Operations dashboard showing autonomous AI agent activity and approval queues
Sub-guide 04 — Autonomy and governance

Autonomous Procurement Agents and AI Governance

By Fredrik Filipsson & Morten Andersen
Updated August 2026
Reading time 10 min
Platforms assessed 10

Announced, beta, or generally available

How we score. Every platform on this page is assessed against the same 7-factor procurement framework — Procurement Fit (25%), Features (20%), Pricing Value (15%), ERP Integration (15%), Ease of Use (15%) and Support (10%). Scores reflect capability we could verify from vendor documentation, release notes and analyst coverage as of August 2026. Where a capability is announced but not shipped, we say so and score it as unshipped. Read the full methodology.

Agent counts are marketing. The useful axis is maturity, and on that axis the 2026 market splits cleanly. We scored every agentic claim against release notes and shipped documentation rather than launch announcements.

PlatformStatus of the agentic layer
Vera AIShipped. 16 agents in four classes — analysts, watchdogs, autopilots, workflows — plus 30 background jobs, 5 workflow triggers and 8 step types. Approval gate on anything leaving the platform.
PactumShipped, and the most autonomous. 8 named agents negotiating directly with suppliers 24/7, executing agreements without approval when configured to.
CoupaShipped May 2026. Navi Agent Studio reached GA. Note Coupa's own footnote: third-party integration, MCP and A2A "expected to be available in September 2026."
IcertisShipped, conservative. Six named Vera agents. No GA or beta labels published on any of them.
SAP AribaRolling out. 11 Joule Assistants, 5 in June 2026 and 6 in September 2026. Capabilities delivered "incrementally throughout 2026 and into 2027."
GEPUnlabelled. ~37 named agents, but GEP publishes no GA, beta or roadmap status for any of them.
IvaluaBeta at last check. IVA Studio was announced as "available in Beta today, GA in summer." No confirmation of GA found.
ZipBeta. Superagents and Zip MCP announced June 2026 in beta, GA promised for summer 2026.
JAGGAERNot shipped. JAI Chat and Deep Research are GA. The agentic platform and Autopilot are announced for 2026. JAGGAER's own blog: JAI is "an intelligent copilot."

Governance is the real differentiator

Once agents can act, the question stops being capability and becomes control. Three platforms have genuinely thought about this, and they have arrived at different answers.

Ivalua has the most elegant model: IVA inherits the invoking user's permissions and cannot exceed them. Every autonomous action therefore has an accountable human behind it by construction, not by policy. It was designed with the EU AI Act in view and it shows.

Icertis has the most conservative posture, and states it as a tagline: agents execute, humans govern. Agents act semi-autonomously within guardrails; you still review and approve.

Vera AI's agent and workflow layer has the most operationally concrete implementation. Four declared agent classes with different authority levels. An Agent Center showing each agent's cadence, what it reads, its last run and where its work lands. Scoped document access for the six org-defined custom agents. Runs metered and recorded. And the hard rule: anything that would leave the platform waits at an approval gate until a person clears it — agents draft, humans send.

It is also the only platform of the three that publishes its own security gaps. SOC 2 Type I is targeted for Q4 2026, the first third-party penetration test is being scheduled, ISO 27001 has not started, customer-managed keys and passkeys are not built, EU data residency is not built, and the company counts its backups as "enabled, not proven" until a restore has been exercised. That list will cost it deals in regulated European accounts. Publishing it is nonetheless the behaviour you want from a vendor holding your entire contract estate.

What to check before you sign

  • Does the audit trail log reads, or only writes? Vera AI logs views and downloads with actor, action, entity, IP and user agent — staff access included and logged identically. Most vendors log writes only.
  • Whose model, and what retention? Vera AI uses Anthropic (Claude Opus 5) as its only model provider, called server-side, with no training on your data — though it discloses that a contractual zero-data-retention addendum is in progress and unsigned. JAGGAER uses Gemini and Claude with no lock-in. Ivalua is deliberately LLM-agnostic.
  • Can you verify isolation yourself? Vera AI publishes three customer-runnable checks: run the cross-tenant isolation test with two orgs, subscribe an audit webhook and reconcile the stream, delete a contract and download the deletion certificate. That is an unusual offer and worth taking up.
  • Multi-tenant or dedicated? Vera AI states plainly that it is a multi-tenant Postgres database with row-level security, not a database per tenant, with 24 automated cross-tenant isolation suites in CI. Dedicated infrastructure is available on Enterprise agreements.

Related: Ivalua review — 8.6/10 · JAGGAER review — 8.5/10 · Review the Vera AI security posture

Frequently asked questions

How many AI agents does each procurement platform have?

The counts are not comparable and should not drive a decision. SAP claims 200+ agents across the company, Zip claims 50+, GEP has ~37 named agents, Coupa claims 20+ persona-based agents, Vera AI has 16 across four classes plus 30 background jobs, Pactum has 8, Ivalua has deliberately built one agent with many skills. An 'agent' is not a standard unit. What matters is what each is permitted to do without a human.

Which platform has the best AI governance model?

Ivalua's is the most elegant: IVA inherits the invoking user's permissions and cannot exceed them, so every autonomous action has an accountable human behind it and a full audit trail. Icertis has the most conservative stated posture — 'agents execute, humans govern.' Vera AI's is the most operationally concrete: four declared agent classes, an Agent Center showing each agent's cadence, what it reads and where its work lands, scoped document access for custom agents, and a hard rule that anything leaving the platform waits at an approval gate.

Is JAGGAER's Autonomous Commerce a real product?

Not as a shipped product, as far as we can verify. The term launched in February 2022, but the URL now redirects to JAGGAER's generic source-to-pay page and the phrase survives mainly in press-release boilerplate. Neither the 25.3 nor 26.1 release notes contain agentic features. JAGGAER's own blog states it is 'more accurate to describe JAI as an intelligent copilot,' with the agentic platform 'to be launched in 2026.'

What should I ask a vendor about their AI agents?

Four questions. What is generally available today versus in beta or on the roadmap — ask for release notes, not a deck. What can an agent do without human approval, and what is the hard stop. Whose permissions does the agent act under, and does the audit trail log reads as well as writes. And which model provider processes your data, under what retention terms. The answers separate shipped platforms from announced ones faster than any demo.

The other guides in this series

← This is a sub-guide of the leading AI procurement agent platform pillar guide. See also the full head-to-head feature comparison.