Seventy-two hours. Three vendors. Same primitive.
Not a smarter chatbot. Not a longer context window. An agent with a login, a permission scope, and a paper trail. The martech layer just stopped shipping AI assistants and started shipping coworkers with their own logins – which makes your next AI decision an access-control decision, not a model decision.
The week the badge became the product
Monday at Opticon in New York, Optimizely announced Virtual Teammates. The company's August 31 press release — corroborated the same day by PRNewswire and Forkast — calls them "a new class of digital coworkers." They take defined responsibilities, retain organizational knowledge over time, and complete work without task-by-task prompting. Five launch roles: Chief of Staff, SEO & AI Search Analyst, Marketing Analyst, Personalization Strategist, CRO Manager. Each has a defined role, responsibilities, and organizational permissions. You hire them from a directory, adapt the work in plain language, and set where human review is required. Activity ties to the teammate's own identity, traceable for accountability.
Wednesday at Webflow Conf 2026 at the Omni Boston Hotel at the Seaport, Webflow unveiled Source. Per webflow.com/source and Dom Nicastro's September 2 CMSWire report, it is a limited research preview: a shared workspace for marketing teams and agents. Agents get direct access to the code that ships, not a visual abstraction layer. Governance ships with the capability — brand systems, approval paths, audit trails "from day one." Agent actions run under the same roles, permissions, and review systems as human work, with a record of what changed and who, or which agent, made the change. Teams set the autonomy dial: human approval before anything ships, or more freedom for lower-risk work. Agents run in the background, flag opportunities in an Inbox with drafts already waiting.
Same Wednesday, Adobe acquired Rilo. TechCrunch's September 2 report, corroborated by Business Standard, Inc42, and Pulse2, frames it as an IP licensing deal plus a six-member team acquisition — terms undisclosed. Founded in 2025 by IIT Bombay batchmates Dhruv Jaglan and Georgi Boby, Rilo raised $1 million from Peak XV, DeVC, and Day Zero Ventures at a $10 million valuation. Jaglan said on LinkedIn that more than 10,000 people had tried the tool. The platform let non-technical users describe a workflow in plain English and have AI agents build and execute it across tools — competitor intelligence, prospecting, LinkedIn outreach, content repurposing, sales call analysis, campaign research. Business Standard put it cleanly: Rilo "evolved into a platform for 'AI employees' for marketing and GTM teams." Rilo shuts down post-acquisition. Existing customers lose access. Adobe's second known India acquisition after Rephrase.ai in 2023.
Three companies. Seventy-two hours. One shape: identity, permissions, audit trail. That is an HR and IAM shape, not a chatbot shape.
Identity is the mechanism, not the feature
Look past the demo reels. The product move is the badge.

Kevin Li, SVP Product at Optimizely, said the quiet part out loud in the August 31 release: "A lot of AI adoption stalls out because getting from idea to finished work is still hard. Even when the AI does its part, you don't always know who did what, or trust it enough to let it act on its own." Then the design choice: "That's why we built Virtual Teammates with their own identity and permissions from day one. They carry the work through to execution, and every action ties back to a clear audit trail."
Webflow built the same spine into Source. Agent actions governed by the same roles and review systems as human work. Per-role Views. Guardrails on what marketers and agents can touch. Agent activity tracking in site logs arriving this month. That is not a compliance afterthought bolted on after a breach. That is the product.
The interesting tell is timing. Governance shipped with the capability instead of trailing it by a year. Vendors learned the hard way that ungoverned agents do not get deployed in the enterprise. Security reviews kill them. Legal kills them. Brand kills them. The companies that want real usage are shipping the IAM layer first, then letting the model run inside it.
Optimizely's own research explains the strategy behind the packaging. A global study of more than 2,000 B2B marketing leaders found 81 percent personally switch between two or more disconnected AI tools each week, including 19 percent who use four or more. Alex Atzberger, CEO of Optimizely, framed the pain: "Marketers want to grow their business, not spend time re-explaining it to multiple AI tools." And: "A Virtual Teammate learns how your organization works once, then keeps going." The binding constraint was never model quality for most of these teams. It was context re-explanation and fragmented accountability. A coworker with memory and a login solves both. A better chatbot solves neither.
Webflow's adjacent numbers sharpen the same point. MCP 2.0, released July 21, 2026, added brand controls, permissions, and analytics for agents — more than 30 percent enterprise customer adoption and fourfold usage growth since January, per the CMSWire report. That is not "people love chatting with the site." That is "people will let agents touch production when the permission model looks like theirs."
What operators keep scoring wrong
Most evaluation decks I see still grade these products like writing assistants. Output quality. Latency. How clever the draft looks in a side-by-side.
Wrong exam.
The binding constraint is the review path and the blast radius. Can this thing push to production without a human? Who owns the approval queue when it drafts ten personalization variants overnight? What happens when the CRO Manager Virtual Teammate changes an experiment that was supposed to be frozen? What is the offboarding checklist when you "fire" an agent that has six months of org context and write access to three systems?
