Dex
8 min readBy Dean Craftsman

What a CIO's AI Buying Committee Actually Asks (And Who Kills the Deal)

Agentic IT deals stall in the buying committee, not the demo. The four seats that review the purchase, what each asks, and the proof that answers it.

Most agentic IT purchases do not die in the demo. They die three weeks later, in a thirty-minute internal review you are not invited to, when someone from a function that never saw the product asks a question your champion cannot answer. The product was never the problem. The relay was.

An agentic IT purchase is unusually exposed to this because it touches four domains at once. It executes changes in production Microsoft 365, so Security reviews it. It replaces labor with usage-based cost, so Finance models it. It absorbs work the team currently owns, so IT operations judges it. It is a new vendor with production access, so Procurement scrutinizes it. Four lenses, four different questions, four different ways to stall the deal. This post maps all four, names the one question each seat actually asks, and gives you the specific, verifiable proof that answers it - so your champion walks into that room already carrying the evidence.

The committee is a relay, not an audience

The evaluation and the decision are two separate events with two different casts. You run the evaluation with the IT champion: they see the product work, they ask the sharp technical questions, they leave convinced. Then they go build the internal case, and every other reviewer gets the product secondhand, filtered through a summary written by someone who was excited.

That filter is where deals are lost. A champion's case is built in the language of their own seat - queue volume, resolution rate, engineer hours recovered. It is a strong case for IT operations and a weak one for everybody else, because it answers a question the other three seats did not ask. Security does not care about queue volume. Finance does not care about resolution elegance. Procurement cares about neither.

The practical consequence: the quality of your deal is not the quality of your demo. It is the quality of the evidence your champion can hand to three people who never met you.

One decision, four lenses

Four-lens agentic IT buying committee: champion, security, finance, and procurement, each with the question they ask and the Dex proof that answers it.

In a 10,000-person enterprise these are four named people with four calendars. In a 400-person company they may be two people wearing four hats. The seat count changes; the four questions do not. Each one has a different failure mode, and each one is answerable with something concrete rather than reassuring.

Seat 1: Security asks whether autonomy stays in bounds

The question is "Can it act without a human and stay in bounds?" Note what it is not. Security is not asking whether the model is smart, accurate, or well-intentioned. They are asking the same three things they ask about any principal with production access: what is it permitted to do, what prevents anything else, and what record does it leave.

Answer with mechanism, not assurance. Every action Dex takes must match an explicit, structured policy across a six-layer model - Global, Tenant, Target Rules, Department, Action, Runtime. No matching policy means no action, and that check runs in the execution layer rather than the model's prompt, which is what makes it a guardrail instead of an instruction. Underneath sit two hard-coded floors: Dex never grants admin roles and never bypasses MFA. Actions run under delegated permissions, as the requesting user or admin using their own access, not a broadly scoped shared API key. And every action writes to both native Microsoft 365 logs and Dex's own Activity Log, capturing who requested it, which policy authorized it, what executed, and the outcome.

That last part is the piece to hand over in writing. Our full walkthrough of why the audit trail is the product exists specifically so a champion can forward one link to a security reviewer instead of paraphrasing a control model they do not own.

Seat 2: Finance asks what it costs at your volume

The question is "What does this actually cost at our ticket volume?" Finance's failure mode is not sticker shock. It is an unforecastable line item. A CFO can approve a large number and refuse a small one if the small one has no ceiling and no relationship to output.

Seat-based pricing is what usually creates that problem for AI tooling: cost scales with headcount, which is uncorrelated with how much IT work actually gets done. Dex is priced per unit of work instead - $1.99 per resolved issue, with $100 in free credit to start and no credit card. The finance model is three numbers a CFO already has: ticket volume, the share resolved end to end, and unit price. Nothing resolved means nothing billed, so the floor is zero and the ceiling moves with output rather than org chart.

The comparison that lands is per-resolution against per-resolution. Published benchmarks put a Tier 1 contact at $20 to $30 of operational cost, and Tier 2 higher. Set that beside a $1.99 unit and the argument stops being about software budget and starts being about substituting one cost per resolution for another. Bring your own ticket volume to the math; the structure holds at any size.

Seat 3: IT operations asks whether it resolves or just routes

The question is "Does it resolve real work, or just route it?" This is the seat most likely to be your champion, and also the seat most able to sink the deal quietly - because they are the only reviewer who can credibly say "we tried something like this and it deflected nothing."

They are right to be skeptical. The market has trained them on containment rates and better-formatted tickets. What separates the categories is scope and finality: Dex resolves L1 through L3 end to end inside Microsoft 365 - password and MFA recovery, group and license access, provisioning, and the deeper Tier 2 and Tier 3 troubleshooting and configuration work that used to need a senior technician. Cases that require genuine architectural judgment escalate to a human with full context attached, which is the honest boundary and worth stating plainly to this seat.

