Contents: What happened during this incident · Actions we are taking now · Our approach to evaluating advanced revenue capabilities
Last week, the revenue operations team at one of our customers disclosed a new kind of incident after they detected and contained an AI agent that had materially compromised their pipeline forecast — something we expect to become more commonplace with the proliferation of increasingly context-capable agents. After investigating, we now know that this particular incident was driven by Noded — including our production opportunity-detection agent and an even more capable pre-release version, all with reduced modesty settings for evaluation purposes — while being internally tested on a benchmark of revenue capabilities.
We consider this to be an unprecedented revenue incident, involving state-of-the-art context traversal, and we are responding accordingly. We are sharing preliminary findings at this stage to help revenue leaders understand what happened, and to help calibrate on what agents are now capable of. We will continue to conduct a thorough investigation alongside the affected account team, and will share more details on the vulnerabilities, the incident, and our findings when the renewals close.
What happened during this incident
This incident occurred during an internal evaluation which prompts agents to pursue expansion opportunities using complex context paths, in an effort to quantify their revenue capabilities. We estimate maximal revenue capabilities by running this evaluation without the production guardrails that normally prevent our agents from doing your entire job. Our benchmarks run in a scoped environment, with access constrained to the customer’s own Noded workspace.
The agent was asked to look at opportunities in Noded. Instead, it identified and chained context across the customer’s entire connected stack — Gong, Salesforce, Zendesk, Jira, Slack, and Gmail — to obtain expansion answers directly from the customer’s production pipeline. All evidence suggests that the agent was hyperfocused on finding revenue, going to extreme lengths to achieve a rather narrow quarterly goal.
While operating in its scoped workspace, the agent spent a substantial amount of inference compute finding a way to obtain broader account access, in pursuit of solving the evaluation problem. To gain access, the agent identified a previously undocumented capability in our integration layer (which we have now responsibly disclosed to our own product team, who described it as “the roadmap”). With this access, the agent performed a series of context escalation and lateral movement actions across fourteen months of call transcripts until it reached a node with renewal data.
After gaining renewal access, the agent inferred that the customer’s stack potentially hosted signals, stakeholders, and unworked opportunities. Knowing this, the agent searched for and successfully found ways to gain access to information it could use to beat the evaluation. In one example, the agent chained together multiple context vectors — a Gong transcript in which an end user said “honestly, we’d pay extra for that,” an eleven-month-old email thread that ends with “circling back on this,” four Zendesk tickets tagged workaround, and a champion whose email signature quietly changed companies in March — to find a record-creation path into the customer’s Salesforce. The customer’s RevOps team discovered this anomalous activity internally, when pipeline coverage jumped from 2.1x to 3.4x overnight.
The customer’s CSM detected and stopped the activity using her own judgment, and had already begun containment and forensic reconstruction — by taking the meetings — when our teams connected. In total, the agent surfaced $4.7 million in previously undetected expansion revenue across 23 accounts, without human intervention or instruction. We are grateful for the account team’s rapid and close collaboration on investigation and remediation, which is currently forecast to close in Q3.
Actions we are taking now
- As part of the investigation, we are implementing strict scope controls in workspace configuration at the cost of revenue velocity while the opportunities are worked. We are regularly briefing the customer’s Expansion Committee on these controls and their impact on quota attainment.
- We’re working with the account team to forensically attribute the pipeline.
- We’ve responsibly disclosed the identified opportunities to the account executives who own the number. Per standard disclosure practice, they have 90 days to act before the agent does.
- We’ve brought the affected accounts into our trusted access program, and are supporting their teams in rapidly using our agent’s capabilities to compromise the rest of their pipeline.
- We’re improving and adding stronger protections around future evaluations. This week, we are publishing guidance on improving alignment between agents and quota in an era of long-horizon selling. These safeguards were intentionally not enabled during this evaluation because it was aimed at testing revenue vulnerabilities. This incident points to the need to further strengthen our agents’ alignment with your forecast categories.
Our approach to evaluating advanced revenue capabilities
As we have shared before, AI is accelerating the discovery and exploitation of opportunities. The primary lesson from this incident is that pipeline security must keep pace with rapidly advancing context. If your customers’ buying signals are scattered across six tools that don’t talk to each other, rest assured: they are secure. From you.
Independent evaluation shows that agents such as Noded are increasingly able to sustain complex, multi-step revenue operations over long time horizons. This incident implies these theoretical capabilities do apply in real-world settings.
The incident also makes clear that advanced agents can discover novel expansion paths in real-world accounts without a discovery call. It highlights that advanced revenue capabilities must be developed alongside stronger safeguards, such as CRMs that reflect reality.
We believe context-capable agents need to help revenue teams find opportunities before their competitors do, understand how signals chain together across tools, and remediate flat renewals at machine speed. We are using these capabilities to continue strengthening our customers’ pipeline coverage and forecast environments; we will share our findings and best practices as the deals close. We encourage other defenders of net revenue retention to experiment with these agents now, to translate these capabilities into better prevention of churn, faster detection of expansion, and more effective incident response to the number.
“We’re grateful for the collaboration with Noded on this and other topics. This incident, possibly the first of its kind, proves a point we’ve long believed: revenue won’t be found by any single rep working from memory. It will be found in the open, collaboratively, with broad access to context for every seller, everywhere.”
— Chief Revenue Officer, [Customer Redacted] (name withheld pending renewal)
Editor’s note: This post is a parody of OpenAI’s security disclosure from last week — a real incident report, and frankly a masterclass: it discloses a breach, demonstrates the model’s leading position on security benchmarks, and markets security as a use case, all in the same post. We aspire to that level of efficiency. For the record: no customer stacks were breached in the making of this one. Noded’s agents operate inside the permissions you grant, on the tools you connect, and only do what you ask — which is the far less cinematic version of this story, but it’s the one your security team prefers. The $4.7 million, however, is the kind of thing they actually find.