Operators also treat vendor roadmaps as capability promises. Read the actual posture. Webflow CEO Linda Tong said on stage that marketers believe in the vision, but she "can also tell you we are nowhere close to it yet." Optimizely defaults Virtual Teammates toward proposing work for human approval, with organizations deciding where review is required. The vendors are more measured than their own marketing decks. If you buy like a hype merchant and operate like an auditor, you will be fine. Reverse that and you will ship an agent into a system you cannot explain to your CISO.
Another common miss: treating "agent" as a feature toggle inside an existing seat. These launches are selling a different unit of work. Optimizely's directory of role-specific teammates. Webflow's per-role workspaces and Inbox of drafted opportunities. Adobe buying a company Business Standard already described as "'AI employees.'" The SKU is starting to look like a headcount line, not a seat upgrade. Price it, review it, and secure it that way, or you will under-govern something that already behaves like a junior with keys.
Second-order effects nobody put in the press release
An agent with its own identity is an audit surface. It shows up in access reviews. It needs a password rotation policy, or whatever the non-human equivalent becomes. It becomes an offboarding problem the day someone leaves and their "teammate" still has write access. It eventually becomes a headcount conversation — not because the agent replaces a person tomorrow, but because the budget line and the permission scope look enough like employment that finance and legal will ask the question.

Dave Steer, Webflow's CMO, said AI agents "have their own budget line and read our websites just like we do." Hold that sentence next to Webflow's AEO maturity study of US brands, presented by chief evangelist Guy Yalif: the median company appears in only 16 percent of the AI answers it would want to be part of, and earns a citation link just 6 percent of the time. If agents have budgets and read sites the way humans do, answer-engine optimization stops being a content calendar problem and becomes an access and presence problem. You are not just writing for Google. You are writing for someone else's digital coworker that may never click through.
Market context from the same CMSWire piece is useful cold water. Gartner placed agentic marketing at the peak of inflated expectations on its 2026 Hype Cycle. Only 17 percent of organizations have deployed AI agents so far; more than 60 percent expect to within two years — the most aggressive adoption curve Gartner tracked among emerging technologies this year. Forrester describes "agentic digital experience platforms" as systems that actively coordinate composable components rather than simply assemble them. As agentic features converge across vendors, differentiation shifts to integration depth, data access, and governance quality. That last clause is the operator brief. Model novelty decays. Permission models compound.
Also notice the acquisition pattern. Adobe did not buy a better generative model. It bought a workflow layer that let non-technical marketers describe work in plain English and have agents execute across tools — then shut the product down for existing customers. That is a talent-and-IP grab into an agentic stack, not a feature you can trial next week. If your roadmap assumed Rilo as a vendor, rewrite it.
What to do before next Monday
Stop scoring demos on prose quality. Build a one-page matrix for every agentic tool you are evaluating: identity model, permission scope, human-review defaults, audit export format, offboarding path. If a vendor cannot answer those five in writing, they are selling you a chatbot with a job title.
Inventory which of your current AI tools have no identity of their own. The 81 percent switching statistic is your smell test. Every disconnected tool that requires you to re-explain the brand, the ICP, and last quarter's wins is a candidate for consolidation into something that retains org knowledge under a permission boundary.
Pick one low-blast-radius workflow and force the governance question before the capability question. Example: draft SEO briefs or experiment hypotheses only — no publish rights. Require human approval. Log every action against a named agent identity. Run that for two weeks. Measure the review queue, not the word count. If your team cannot operate the approval path cleanly on low-risk work, you are not ready for an agent that can touch production code or live personalization.
Ask security and legal into the evaluation early, with a concrete artifact: "this agent will have X scope, Y data access, Z audit trail." Do not bring them a slide about model benchmarks. Bring them an IAM diagram. That is the conversation that determines whether this ships.
Watch the Webflow and Optimizely defaults, not the keynotes. Limited research preview. Human review required unless you loosen it. Linda Tong saying we are nowhere close. That honesty is the useful signal. Design your rollout to match the vendors' actual posture, not the LinkedIn clips.
If Adobe/Rilo was on your stack map, replace it this week with an explicit "build vs buy" note. The product is gone for customers. The capability is migrating into Adobe. Plan for a platform decision, not a point-tool renewal.
The login is the story
The last three days did not prove that AI coworkers are ready to run your marketing org. They proved that the serious vendors have stopped pretending the hard problem is generation.
The hard problem is trust under load: who acted, with what authority, on what system, and can you prove it later. Optimizely shipped role-specific teammates with identity and permissions from day one. Webflow shipped a shared workspace where agents and humans share the same governance plane. Adobe bought a company already framed as "AI employees" and absorbed the team. Different packaging. Same primitive.
So when someone asks you which model to pick for the next marketing agent, answer the wrong question last. Ask first: what login does it get, what can that login touch, who reviews the blast radius, and how do we revoke it. The martech layer just stopped shipping AI assistants and started shipping coworkers with their own logins – which makes your next AI decision an access-control decision, not a model decision.




