Expense work is a useful test for enterprise agents because the task looks small until it touches policy, approval authority and employee trust. Microsoft lists Expense Agent in Dynamics 365 Business Central as a production ready preview that extracts receipt data, creates expense entries, itemises complex receipts and groups claims into reports by trip or project. The 2026 Business Central release plan adds mobile receipt capture, project assignment, travel requisitions and approval support around Expense Agent. Workday’s Sana Self-Service Agent in Microsoft 365 Copilot brings HR and finance questions into Microsoft 365, including expense status and policy guidance, while keeping Workday approvals, policies and business rules in the underlying system.

The pattern is clear: expense AI is moving from document reading into finance workflow. The agent reads receipts, asks for missing evidence, checks policy, drafts the claim, routes approval and updates the system of record. That only works when the organisation has a governed memory layer around policy, exceptions and reimbursement outcomes.

Expense agents need policy memory. Policy memory is the governed record of spend rules, receipt evidence, employee context, exception decisions, approval trails, human corrections and finance write-back that tells the company how expense judgement works.

Receipt capture needs evidence memory

Receipt extraction is useful because it removes a low-value step from the employee and finance team. Microsoft says the Business Central Expense Agent can extract receipt details from uploads, mobile capture and email, then generate expense reports. That shortens the admin loop, but extraction only creates trust when the evidence trail survives the handoff.

Evidence memory records:

  • which receipt, booking confirmation or invoice supported the claim
  • which fields the agent extracted and which fields a person corrected
  • what currency, VAT, merchant and project code were used
  • whether the item was part of a trip, client visit or internal cost centre
  • which duplicate or missing-document checks ran before submission
  • where the final reimbursement record landed

This is close to finance AI agents needing close memory, but the pressure is different. Close memory protects period-end finance judgement. Policy memory protects the daily trust contract between employees, managers and finance.

Expense policy needs source authority

Expense policies drift. A PDF in SharePoint, a finance note in Teams, a travel rule inside the ERP and a manager’s private exception can all describe the same situation with different authority. The agent needs a way to know which source wins before it tells an employee their claim is allowed.

Policy memory defines the source hierarchy:

  • current finance policy and its owner
  • regional, department or project-specific variations
  • approved merchant, mileage, per diem and accommodation rules
  • thresholds that change approval routes
  • prohibited spend categories
  • temporary exceptions tied to a named trip, customer or event

This connects to SharePoint agents needing source memory. A policy answer sourced from stale content creates more work than no answer because finance has to repair the employee expectation after the fact.

Approval support needs exception memory

Clean receipts are the easy part of expense automation. The expensive work sits in the exception: missing documentation, mixed personal and business spend, unclear client entertainment, late submission, duplicate reimbursement, unassigned project codes, regional tax treatment or a manager approving something finance later rejects.

Microsoft’s release plan includes approval-process support for Expense Agent. That matters because an expense workflow becomes operationally sensitive at the approval edge. The agent can check a policy document and prepare a recommendation, but the organisation still needs memory around why a claim moved forward or got blocked.

Exception memory records:

  • what rule the claim breached or nearly breached
  • which evidence changed the decision
  • who had authority to approve the exception
  • whether the approval was one-off or reusable precedent
  • how the employee was told what to change next time
  • which correction updated the policy, form or agent instruction

This is where AI approval agents needing decision memory becomes concrete. Approval memory records the authority decision. Policy memory feeds the agent enough expense-specific context to route that decision properly.

Employee self-service needs permission memory

Workday’s Sana announcement is useful because it frames employee finance support inside the flow of work. Employees can ask about expense status or travel policy in Microsoft 365 Copilot, while Workday keeps the underlying data, policies, approvals and business rules under its controls.

That interface choice changes adoption. Employees ask finance questions where they already work. Managers approve or request clarification without chasing portals. Finance gets fewer repetitive tickets if the answer is grounded in the right policy and the action respects role permissions.

Permission memory decides what that employee-facing agent can reveal and do:

  • which worker can see which claim, status or policy answer
  • which manager can approve which team’s expense
  • which finance user can override, reject or request evidence
  • which questions produce guidance rather than action
  • which sensitive records stay inside the finance system
  • which agent responses need a source citation before reaching the employee

Without that memory, self-service creates a support problem. The employee receives a confident answer, the finance system applies a different rule, and trust gets spent on a workflow that was meant to remove friction.

ERP write-back needs outcome memory

Expense agents create leverage when they close the loop. A cleaner draft helps the employee, but the reimbursement record, project cost, VAT treatment, approval status and policy correction have to land in systems finance already trusts.

Outcome memory captures the last mile:

  • submitted, approved, rejected and reimbursed states
  • reimbursement timing and payment status
  • cost centre, project and client allocation
  • tax treatment and audit evidence
  • manager or finance correction history
  • employee education triggered by repeated errors

This is the difference between a helpful assistant and an operating layer. A helpful assistant reduces typing. An operating layer keeps the judgement, correction and system record connected so the same problem becomes easier next month.

What to map before expanding expense-agent authority

A team testing expense agents should start with one workflow, such as business travel, mileage, customer entertainment or software reimbursement. The useful diagnostic is practical:

  • Which policy source wins when guidance conflicts?
  • What evidence does the agent require before submission?
  • Which spend categories stay draft-only?
  • Who approves exceptions, and where does that reason get stored?
  • Which employee or manager data can the agent reveal?
  • Where does the final reimbursement outcome write back?
  • Which repeated correction should update the policy or agent instruction?

Those questions slow the pilot down in the right place. The aim is a workflow finance can defend, employees can understand and managers can operate without rebuilding context in every case.

Where Model Operator fits

Model Operator builds governed company memory and brings AI into the workflow surfaces where teams already operate: Slack, Microsoft Teams, meetings, calls, internal tools, CRM and finance systems.

For expense agents, the useful build maps policy source authority, receipt evidence, permission rules, approval paths, exception memory, audit trail and ERP write-back before the agent gets broader action rights.

That sits naturally inside the Agentic Company Brain and AI Initiative Consulting packages. For teams already asking finance or HR questions in Slack and Teams, Company Brain + Slack / Teams Bots adds the shared interface once the memory layer can support it.

If your expense AI pilot can read a receipt but cannot explain which policy, permission, exception route and reimbursement record shaped the result, the operating memory is unfinished.

Start a build conversation: modeloperator.io or alexander@modeloperator.io.