p><span>• Where third-party managers or owners are involved, confirm in writing whose approval matrix governs</span></p><p><b style="color:rgb(22, 56, 90);">First 90 days</b></p><p><span>• Owner reviews the exception log weekly</span></p><p><span>• Re-run the regression suite after any platform release</span></p><p><span>• Compare post-enablement process-mining data to baseline at day 90; report cycle time, override rate and error rate</span></p><p><b style="color:rgb(22, 56, 90);">Ongoing</b></p><p><span>• Quarterly threshold review, minutes</span></p><p><span>• Agent reassigned or disabled on the day its owner leaves</span></p><p><span>• Register and evidence pack presented to the audit committee annually</span></p><p><span>None of this slows down a well-run deployment. It mostly moves work that would otherwise happen in a panic, three weeks after a distribution went out wrong, to a planned fortnight before go-live.</span></p></div><p></p></div>
</div><div data-element-id="elm_69Ryvt9dVjj7UQa86xGtLw" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">W</span>here this fits in a Yardi or MRI roadmap</b></b></b></span><span style="font-size:20px;"><b></b></span></h2></div>
<div data-element-id="elm_kSRIZle3G5pdm3EuMm0aCw" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p><span>Agent governance is not a standalone project, and firms that try to run it as one tend to produce a policy document that nobody reads. It works when it is attached to four things most property operators are already doing or planning.</span></p><p><b style="color:rgb(22, 56, 90);">A platform health check.</b><span> You cannot govern agents on a Yardi or MRI instance you do not fully understand. Most operators running a platform for five or more years carry undocumented customizations, dormant user accounts, over-broad security roles, and workflow exceptions that were &quot;temporary&quot; in 2021. A structured health check of security roles, workflows, configuration, and data quality is the prerequisite: it tells you which human roles are safe to model agent roles on, and which are not.</span></p><p><b style="color:rgb(22, 56, 90);">A Yardi or MRI AI strategy.</b><span><span style="color:rgb(22, 56, 90);"></span>The platforms are shipping agents faster than any operator can evaluate them. A written AI strategy decides which workflows are candidates for Level 2 automation, in what order, under what thresholds, and what the business case has to show. It is also where the firm decides its posture on third-party and custom agents, the question Cisco answered with an outright ban and most property firms will answer with a tiered approval process.</span></p><p><b style="color:rgb(22, 56, 90);">Test automation.</b><span> The regression suite described above is the same asset that de-risks every platform upgrade. Firms that have invested in UiPath Test Suite or equivalent for Yardi and MRI releases already have the harness; adding agent test cases is incremental. Firms that have not usually find that the agent project is the business case for building it.</span></p><p><b style="color:rgb(22, 56, 90);">Process mining.</b><span><span style="color:rgb(22, 56, 90);"></span>The baseline-and-compare method is also how you find the next workflow worth automating, measure the one you just automated, and give the audit committee numbers instead of adjectives. It tends to pay for itself in the AP process alone.</span></p><p><span>Firms such as <a href="https://www.assetsoft.biz/" style="text-decoration-line:underline;color:rgb(48, 4, 234);">Assetsoft</a>, which has implemented, integrated, and supported Yardi and MRI for owners and managers in Canada, the United States, and Australia since 2012 and runs UiPath test-automation and process-mining engagements on those platforms, see the same pattern across clients: governance done before enablement is a two-week task; governance done after the first incident is a two-quarter one. The difference is rarely the technology. It is whether anyone owned the agent register.</span></p></div><p></p></div>
</div><div data-element-id="elm_98yOkZqpPugQ5LBtK_0gAg" data-element-type="heading" class="zpelement zpelem-heading " data-animation-name="bounceIn"><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span style="font-size:20px;"><b><span style="color:rgb(29, 128, 226);"><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><b><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;"></span><span style="font-size:32px;">F</span>AQ: Who is accountable when an AI agent acts in Yardi or MRI?</b></b></b></span></b><b></b></span></h2></div>
<div data-element-id="elm_1kjewu_tvUbb_vyseuW2LA" data-element-type="codeSnippet" class="zpelement zpelem-codesnippet "><div class="zpsnippet-container"><!-- ASSETSOFT FAQ ACCORDION – ONE COLUMN --><section class="as-faq-accordion"><style> @import url("https://fonts.googleapis.com/css2?family=Poppins:wght@400;500;600;700&display=swap"); .as-faq-accordion, .as-faq-accordion * { box-sizing: border-box; font-family: "Poppins", sans-serif; } .as-faq-accordion { width: 100%; max-width: 1100px; margin: 0 auto; padding: 20px 0; } .as-faq-list { display: flex; flex-direction: column; gap: 14px; } .as-faq-item { overflow: hidden; background: #ffffff; border: 1px solid rgba(29, 128, 226, 0.15); border-radius: 16px; box-shadow: 0 6px 22px rgba(0, 55, 110, 0.06); transition: border-color 0.3s ease, box-shadow 0.3s ease, transform 0.3s ease; } .as-faq-item:hover { border-color: rgba(29, 128, 226, 0.35); box-shadow: 0 10px 30px rgba(29, 128, 226, 0.12); transform: translateY(-2px); } .as-faq-item.is-open { border-color: rgba(29, 128, 226, 0.4); box-shadow: 0 12px 32px rgba(29, 128, 226, 0.14); } .as-faq-question { width: 100%; display: flex; align-items: center; justify-content: space-between; gap: 20px; padding: 22px 24px; background: transparent; border: 0; color: #00376e; text-align: left; cursor: pointer; outline: none; } .as-faq-question-text { flex: 1; font-size: 17px; font-weight: 600; line-height: 1.5; } .as-faq-icon { position: relative; flex: 0 0 38px; width: 38px; height: 38px; border-radius: 50%; background: #cee0f3; transition: background-color 0.3s ease, transform 0.35s ease; } .as-faq-icon::before, .as-faq-icon::after { content: ""; position: absolute; top: 50%; left: 50%; width: 14px; height: 2px; border-radius: 10px; background: #1d80e2; transform: translate(-50%, -50%); transition: transform 0.35s ease, background-color 0.3s ease; } .as-faq-icon::after { transform: translate(-50%, -50%) rotate(90deg); } .as-faq-item.is-open .as-faq-icon { background: #1d80e2; transform: rotate(180deg); } .as-faq-item.is-open .as-faq-icon::before, .as-faq-item.is-open .as-faq-icon::after { background: #ffffff; } .as-faq-item.is-open .as-faq-icon::after { transform: translate(-50%, -50%) rotate(0deg); } .as-faq-answer { display: grid; grid-template-rows: 0fr; opacity: 0; transition: grid-template-rows 0.45s ease, opacity 0.35s ease; } .as-faq-item.is-open .as-faq-answer { grid-template-rows: 1fr; opacity: 1; } .as-faq-answer-inner { min-height: 0; overflow: hidden; } .as-faq-answer-content { margin: 0 24px; padding: 0 0 24px; border-top: 1px solid rgba(29, 128, 226, 0.12); } .as-faq-answer-content p { margin: 18px 0 0; color: #425466; font-size: 15px; font-weight: 400; line-height: 1.8; } .as-faq-question:focus-visible { box-shadow: inset 0 0 0 3px rgba(29, 128, 226, 0.25); border-radius: 16px; } @media (max-width: 767px) { .as-faq-list { gap: 12px; } .as-faq-question { gap: 14px; padding: 18px; } .as-faq-question-text { font-size: 15px; line-height: 1.45; } .as-faq-icon { flex-basis: 34px; width: 34px; height: 34px; } .as-faq-answer-content { margin: 0 18px; padding-bottom: 20px; } .as-faq-answer-content p { margin-top: 16px; font-size: 14px; line-height: 1.7; } } @media (prefers-reduced-motion: reduce) { .as-faq-item, .as-faq-icon, .as-faq-icon::before, .as-faq-icon::after, .as-faq-answer { transition: none; } } </style><div class="as-faq-list"><!-- FAQ 1 --><article class="as-faq-item"><button
 class="as-faq-question" type="button" aria-expanded="false" aria-controls="as-faq-answer-1"><span class="as-faq-question-text"> Who is responsible when an AI agent approves an invoice incorrectly? </span><span class="as-faq-icon" aria-hidden="true"></span></button><div class="as-faq-answer" id="as-faq-answer-1"><div class="as-faq-answer-inner"><div class="as-faq-answer-content"><p> The organization is, and specifically, the human owner of the agent and the authority that approved its thresholds. Yardi and MRI provide tooling and logs; they do not assume your control environment. Treat the agent's approval limit as a delegated authority from a named person. </p></div>
</div></div></article><!-- FAQ 2 --><article class="as-faq-item"><button
 class="as-faq-question" type="button" aria-expanded="false" aria-controls="as-faq-answer-2"><span class="as-faq-question-text"> Can AI agents in property management software violate segregation of duties? </span><span class="as-faq-icon" aria-hidden="true"></span></button><div class="as-faq-answer" id="as-faq-answer-2"><div class="as-faq-answer-inner"><div class="as-faq-answer-content"><p> Yes, in two ways: by collapsing capture, approval, and payment into a chain of agents configured by one person, and by inheriting an over-privileged human role. Map every agent's duty against your SoD matrix before enablement. </p></div>
</div></div></article><!-- FAQ 3 --><article class="as-faq-item"><button
 class="as-faq-question" type="button" aria-expanded="false" aria-controls="as-faq-answer-3"><span class="as-faq-question-text"> What is agent sprawl and why does it matter for Yardi and MRI users? </span><span class="as-faq-icon" aria-hidden="true"></span></button><div class="as-faq-answer" id="as-faq-answer-3"><div class="as-faq-answer-inner"><div class="as-faq-answer-content"><p> Agent sprawl is the uncontrolled growth of AI agents across an organization, each with system access and no clear owner. In property platforms, agents arrive through releases, marketplaces, and no-code builders rather than through IT, so sprawl happens faster and is harder to see. </p></div>
</div></div></article><!-- FAQ 4 --><article class="as-faq-item"><button
 class="as-faq-question" type="button" aria-expanded="false" aria-controls="as-faq-answer-4"><span class="as-faq-question-text"> How do I audit an AI agent in Yardi or MRI? </span><span class="as-faq-icon" aria-hidden="true"></span></button><div class="as-faq-answer" id="as-faq-answer-4"><div class="as-faq-answer-inner"><div class="as-faq-answer-content"><p> Maintain an agent register, keep the platform's action logs, run a regression test suite before go-live and after each release, and use process mining to compare actual production behavior against a pre-enablement baseline. Together, these produce evidence an external auditor can rely on. </p></div>
</div></div></article><!-- FAQ 5 --><article class="as-faq-item"><button
 class="as-faq-question" type="button" aria-expanded="false" aria-controls="as-faq-answer-5"><span class="as-faq-question-text"> What approval threshold should an invoice-approval agent start with? </span><span class="as-faq-icon" aria-hidden="true"></span></button><div class="as-faq-answer" id="as-faq-answer-5"><div class="as-faq-answer-inner"><div class="as-faq-answer-content"><p> Conservatively. Yardi's early clients ran Smart Approval at invoices up to $2,500. Start at or below your lowest human approval tier, add a cumulative-per-vendor limit, and loosen only on measured evidence after a quarter. </p></div>
</div></div></article><!-- FAQ 6 --><article class="as-faq-item"><button
 class="as-faq-question" type="button" aria-expanded="false" aria-controls="as-faq-answer-6"><span class="as-faq-question-text"> Do I need a kill switch for AI agents? </span><span class="as-faq-icon" aria-hidden="true"></span></button><div class="as-faq-answer" id="as-faq-answer-6"><div class="as-faq-answer-inner"><div class="as-faq-answer-content"><p> Yes. Know who can disable each agent, how long it takes, and what the manual fallback is for the workflow, especially at month-end. Test it once before you need it. </p></div>
</div></div></article><!-- FAQ 7 --><article class="as-faq-item"><button
 class="as-faq-question" type="button" aria-expanded="false" aria-controls="as-faq-answer-7"><span class="as-faq-question-text"> Should property companies ban third-party AI agents like Cisco did? </span><span class="as-faq-icon" aria-hidden="true"></span></button><div class="as-faq-answer" id="as-faq-answer-7"><div class="as-faq-answer-inner"><div class="as-faq-answer-content"><p> Most should not. A tiered approval process (native platform agents reviewed by the controller, custom and third-party agents reviewed by a cross-functional group) gives the benefit without the sprawl. </p></div>
</div></div></article></div><script>
    (function () {
      const faqSections = document.querySelectorAll(".as-faq-accordion");

