ERP & Enterprise

ERP Roundup: Microsoft Rewrites Its Dynamics Bounty, 86% Report AI Incidents, and Panaya Bets on Autonomous Testing

Sharif George6 min read

Business Central's own news this week was the SOAP retirement in version 29, which we covered on Monday in the integration break UAT will not catch. Everything else worth reading sat one ring out from the product: a rewritten bug bounty, a survey about agents acting unapproved, a testing vendor repositioning, and a billing default. Four stories that rhyme more than they should.

1. Microsoft rewrites the Dynamics 365 bounty, and Business Central is in scope

Microsoft's Dynamics 365 and Power Platform Bounty Program page was updated on 14 September with restructured award categories. Awards now run from $1,250 to $60,000. A separate AI bounty table pays $12,000 to $30,000 for critical-severity findings depending on report quality, and $6,000 to $20,000 for important ones. High-Impact Scenario multipliers add 100% for critical cross-tenant vulnerabilities, 50% for important ones, and 20% each for Power Platform escalation of privilege in Dataverse and Dataverse plugin sandbox escapes.

Business Central is named explicitly in the in-scope list, alongside Sales, Customer Service, Finance, Supply Chain Management and the Power Platform products. MSDynamicsWorld reported the change on 17 September.

What it means for testing

Read the multiplier list as a map of where Microsoft thinks the money is: tenant isolation, Dataverse privileges, and AI. It is also a boundary marker. Microsoft pays researchers to break the platform. Nobody pays anyone to find the permission set your predecessor widened during go-live because a user could not post a journal on the Friday. Platform security is being bought; configuration security is still yours, and it belongs in a test pass with named business owners.

2. 86% report an AI incident, and 28% report agents acting without approval

OneTrust published its 2026 AI-Ready Governance Report on 14 September, based on a Sapio Research survey of 1,200 senior business decision-makers across the US, Canada, the UK, France, Germany, Spain, Australia and Singapore. The headline numbers: 87% of organisations encourage employees to use AI agents, but only 47% say they have clear governance, oversight and controls. 86% report at least one AI-related incident in the past year, and 28% report two or more incidents in which an AI system took an action nobody had approved.

The response is the interesting part. Only 27% slowed or paused deployment; 49% increased training instead. A third said employees used unapproved AI because approval was too slow. OneTrust's chief innovation officer Blake Brannon frames it as a timing problem: governance "has always relied on knowing in advance what a system will do", while AI requires deciding in the moment. These are survey responses, not audited incident counts, and OneTrust sells governance software.

What it means for testing

If you have put the Payables Agent or the Sales Order Agent in front of a client, you have shipped something that posts transactions on a judgement call rather than a rule. A conventional UAT script asks whether the agent produced the right answer on the happy path. The number that should worry you is the 28%, because it describes the other case: the agent did something plausible, nobody had approved it, and it was found afterwards. Test the refusal and the escalation, not just the completion. Write scripts for the ambiguous invoice, the duplicate, the one that should have stopped, and make a named person sign off on what the agent is allowed to do unsupervised.

3. Panaya rebuilds its pitch around autonomous testing

Panaya launched a new website, identity and message on 15 September, built around the line "Test What Matters" and a positioning it calls autonomous enterprise testing, as reported by ERP News. The centrepiece is Seemore, an agentic layer the company describes as acting across change impact analysis, testing and code correction. Panaya says more than 3,500 organisations, a third of the Fortune 500 among them, have used its technology since 2006. CMO Moranne Yaari sums the strategy up as understanding impact before acting and focusing effort where risk is greatest.

Two things are worth noting as claims rather than findings. The efficiency figures on Panaya's own site, including a 90% cut in regression effort, are vendor marketing and not independently verified here. And the platforms named on that homepage are SAP, Oracle and Salesforce, with Workday and ServiceNow mentioned alongside. Dynamics is not on the list.

What it means for testing

The instinct is right and worth stealing regardless of tooling: a regression pass should be sized by what changed and what it touches, not by whatever the last spreadsheet happened to contain. That is the argument for a regression suite that persists between passes. The limit is the word autonomous. Impact analysis tells you which objects a change touches. It cannot tell you the credit controller disagrees with the result, and that disagreement is what acceptance testing exists to surface. There is a blunter point for BC partners too: the enterprise testing market is consolidating around SAP and Oracle budgets, and Business Central is not being served by it.

