cvtoken.vip

Council Post: The Expiring Enterprise: Why Every App, Agent And Automation Needs A Half-Life

Akhilesh Sharma, Founder & CEO, A3logics—20+ years in digital transformation, AI & EDI. Firsthand insight into AI-augmented workplaces.getty​Enterprise technology usually fails in visible ways: an outag...

Akhilesh Sharma, Founder & CEO, A3logics—20+ years in digital transformation, AI & EDI. Firsthand insight into AI-augmented workplaces.

getty

​Enterprise technology usually fails in visible ways: an outage, a security incident or a project that never delivers. A quieter risk is emerging as AI, low-code platforms and automation make software easier to create. Applications and workflows can continue operating long after their original purpose, owner or assumptions have disappeared.

One recurring pattern I’ve observed in digital transformation work is that the technology often survives the organizational context that justified it. An employee might change roles, a department might redesign a process or an integration might gain new dependencies. However, the automation continues to use valid credentials and make technically permitted decisions.

The enterprise technology crisis won’t come from employees building too much but from allowing everything they build to live forever.

From Approval To Expiration

Most governance concentrates on creation. Teams register an application, assign an owner, approve its access and send it into production. Those controls answer whether the technology was acceptable when it launched but don’t establish whether it deserves to remain active six or 12 months later.

Inventories help, but an inventory can become a catalog of abandoned intentions. Named ownership also decays when people move between teams. Even correctly scoped permissions can become excessive as the surrounding process changes.

The missing control is expiration. Every application, AI agent, automation and integration should receive a time-to-live when it’s created. At the end of that period, its continued operation should depend on evidence that its purpose, ownership, permissions and outcomes remain valid.

Creation can be decentralized. Persistence should have to earn renewal.

Build The Half-Life Into The Life Cycle

Expiration begins at birth. Each technology asset needs a named owner, a declared business purpose and a permission envelope defining which systems, data and actions it may access. “Owned by finance” is insufficient. Accountability must reach a person with the authority to renew, restrict or retire it.

During operation, the asset needs usage and outcome telemetry. Usage answers whether anybody still depends on it. Outcome monitoring asks whether it continues producing the result it was designed to deliver. This distinction matters because a frequently used automation can still be creating inaccurate decisions or unnecessary work.

Post-deployment monitoring is especially important for AI systems. A 2026 NIST report identified performance degradation, fragmented logging and uncertainty around monitoring cadence as continuing challenges. An asset can’t earn renewal if leaders can’t see what it’s doing.

The time-to-live should reflect consequence. A personal workflow without sensitive access might receive an annual review. A departmental automation might be reviewed every six months. A customer-facing application may need quarterly re-attestation. An agent that can modify production, financial or customer data may require monthly or quarterly review supported by continuous monitoring.

Make Renewal Evidentiary

Re-attestation shouldn’t become another checkbox. The owner should demonstrate continuing usage, acceptable outcomes, current permissions, understood dependencies and a justified cost-to-operate. The review should also confirm that incident history has been examined and that the kill switch still works.

Permission renewal deserves particular attention. CISA’s 2025 security capabilities guidance calls for maintaining a current inventory of user and entity permissions and authorizations. For an automation, renewal should ask more than whether it still has access. Ask whether you would grant this access again today.

The primary executive metric should be orphaned-technology exposure: the percentage of active assets without a recently validated owner, purpose and permission envelope. Supporting measures can include revocation time, evidence-backed renewal rates and the operating capacity recovered through retirement.

Retire Without Breaking The Business

Expiration can’t mean indiscriminate deletion. Other systems may depend on an automation without appearing in its original documentation. Retirement should be staged; stop accepting new work, observe downstream calls, notify dependent teams, withdraw permissions progressively, preserve required records and maintain a rollback checkpoint.

The U.K. National Cyber Security Centre has advised organizations to consider decommissioning at the beginning of an asset’s life cycle, not only at the end. That changes the kill switch from an emergency feature into a designed operating capability.

The strongest objection is bureaucracy. If a personal spreadsheet workflow receives the same review as an agent with production write access, the framework will slow useful experimentation. Risk tiers and automated evidence collection keep the burden proportional. Governance should become stricter only as potential consequences increase.

Innovation is no longer constrained by the ability to build. The next leadership challenge is deciding what deserves to remain alive. In an expiring enterprise, technology persists because an accountable owner can prove that it still creates value within boundaries the organization is willing to defend.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?