For as long as I can remember, advisory firms have wanted their systems to talk to each other properly. That hope is old, it is reasonable, and AI has intensified it, perhaps further than it should have. I think that explains most of the reaction to Claude for Financial Advisors at Future Proof, which was out of proportion to what actually shipped.
The capability itself is welcome. We built the Sentir MCP and optimized it for Claude, so this is not a complaint about the technology. Anthropic should be applauded for raising the bar and for pulling attention toward our industry.
But they are connectors, not integrations, and that difference is the subject of this piece. It also raises the stakes on the three governance properties we wrote about here in July. Auditability, permissioning, and policy enforcement are comparatively easy to satisfy inside one system, and connectors are by definition the business of crossing systems.
Our industry already has a shorthand for this kind of problem. AAA is the rating that says an obligation will be met, verifiably, under stress. Not that it probably will be met. That it can be shown to have been.
So borrow the letters. Auditable Agentic Autonomy is the standard your stack is about to be held to.
What does auditable agentic autonomy mean?
Auditable Agentic Autonomy is the ability to let software act on the firm’s behalf and afterward reconstruct, from records the firm itself controls, what was done, on what basis, and under whose authority.
The words are ordered on purpose. Autonomy is the capability. Agentic describes its shape, software that reasons over context, chooses a course of action, and carries it through. Auditable is the constraint, and it is the only one of the three that decides whether the other two are usable in a regulated business.
Read backward it stops being a label and becomes a test. Can you audit it? Then you can let it act. Then you can extend it autonomy.
Why is an AI connector different from an integration?
An AI connector reaches across systems, while an integration holds the record inside them. The model behind a connector responds when asked, in the moment. When the moment ends, it keeps no memory of what it concluded and no record of having concluded it.
You can build agents in that layer, and people will. They still sit outside the core systems and depend on them for everything that matters. The swivel chair stays. Someone else is just sitting in it.
That is a fine trade for research and drafting. For anything a firm has to stand behind later, it is a poor one, because a layer that keeps no memory can’t be where your record lives.
Where does the AI audit trail stop?
The AI audit trail stops at the edges between systems. Every system in the chain logs what happens inside itself, while the connector layer doing the reasoning between them logs almost nothing about that reasoning.
Take the announced controls seriously, because they are real. Access is controlled per user, account and Social Security numbers are masked, Schwab’s release describes audit logs for admins, and training on client data is prohibited.
Then read Anthropic’s own documentation on what those audit logs contain. They are available to Enterprise organizations only, and they capture events such as a user signing in, a project being created, and a file being uploaded. The titles and contents of chats and projects are explicitly not exported in them, only their identifiers.
That is a sensible design for an enterprise software log. It is not a record of advice. Your custodian logs the read. Your CRM logs the write. The layer in between logs that a project existed.
James Cantwell read the repository rather than the press release, which more of us should have done, and his findings sharpen it further. The safeguards that matter most, including getting advisor approval before anything is written back to a client system, are enforced by the model following its instructions rather than by the runtime enforcing them. He also flags the failure mode I would lose sleep over, which is that the screen that used to make an advisor pick the right household record is gone and the prompt now has to find it. Anthropic’s own skill calls pulling the wrong household’s data a privacy incident. Quite right.
An instruction is not a control.
Why is a fragmented AI stack riskier than an autonomous one?
Because autonomy is governable inside one system and close to ungovernable across four. Deloitte’s 2026 sector work found 5% of advisory firms have cross-system AI integration. Almost everybody deploying AI is deploying it in pieces.
Here is a path that is already ordinary. A notetaker joins a client review and produces a summary. An assistant reads that summary and drafts CRM updates and a follow-up email. Someone in operations reads the same summary, concludes the client’s circumstances have changed, and triggers a workflow that reassigns a service tier.
Now run it forward six months, when the client disputes what was agreed. Rule 204-2 asks you to retain the records supporting that advice for five years. The transcript sits with one vendor on its own retention schedule. The summary everything depended on may have been edited since. The reasoning behind the email does not exist anywhere. Your CRM shows the end state without the input that justified it. The workflow logs who clicked, which is the cleanest evidence in the chain and the least useful piece of it.
Nobody behaved improperly. The firm simply cannot show that.
What happens to your audit record if the vendor disappears?
It becomes your problem, because the obligation was always yours. Rule 204-2 sits with the adviser regardless of who happens to be holding the file.
Worth sitting with, because a good deal of the new AI tooling in our space is narrow and sub-scale. Single-feature companies, one funding round in, selling into a market that is consolidating around them. Some will be acquired and absorbed, some will be quietly folded into a larger stack, and some will simply stop. That is not a criticism of any of them. It is what happens to a category with this many entrants.
The SEC saw the shape of this. Its 2022 outsourcing proposal would have required advisers to obtain reasonable assurances that arrangements exist to keep records available if a third party ceases operations or the relationship ends. The Commission withdrew that proposal in June 2025, along with thirteen others. The question is still live, and there is now no rule telling you how to answer it.
So ask it at the point of purchase rather than at the point of failure. If this vendor is gone in eighteen months, what do I still hold? If the honest answer is a login that stops working, the record was never yours.
How do you test whether your stack is AAA ready?
Run a reconstruction test. Take one client-affecting action from last quarter that an AI tool touched somewhere along the way, and rebuild it end to end using only records your firm controls. Give it an hour.
You are looking for five things. The source material, the interpretation drawn from it, the action that interpretation produced, the person who authorized that action, and timestamps that put them in order. Whatever you cannot assemble in an hour you will not assemble for an examiner, and you certainly will not assemble it for opposing counsel two years from now.
The vendor conversation follows from the same exercise. Ask where the reasoning is written down and whether it survives the handoff. Ask whether an approval is enforced by the software or requested in an instruction.
Where this leaves the buying conversation
The evolution firms actually need comes from inside the core systems they already use every day. Not static rules rebadged as agents by vendors leaning on misunderstood terminology, but software that reads millions of rows and raises the risk or the opportunity without anyone asking it to, acting where it acts with the operational and compliance controls already around it.
I am plainly an interested party, so weigh that accordingly. We built Sentir on the position that the reasoning and the record belong in the same place, and the Sentir MCP exists because connectors have a real role alongside that rather than instead of it. They have not replaced the need for high-quality API integration between core systems, and they will not.
Whatever you run today, the reconstruction test costs an hour of your operations lead’s time. Worth doing before somebody else asks the question.
Want to see what an auditable agent workforce looks like in practice?
With Sentir, our AI-native CRM, the AI functionality is built directly into the CRM.
Schedule a demo to learn more.


