In 1994, the Workflow Management Coalition published a reference model specifying what workflow software was supposed to accomplish: automating processes involving "combinations of human and machine-based activities" across insurance, banking, legal work, and administration. The model laid out start and completion conditions, navigation rules, role assignments, state recovery. It also acknowledged something revealing. The market had already produced many workflow products and zero interoperability standards, creating incompatible "islands" of process automation.
Each island was encoding its own version of institutional authority into software, independently, because the alternative was that authority simply evaporated when work moved to screens. Nobody coordinated the reconstruction. Everyone recognized the need for one.
The rebuilding proceeded layer by layer. Routing and operational controls arrived in the late 1990s, with frameworks for dynamic sequencing, exception handling, and ad hoc rework. By 2010, OASIS had formalized WS-HumanTask, specifying task initiators, potential owners, actual owners, excluded owners, and business administrators, with delegation constraints governing whether a task could be reassigned freely, only to potential owners, or to nobody at all. Regulated industries built the signature and audit layer separately: 21 CFR Part 11 required time-stamped audit trails, operational checks enforcing permitted sequencing, authority checks, and electronic signatures displaying the signer's name, the date, and the meaning of the signature. Not just that someone signed, but what the signature meant: review, approval, responsibility, authorship.
This was painstaking, expensive work. And all of it rested on a single structural assumption: that the entity at the keyboard was a human being, inhabiting a role, bound by the process the software encoded.
Robotic process automation was the first real stress test of that assumption. UiPath's documentation draws a careful line between attended robots, which help a user fill fields and click submit, and unattended robots, which log in with no human present and process work autonomously. Attended robots "impersonate real individuals" and should never exceed the triggering user's permissions. Unattended robots run under dedicated accounts with administrator-configured credentials. The distinction is honest about the problem it is trying to solve. It also tells you the problem was already visible well before language models entered the picture.
The GSA Inspector General's 2024 audit showed what happens when that honesty doesn't reach operations. GSA had 119 active bots and 24 decommissioned ones. Of 16 systems reviewed, seven had security plans that didn't mention bots at all. Ten failed to authorize non-person entities' access. For the 24 decommissioned bots, 55 of 56 assigned custodians didn't have access removed within the required 14-day window. Bot developers' access was never revoked. The affected systems held personally identifiable information, financial records, and procurement-sensitive data.
The bots weren't rogue. The institutional apparatus simply hadn't absorbed them as actors requiring lifecycle management. Security plans written for human users didn't mention bots because nobody had updated the plans to account for entities that could click every button in an approval chain without understanding what approval means.
Workflow systems spent decades reconstructing institutional process in software. The approval chain, the role assignment, the audit trail, the digital signature. Each one carefully built for occupants who understood what the furniture was for. Web agents now encounter that furniture as navigable terrain: pages to fill, buttons to press, sequences to complete. They can traverse the process without inheriting any of the institutional logic the process was designed to enforce.
The GSA audit suggests we already know what this looks like, because we have seen the earlier version. The bots were not malicious. The people who deployed them were not negligent in any dramatic sense. The institutional apparatus simply had not been redesigned to account for actors that could operate the controls without understanding the controls. The question now is whether security plans get updated before the next audit, or after it.