Two things help here. The three questions that separate agentic IT from chatbot copilots gives an ops reviewer a vendor-neutral filter they can apply to us as easily as to anyone else. And because this seat almost always owns the ITSM, the boundary question comes up immediately: our answer to whether you still need an ITSM is yes. The ITSM stays the system of record. Agentic IT removes the work before it becomes a record. For admin-side scope specifically, Dex Pro is the console where delegated M365 operations get executed and approved.

Seat 4: Procurement asks whether the vendor is enterprise-safe

The question is "Is the vendor and platform enterprise-safe?" Procurement is checking vendor durability, data handling, and certificates, and they are the seat where imprecision costs the most - because anything you claim gets verified against a document.

So be exact. Dex runs on the SysAid platform, which is ISO 27001, ISO 27017, and ISO 27018 certified and SOC 2 Type 2 compliant with annual third-party audits, and which serves 3,000-plus organizations. Dex is built on that foundation and to those standards. Dex's own SOC 2 Type 2 is in process and not yet held; HIPAA attestation is roadmap. Infrastructure is AWS-hosted with encryption in transit and at rest, SSO and MFA support, per-organization isolated databases and encryption keys, and a zero-data-retention model in which Dex reads only what a task needs and discards it.

If a questionnaire requires the certificate in the product's own name, that is a real gap and saying so early is cheaper than being caught by diligence later. Precision here is not a weakness in the pitch. It is the thing procurement is actually testing.

Who kills the deal

Not the loudest skeptic. The seat nobody briefed.

Deals in this category rarely die from a hard "no." They die from a deferral: a reviewer has an open question, cannot resolve it in the room, and the safe move is next quarter. Security and Procurement produce most of those deferrals, and not because they are obstructive. They are simply the two seats that receive the least role-matched evidence, because the champion's case was built for IT operations and then forwarded unchanged.

The corollary is the useful part. You cannot win the room you are not in, but you can decide what walks in with your champion.

What to hand your champion before the meeting

Four artifacts, one per seat, each answering that seat's question in its own language rather than yours.

For Security: the policy model and the per-resolution audit record, including what happens to an out-of-policy request. For Finance: the unit-cost model run against their real ticket volume, with the floor-of-zero property stated explicitly. For IT operations: the L1-through-L3 scope, the escalation boundary, and how the ITSM stays the system of record. For Procurement: the exact certification posture, including what Dex holds today and what it does not.

Then check the one thing most champions skip: ask them which seat they are least confident presenting to. That is the seat that kills the deal, and it is almost always the one you spent the least time on.

Frequently asked

Who sits on the buying committee for an agentic IT purchase?
Four functions review it, even in a mid-sized organization where one person may wear two hats. Security asks whether an autonomous system can act without a human and stay in bounds. Finance asks what it costs at real ticket volume. IT operations asks whether it resolves work or just routes it. Procurement asks whether the vendor and platform are enterprise-safe. The IT champion who ran the evaluation is a fifth seat, but their job is relaying the case, not deciding it.
What does a security team ask about autonomous IT?
Security asks a narrower question than 'can we trust the AI.' They want to know what the system is permitted to do, what stops it from doing anything else, and what record it leaves. For Dex, the answers are a six-layer policy engine enforced in the execution layer rather than the prompt, two hard-coded guardrails (never grants admin roles, never bypasses MFA), delegated permissions so actions run under the requesting user's own access, and a per-resolution audit trail written to both Microsoft 365 native logs and Dex's own Activity Log.
How should finance evaluate the cost of agentic IT?
Per unit of work resolved, not per seat. Seat-based pricing makes cost a function of headcount, which is uncorrelated with how much IT work the tool actually does. Dex is priced at $1.99 per resolved issue with $100 in free credit to start, so the finance model is ticket volume times resolution rate times unit price. That gives a CFO a number they can forecast and a floor of zero if nothing gets resolved.
Is Dex SOC 2 certified?
Not yet in its own right, and it matters that we say so precisely. Dex runs on the SysAid platform, which is ISO 27001, ISO 27017, and ISO 27018 certified and SOC 2 Type 2 compliant with annual third-party audits. Dex's own SOC 2 Type 2 is in process, and HIPAA attestation is on the roadmap rather than held today. For a procurement questionnaire that requires the certificate in the product's own name, that distinction is the answer, and vendors who blur it fail the diligence step later at higher cost.
Which seat most often kills an agentic IT deal?
The one nobody briefed. A deal rarely dies from a hard 'no' in the meeting - it dies when a reviewer has an unanswered question, cannot get an answer in the room, and defers the decision to next quarter. Security and procurement kill deals most often, not because they are hostile, but because they are the two seats that receive the least role-matched evidence from a champion whose case was built for IT operations.
Does Dex only handle L1 tickets?
No. Dex autonomously resolves L1 through L3 - routine Tier 1 work like password resets, MFA recovery, and access provisioning, plus the deeper Tier 2 and Tier 3 troubleshooting, configuration, and engineering-adjacent work that used to need a senior technician. Genuine architectural and judgment cases escalate to a human with full context attached. For an IT operations reviewer, that scope distinction is usually the whole evaluation.