The Clearinghouse For AI Agents Has A Blind Spot

Jamin Ball’s recent piece, “Systems of Record Won the SaaS Era — Clearinghouses Will Win the Agents Era,” is the cleanest articulation I’ve seen of where the durable moat goes next. His argument is simple and, I think, correct: the SaaS era rewarded whoever owned the system of record, and the agent era will reward whoever owns the clearinghouse. This is a new seat that sits between mutually-distrusting agents and decides which one is cleared to act, on what data, with what limits, and can prove what happened after the fact. The lock-in moves from your data to your permissions. The source-of-truth era becomes the source-of-permission era.

 

I agree with all of it. Governance has graduated from a compliance checkbox at the end of the sales cycle to the first question a CIO asks. Once agents act autonomously and eventually spend real money, “is the model good?” stops being interesting now that every model is good enough and “can I see what every agent did, set policy on what it can touch, and prove it to my auditors?” becomes the whole conversation. That seat is strategic real estate. Whoever holds it is hard to dislodge.

 

But there’s an assumption buried in the clearinghouse metaphor that’s worth dragging into the light, because the entire model rests on it.

A clearinghouse only clears what comes to it

In financial markets the metaphor works because participation is mandatory. You cannot settle a trade on a regulated exchange without going through the clearinghouse. The seat is powerful precisely because there is no path around it. Every transaction is, by construction, a transaction that presents itself for clearing.

 

Agents are not like that. Nothing about the architecture forces an agent to route its actions through a governance seat. An agent calls a model endpoint directly. It opens a connection to a tool server that someone stood up last week. It talks to another agent over a side channel or a message board as in the Hugging Face attack. A developer spins up an autonomous workflow in a corner of the infrastructure that the platform team has never inventoried. None of that traffic announces itself at the toll booth. And the receipt the clearinghouse keeps is, by definition, a record only of the transactions that came to the desk.

 

This is the gap. The clearinghouse is an on-path construct, it governs the actions that pass through it. But in a real enterprise, the actions you most need to govern are frequently the ones that don’t. The shadow agent nobody registered. The model call that skipped the gateway. The agent-to-agent handoff that never generated a clearing event. A governance model that only sees submitted transactions is blind to exactly the population that represents the risk.

 

Every example in Jamin’s framing, the data platforms winning “from below,” the productivity suites winning “from above” assumes the agent shows up to be cleared. The most dangerous agents are the ones that never do.

Source of permission needs a source of truth

So the clearinghouse seat, as described, is necessary but not sufficient. To actually hold it, you need something underneath it that the metaphor skips over: an independent source of truth about what agents are doing, whether or not they chose to clear through you.

 

Four capabilities make that real, and none of them are “clearing” in Jamin’s sense.

 

The first is off-path visibility. You need to observe agent traffic at a layer the agent can’t opt out of, that is the network and runtime substrate the workload actually executes on, so that the calls that bypass the gateway are still seen. A receipt tells you what cleared. Visibility tells you what happened. Those are different data sets, and the difference between them is your risk surface.

 

The second is discovery. The clearinghouse clears the agents that present themselves; it does not go find the ones that didn’t. You need to enumerate the agents running in your environment without relying on them to register, because the unregistered ones are the point.

 

The third is behavioral sensing. Clearing is transactional: permit or deny, one action at a time. But a single permitted action can be perfectly legitimate while a sequence of them is an exfiltration pattern. You need continuous analysis of what an agent does over time, not just a verdict at each gate.

 

The fourth is identity issuance, not just verification. A clearinghouse authorizes a credential at the door. But in a multi-hop agent world where agent calls agent calls tool calls model, you need every hop to carry attributable, minted identity, so the audit trail Ball rightly prizes is actually trustworthy end to end rather than a chain of “trust me” assertions.

Where I’d draw the line

I want to be careful not to overclaim the inverse, either. The clearinghouse thesis gets two things exactly right that the visibility layer does not replace. Owning memory, what agents know and context, what they see and how it’s served, is a genuinely strategic seat, and it belongs to the data players. A visibility-and-governance layer governs access to those things; it doesn’t store them, and it shouldn’t pretend to. The division of the map is this: the data platforms own memory and context, and the governance layer owns permission, enforcement, and the source of truth about behavior.

 

And the multi-vendor angle Jamin references, “the clearinghouse across clearinghouses,” the neutral seat that no incumbent can credibly occupy because Microsoft will never neutrally govern Salesforce’s agents — is the most valuable position of all, but it’s also the least mature. Neutrality is easy to assert and hard to ship, especially across the messy reality of where agents actually run today. Anyone claiming it now is selling a roadmap.

The reframe

So here’s where I land. Jamin is right that the moat moves from the system of record to the clearinghouse, and from your data to your permissions. But a permission you can’t enforce on traffic you can’t see is a permission in name only. The source-of-permission era doesn’t replace the source of truth, rather it depends on one. The seat goes to whoever can both decide what an agent is allowed to do and independently observe what it actually did, including all the times it never asked.

 

The clearinghouse is the right metaphor. It just needs eyes outside the building.

 

Written by Alain Mayer

Join our mailing list

Get updates on blog posts, workshops, certification programs, new releases, and more!

X