      faqSections.forEach(function (section) {
        const items = section.querySelectorAll(".as-faq-item");

        items.forEach(function (item) {
          const button = item.querySelector(".as-faq-question");

          button.addEventListener("click", function () {
            const isOpen = item.classList.contains("is-open");

            /* Close all other FAQs */
            items.forEach(function (otherItem) {
              otherItem.classList.remove("is-open");

              const otherButton =
                otherItem.querySelector(".as-faq-question");

              otherButton.setAttribute("aria-expanded", "false");
            });

            /* Open selected FAQ if it was closed */
            if (!isOpen) {
              item.classList.add("is-open");
              button.setAttribute("aria-expanded", "true");
            }
          });
        });
      });
    })();
  </script></section></div>
</div><div data-element-id="elm_7jHmxFfaTDmwlMN8hpEEeg" data-element-type="button" class="zpelement zpelem-button " data-animation-name="bounceIn" data-animation-repeat="true"><style></style><div class="zpbutton-container zpbutton-align-center zpbutton-align-mobile-center zpbutton-align-tablet-center"><style type="text/css"></style><a class="zpbutton-wrapper zpbutton zpbutton-type-primary zpbutton-size-md zpbutton-style-none " href="/contact-us" target="_blank"><span class="zpbutton-content">Get Started Now</span></a></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Thu, 01 Oct 2026 12:30:54 -0500</pubDate></item></channel></rss>