eBiz Analysis Security

Why a valid login is now the biggest risk to your deal data

Agentic AI lets someone with legitimate access walk an entire agreement library overnight. No login screen can stop that, because the login is genuine.

By Tom Miller 4 min read

The eBiz platform holds your most commercially sensitive data: deal terms, rebates, supplier agreements and price lists. The platform itself is secure. It is regularly penetration tested by third parties, we are an Amazon AWS certified partner, it runs on AWS infrastructure independently certified to ISO 27001 and SOC 2, and it has never been hacked or compromised in the 25 years it has been operational.

None of that is the part I would worry about now.

What agentic AI actually changes

The world is changing fast. Agentic AI means anyone with a valid login can fire up an AI agent in their browser — using ChatGPT, Claude or similar — and misuse access they legitimately hold. The agent works through your deal and rebate data page by page and compiles it into a single document. It does not need to break anything. It simply uses the access that person already has, far faster and far more thoroughly than a person ever would.

It is worth being clear about where that data then goes. It does not just end up in a spreadsheet on someone’s laptop. It ends up on the servers of a US AI company, under a consumer account with no confidentiality obligation to you, where it can be retained for up to five years and used to train future models. Your negotiated terms are suddenly outside anyone’s control, permanently.

No login screen can stop this, because the login is genuine. It has to be detected by behaviour.

Watching how accounts behave, not just who gets in

The industry-standard approach to security is about controlling who gets in. That remains necessary, and none of it goes away. But it is no longer sufficient, because in this scenario the person getting in is supposed to be there.

Our new Enhanced Security and Threat Management Tools watch how accounts behave once they are inside. A user who normally views three deals a day suddenly opening two hundred. An AI browser agent, working on behalf of a genuine user, walking an entire agreement library overnight and capturing every rebate figure in it.

There are two detection methods, and they look for different things:

  • Out-of-character detection. Every user’s deal views and downloads are checked hourly against their own 30-day baseline. Alerts fire only when activity is several times their personal norm, so heavy users doing their usual job will not trigger false alarms.
  • AI agent detection. This flags machine behaviour across the whole platform: request bursts, metronomic timing, sequential ID crawling and round-the-clock activity.

The first is about the individual. The second is about the pattern — because an agent does not behave like a person, no matter whose credentials it is using.

One user's daily deal views against their own 30-day baseline Daily deal views sit between zero and seven for thirty days, averaging 3.5 a day. On day 31 the same account records 214 views in 24 hours — roughly sixty times its own norm. 0 50 100 150 200 Deal views 30-day typical range — averaging 3.5 views a day 214 deal views in 24 hours Alert fires — roughly 61× this account's own norm Day 1 Day 10 Day 20 Day 30 Day 31
Fig. 1 Out-of-character detection compares each user against themselves, not against a platform-wide threshold. Thirty days of ordinary use establish the baseline; the agent run on day 31 is what breaks it.

What happens when something is flagged

When something is flagged, your nominated recipients immediately receive the who and the why in plain English — for example, “214 deal views in 24h vs a typical 3.5/day” — along with a full seven-day activity report showing everything that user touched.

Administrators can also run that report on demand against any user, without waiting for an alert. Every alert is written to the audit feed.

The deliberate choice here is that alerts explain themselves. An alert nobody understands is an alert nobody acts on.

Terms that are actually yours

We have also added customisable usage terms: your own terms, specific to your business and buying group, displayed at login before anyone gains access.

This matters more than it might appear. Standard tick-box website terms are a weak basis for recourse if someone extracts your data and takes it with them. Terms written for your group, agreed at the point of access, are a considerably stronger one.

What we would suggest doing now

Everything is configurable under Settings → General → Suspicious Activity Alerts.

Two things are worth doing together rather than separately. The first is setting the alert thresholds. The second is reviewing your user permissions — because behavioural detection tells you when someone is using their access unusually, and permissions determine how much access there was to misuse in the first place. The two work as a pair.

We are happy to go through both with you. They are covered in our regular calls, or you can get in touch directly.

We have put the full picture — the risk, the detection tools we have built for it, and what we recommend you do now — into a short whitepaper: Your Data in the Age of AI Agents (PDF, four pages).