Home › Use cases › Finance
CFO · GL, AP, AR

Finance agents: 5 use cases

Agents that move money-adjacent records between ServiceNow, Salesforce and Atlassian. The risk is rarely the task — it is the standing grant behind it.

ServiceNowSalesforceHubSpotAtlassian Each step lists the resource and the exact permission or role the agent uses.

F1

AP invoice-to-pay three-way match

  1. TriggerNew vendor expense line lands in ServiceNow
  2. ServiceNow1Read expense lineservicenow:fm_expense_line · role:itil
  3. ServiceNow2Validate vendorpc_vendor_cat_item, vendor_type · role:public
  4. Salesforce3Match PO / receipt / invoiceOrder: PermissionsRead · Invoice: PermissionsRead, PermissionsEdit
  5. Atlassian4On mismatch, open AP-exception requestwrite:request:jira-service-management
  6. ParapetEdit-only, on the matched record. Modify-all is denied.Deny excess
Why Parapet

The agent actually holds PermissionsModifyAllRecords on Invoice — far broader than a three-way match needs. Discovery surfaces the gap between "itil on expense lines" and "modify-all on every invoice in the org."

− granted: Invoice: PermissionsModifyAllRecords
+ needed: Invoice: PermissionsEdit on the matched record
F2

Contract-to-billing kickoff

  1. TriggerSalesforce Contract status flips to Activated
  2. Salesforce1Read ContractContract: PermissionsRead
  3. Salesforce2Create OrderOrder: PermissionsCreate
  4. Salesforce3Edit first InvoiceInvoice: PermissionsEdit
  5. ServiceNow4Mirror milestone to contract recordsast_contract, ast_contract_instance · role:public
  6. ParapetServiceNow contract writes fire only with matching Salesforce Contract authority.Gate / review
Why Parapet

A purely financial agent could write ServiceNow contract instances with no Salesforce-side authorization behind the action. Parapet ties the two together.

− granted: Write on ast_contract with no upstream authorization
+ needed: ast_contract writes only when the same identity is authorized on the triggering Contract
F3

Fixed-asset lifecycle & depreciation sync

  1. TriggerSalesforce Asset created after PO receipt
  2. Salesforce1Create AssetAsset: PermissionsCreate
  3. ServiceNow2Track retirementsasset_reclamation_request · role:public
  4. Salesforce3Update Asset statusAsset: PermissionsEdit
  5. ServiceNow4File change request if IT-managedchange_request · role:public
  6. ParapetUnused change_request write path revoked.Deny excess
Why Parapet

The agent’s write reach outruns its purpose: it can file real infrastructure change_request tickets though its job is asset bookkeeping. Parapet inventories and revokes the unused path.

− granted: Write on change_request
+ needed: Asset create/edit, retirement tracking
F4

Vendor onboarding & procurement compliance

  1. Triggersc_request / sc_req_item raised against the vendor-onboarding catalog item
  2. ServiceNow1Intake requestsc_request, sc_req_item · role:public
  3. ServiceNow2Validate vendorvendor_type, pc_vendor_cat_item · role:public
  4. Salesforce3Create vendor AccountAccount: PermissionsCreate
  5. Atlassian4Route to Legal / Finance approvalwrite:request:jira-service-management
  6. ParapetShared-identity inheritance flagged; role must be held by the agent’s own account.Gate / review
Why Parapet

sc_cat_item needs catalog_manager. Parapet checks the agent’s own service account holds it directly, rather than inheriting it from a shared integration user also used by HR’s benefits catalog (HR5) — one over-privileged bot silently spanning two departments.

− granted: catalog_manager inherited from a shared integration user
+ needed: catalog_manager held directly by this agent identity
F5

Month-end close checklist automation

  1. TriggerScheduled month-end job
  2. Salesforce1Read AR agingInvoice, Order: PermissionsRead, PermissionsViewAllRecords
  3. ServiceNow2Pull AP accrualsfm_expense_line · role:itil
  4. Atlassian3Publish close checklistwrite:page:confluence
  5. ParapetTime-boxed grant; auto-revoked after publish.Allow, time-boxed
Why Parapet

PermissionsViewAllRecords is the riskiest standing grant for a non-human identity. Parapet time-boxes it to the close window and auto-revokes once the checklist is published.

− granted: Standing ViewAllRecords on Invoice & Order
+ needed: ViewAllRecords only during the close window

See what your agents actually hold.

Discover, inventory and enforce across every connected SaaS system.