Finance agents: 5 use cases
Agents that move money-adjacent records between ServiceNow, Salesforce and Atlassian. The risk is rarely the task — it is the standing grant behind it.
ServiceNowSalesforceHubSpotAtlassian Each step lists the resource and the exact permission or role the agent uses.
AP invoice-to-pay three-way match
- TriggerNew vendor expense line lands in ServiceNow
- ServiceNow1Read expense line
servicenow:fm_expense_line · role:itil - ServiceNow2Validate vendor
pc_vendor_cat_item, vendor_type · role:public - Salesforce3Match PO / receipt / invoice
Order: PermissionsRead · Invoice: PermissionsRead, PermissionsEdit - Atlassian4On mismatch, open AP-exception request
write:request:jira-service-management - ParapetEdit-only, on the matched record. Modify-all is denied.Deny excess
The agent actually holds PermissionsModifyAllRecords on Invoice — far broader than a three-way match needs. Discovery surfaces the gap between "itil on expense lines" and "modify-all on every invoice in the org."
Contract-to-billing kickoff
- TriggerSalesforce Contract status flips to Activated
- Salesforce1Read Contract
Contract: PermissionsRead - Salesforce2Create Order
Order: PermissionsCreate - Salesforce3Edit first Invoice
Invoice: PermissionsEdit - ServiceNow4Mirror milestone to contract records
ast_contract, ast_contract_instance · role:public - ParapetServiceNow contract writes fire only with matching Salesforce Contract authority.Gate / review
A purely financial agent could write ServiceNow contract instances with no Salesforce-side authorization behind the action. Parapet ties the two together.
Fixed-asset lifecycle & depreciation sync
- TriggerSalesforce Asset created after PO receipt
- Salesforce1Create Asset
Asset: PermissionsCreate - ServiceNow2Track retirements
asset_reclamation_request · role:public - Salesforce3Update Asset status
Asset: PermissionsEdit - ServiceNow4File change request if IT-managed
change_request · role:public - ParapetUnused change_request write path revoked.Deny excess
The agent’s write reach outruns its purpose: it can file real infrastructure change_request tickets though its job is asset bookkeeping. Parapet inventories and revokes the unused path.
Vendor onboarding & procurement compliance
- Triggersc_request / sc_req_item raised against the vendor-onboarding catalog item
- ServiceNow1Intake request
sc_request, sc_req_item · role:public - ServiceNow2Validate vendor
vendor_type, pc_vendor_cat_item · role:public - Salesforce3Create vendor Account
Account: PermissionsCreate - Atlassian4Route to Legal / Finance approval
write:request:jira-service-management - ParapetShared-identity inheritance flagged; role must be held by the agent’s own account.Gate / review
sc_cat_item needs catalog_manager. Parapet checks the agent’s own service account holds it directly, rather than inheriting it from a shared integration user also used by HR’s benefits catalog (HR5) — one over-privileged bot silently spanning two departments.
Month-end close checklist automation
- TriggerScheduled month-end job
- Salesforce1Read AR aging
Invoice, Order: PermissionsRead, PermissionsViewAllRecords - ServiceNow2Pull AP accruals
fm_expense_line · role:itil - Atlassian3Publish close checklist
write:page:confluence - ParapetTime-boxed grant; auto-revoked after publish.Allow, time-boxed
PermissionsViewAllRecords is the riskiest standing grant for a non-human identity. Parapet time-boxes it to the close window and auto-revokes once the checklist is published.
See what your agents actually hold.
Discover, inventory and enforce across every connected SaaS system.