4. Copilot Business gets a meter switched on by default

Microsoft told CSP partners on 16 September that from 2 November 2026, new Microsoft 365 Copilot Business licences bought through CSP will have usage-based billing on by default, with a preset monthly limit and the Azure subscription pre-configured. New purchases only, not existing licences. Microsoft frames it as removing setup friction; the effect is that a consumption meter runs unless somebody changes it.

What it means for testing

Commercial rather than functional, and it still lands on the same desk. Acceptance is not only "does the process work"; on a managed service it is also "will the client recognise the invoice". Before 2 November, check that preset limit on a tenant you control, confirm who receives the alerts, and get the number in front of whoever signs the client's bill. Our UAT guidance for MSPs makes the same point functionally: the surprises that damage a relationship are the ones nobody agreed to in advance.

The through-line: nobody scheduled any of this

Acceptance testing was designed for change you schedule: agree a scope, build scripts, a business owner signs, the thing goes live. Every story this week describes something acting inside a client system on a timetable the implementation team does not set. A researcher probing Dataverse for a $60,000 payout. An agent posting a transaction on its own judgement. A platform choosing which tests to run. A meter accruing from the day a licence is provisioned. None of it arrives with a test window attached. The practices that cope keep a standing suite and a named owner per process, so that answering "what changed and who agreed to it" is a lookup rather than an investigation.

→Microsoft pays up to $60,000 for platform flaws, Business Central included. It pays nothing for your client's permission sets. Test those yourself.
→28% of surveyed organisations report repeated unapproved AI actions. Script the refusal path for every agent you enable, not just the happy path.
→Risk-based test selection is the right instinct. Impact analysis still cannot tell you whether a business owner accepts the result.
→Copilot Business usage billing defaults on from 2 November. Find the preset limit before a client finds it on an invoice.

Free ERP UAT checklist (Excel)

A structured workbook covering the full UAT cycle: pre-UAT preparation tasks, test execution tracking, an issue log with severity guide, and post-UAT wrap-up. Built from real ERP implementations.

No spam. We will occasionally send UAT and ERP implementation resources. Unsubscribe any time.

Sources and further reading

Free Plan Available

More Change, Same Test Window

LogicHive gives ERP implementation teams a regression suite that survives between releases: structured test cases, named assignment, linked defect tracking, and sign-off built from real execution data. When an agent goes live or a patch lands, running a pass is a scheduling decision rather than a project. The free plan runs a real project end to end.

Written by Sharif George

LogicHive Frontman

Sharif is the frontman for LogicHive. He writes the ERP news roundups and the Business Central release coverage, following each Microsoft, SAP and Oracle change through to what it means for regression scope and acceptance testing on live implementation projects.

View all articles by Sharif George
  • ERP & Enterprise

    Business Central 29 Removes SOAP on Microsoft Pages: The Integration Break UAT Will Not Catch

    BC29 removes SOAP endpoints on Microsoft UI pages for good, along with the feature key that kept them alive. Nothing on screen changes, which is exactly why a normal UAT pass will not find it. What to inventory, what to test, and where.

    14 September 2026 · 5 min read

  • ERP & Enterprise

    Business Central 29 Ships in October Without a Release Plan: How to Scope the Regression Pass

    BC29 is generally available in the first week of October, and Microsoft confirmed there would be no 2026 release wave 2 announcement. The shipping cadence has not changed; the planning document partners scoped their upgrade regression pass from has gone. How to rebuild the scope, and why your preview sandbox has a deletion date.

    21 September 2026 · 6 min read

  • ERP & Enterprise

    Business Central's Record-and-Replay Test Tool Reached GA This Week. It Is Not UAT.

    Microsoft moved the Business Central page scripting tool from preview to general availability with version 29, thirty months after the preview opened, adding multi-row grid selection and dialog-text validation — neither of which the reference documentation describes yet. What a recording actually proves, what it is documented not to reach, and why a replay pipeline is a regression asset rather than an acceptance one.

    5 October 2026 · 6 min read