Skip to content
Can an agent do?

Can an agent replace Duo?

Cisco’s multi-factor authentication: the push notification your team approves to prove it is really them.

NOT YETKeep it

No. MFA is the control that stops a stolen credential — including an agent’s — from becoming a breach. It is cheap and it gates what agents may do. The exposed labour is around it: enrolment chasing, reset tickets, access-review evidence.

Indicative spend
€60/mo
What it actually costs
from about €3/user/mo; one of the smallest lines on the security bill
Verdict
The moat is real — a network, a dataset, or a liability someone else carries.

What the agent takes over

Every job this product exists to perform, with our verdict on each. Follow one through for the step-by-step breakdown.

Why it survives

It is a security control, not a labour product. There is barely a bill to attack.

What you would still need it for

  • The second factor your insurer and auditor require
  • Device-trust checks at login

What replaces it

  • Agent handling MFA-reset and enrolment tickets with a verification step
  • Agent assembling the MFA-coverage evidence auditors ask for

The brief

What you would tell an agent to take over from Duo, assembled from the jobs above.

duo.brief

I want to keep Duo. It currently does: Cisco’s multi-factor authentication: the push notification your team approves to prove it is really them. Take over this work: - Admin and back office — MOSTLY. Mostly. The inbox triage, the filing, the chasing, the scheduling, the form-filling — an agent does the great majority of what a competent assistant does. What it lacks is knowing which of your relationships need care. - Helpdesk triage — YES. Yes. Reading a ticket, working out what it is really about, tagging it and putting it in front of the right person is exactly what language models do well — and it is the step where human queues quietly lose hours. - Compliance checks — MOSTLY. Mostly, for monitoring rather than for deciding. An agent checks documents, expiries, and records against a checklist continuously and never forgets. Signing off compliance remains a named human responsibility, usually by law. Do not take over: - The second factor your insurer and auditor require - Device-trust checks at login These stay with me across all of it: - Sensitive communication - Anything that spends money - Deciding what matters this week - Deciding staffing - Declaring a major incident externally - Overriding priority for a strategic account - Sign-off and attestation - Regulatory interpretation - The relationship with your regulator Before we start, tell me: which of these you cannot do with the access I can actually give you, and what would break if this ran unattended for a month. — brief built at cananagentdo.com/duo

Compare

Keep the tool, cut the hours

Duo is not the line item worth attacking. The money is in the people-hours spent working inside it, and that is what an agent takes over — with Duo still holding the data.

Put an agent on it