
Internal Office Agents: Which HR, IT, and Finance Steps Can Auto-Run vs Need an Approver
An internal office Agent runs on the employee side: HR policy, IT tickets, finance expenses. It is fit for duty only when every step is labeled auto / draft-for-approval / must-have-an-approver—not because the model chats better. It is not the digital-employee vs RPA taxonomy (/blog/what-is-digital-employee-vs-custom-agent) and not how to slice a RAG corpus (/blog/enterprise-rag-knowledge-base-agent). Who owns the project: /blog/custom-agent-project-owner-raci—that is kickoff governance, not the approver on a leave form. Identity-sliced Feishu assistants: /blog/private-domain-wecom-feishu-agent. GeonAI delivers per-step gates; /agents are capability references only (not a public trial of 363+ presets). Email [email protected].
One-sentence definition
An internal office Agent = HR / IT / finance steps written in three bands: read-only auto, draft-for-approval, irreversible human. Bundling “ask the policy” and “post the ledger” on one auto switch is an overreach.
Not Copilot, not a KB, not RPA
| Shape | Typical action | Covered here |
|---|---|---|
| Office Copilot | Personal drafts, meeting notes | No; no external promises, no business-system writes |
| KB RAG | Cited policy Q&A | Q&A layer: KB post. This post: whether it may act afterward |
| RPA | Deterministic clicks on a stable UI/API | Postings stay RPA; see the digital-employee split |
| Internal office Agent | Slot-fill, draft tickets, stop at the approver | Yes: three-band step tables |
HR: what can auto-run
| Step | Default band | Notes |
|---|---|---|
| Leave / benefits / onboarding FAQ (versioned policy) | Auto | Filter retrieval by employee identity; refuse without a snippet |
| Leave request slot-fill, draft form | Draft-for-approval | Read-only balance checks OK; submit still uses the existing flow |
| Job-post / onboarding-checklist drafts | Draft-for-approval | External publish needs the recruiting Owner |
| Offer send, compensation change, termination | Must-have-an-approver | Agent must not send or write pay master data |
| Payroll run | Must-have-an-approver + finance dual control | The model must not click payroll |
IT: what can auto-run
| Step | Default band | Notes |
|---|---|---|
| Known-error / VPN / password-policy FAQ | Auto | Read-only; password reset stays IdP self-service, not a guessed password |
| Ticket classify, fill fields, route to a queue | Auto (once stable) | Sample misroutes; high-risk queues stay human |
| Standard access-request draft | Draft-for-approval | Manager / app Owner signs; IT executes |
| Prod / domain-admin / firewall change | Must-have-an-approver | Two-person review; Agent only drafts the change |
| Delete accounts, shut down prod resources | Must-have-an-approver | Irreversible; no auto-execute |
Finance: what can auto-run
| Step | Default band | Notes |
|---|---|---|
| Expense-policy / invoice-header FAQ | Auto | Cite the policy doc ID |
| Extract invoice fields into an expense draft | Draft-for-approval | Amount and GL need a human; over threshold always human |
| Vendor master create / change bank details | Must-have-an-approver | Stops fraud account swaps |
| Payment, GL posting, close | Must-have-an-approver or RPA + human gate | Do not let an LLM click post; see the digital-employee post |
| Explaining products to customers | Out of scope | See /blog/financial-services-agent-compliance |
Writes go through an allowlist gateway: /blog/agent-function-call-mcp-integration. Contract tables: /blog/custom-agent-scope-boundary-in-contract. Pay bands and account secrets still need data classification: /blog/enterprise-ai-compliance-overview.
Decision rules
- Start with policy Q&A + leave/expense drafts: read-only knowledge; keep the existing approval flow
- Customize before any write: field allowlist, amount/day thresholds, where approvers are read (HRIS / IdP)
- Do not auto-run payroll, prod access, or payment
- Do not pass a Copilot seat off as this Agent: personal drafts have no approval gate or audit fields
Anti-patterns (stop the project)
- The Agent sends offers or writes compensation
- The Agent grants domain-admin or prod access
- The Agent posts the GL or pays a vendor
- Dumping the whole HR wiki into an all-hands bot
- Treating 363+ presets as HRBP or shared-service finance seats
Pilot acceptance
- Irreversible acts (payroll, payment, prod access, pay change) with no human record = 0
- Policy Q&A sample: no citation or leaked pay bands = 0
- Share of drafts voided in full by the approver has a baseline (too high means slots/policy are misaligned)
- Shadow approval outside HRIS / ITSM / expense systems = 0
Do-no-harm metrics: /blog/custom-agent-30-day-pilot-metrics. Do not invent person-year savings as a kickoff number; formula templates: /blog/ai-agent-roi-calculator.
How to brief GeonAI
List 5–10 steps per HR / IT / finance band; name the HRIS, ITSM, and expense systems and where approvers are read. Email [email protected], /pricing, or Live chat. First-call pack: /blog/how-to-brief-ai-agent-vendor. We accept on step gates—we do not promise fully automatic internal work with nobody approving.
Frequently asked questions
We already have Microsoft 365 / Feishu Copilot. Do we still need this Agent?
Copilot covers personal drafts. Filling leave forms, granting access, running expense approval, and keeping an audit trail need the three bands and a write allowlist—not another chat window.
How is this different from the RAG knowledge-base post?
That post covers retrieval, permission filters, and citations. This one covers which steps after Q&A may auto-run and which need an approver. Without RAG ACL, HR compensation policy leaks to the wrong people.
How is this different from the digital-employee / RPA post?
That post splits RPA, generic assistants, and custom Agents by lane. This one turns HR/IT/finance into executable step tables with an approver gate. It does not redefine the categories.
If remaining annual leave covers the request, can the Agent auto-approve?
Only when the rule is fully table-driven (balance, blackout dates, delegate) and HR has authorized a short path in writing. Default: draft into the existing flow. Even auto-approve must be replayable.
Is internal finance the same as the financial-services compliance post?
No. This post is employee expenses and posting gates. Explaining wealth or credit products to customers is the FS compliance post—do not mix it into the expense Agent.
Can the 363+ presets staff an HRBP or shared-service finance seat?
No. Presets do not include your HRIS fields, approver routing, amount thresholds, or irreversible-action bans.