problem_kicker

Treat AI agents as machine actors with explicit identity and capabilities.

An agent that can call tools is an actor in the security model. Giving it a broad API key or inheriting a human session makes authorization ambiguous, difficult to revoke and hard to audit.

Agent securityLeast privilegeShort-lived credentialsPolicy enforcementAuditable

DEMAND LANGUAGE / REAL-WORLD PROBLEM

Does this sound familiar?

“Can AI do this itself without getting full access to everything?”
“What happens when the agent makes the wrong change?”

WHAT CAUSES THIS?

Why it breaks in production

Shared credentials erase actor identity.

  • Tool descriptions are mistaken for authorization policy.
  • Long-lived secrets outlive tasks and ownership changes.
  • Systems verify that a tool returned, not that the intended state change occurred.

architecture_for SECURE AI AGENT PERMISSIONS

engineering

We inventory machine actors, tools, data boundaries and irreversible actions. Each capability receives explicit policy, credential lifetime, approval requirements and post-condition verification.

security

authority

Prefer short-lived credentials, least privilege, deny-by-default policies, human approval gates for high-impact actions, dependency inventories and tamper-evident audit evidence.

performance

critical

Authorization must be observable but should not force every action through a high-latency remote path. Cache only policy decisions whose inputs and expiry semantics are explicit.

technologies

vendor

AI agents · IAM · policy engine · short-lived credentials · audit logs

failure_kicker

anti_title

  • One service account for every agent.
  • Prompt instructions as the primary safety boundary.
  • Permanent tokens stored in agent memory.
  • No read-back verification after a mutation.

measure_kicker

verify_title

verify_intro

  1. Negative authorization tests for every privileged capability.
  2. Credential expiry and revocation drills.
  3. Mutation read-back and invariant checks.
  4. Audit reconstruction: actor, policy, tool, inputs, result and verified state.

CTO / CIO FAQ

faq_title

Is a tool allow-list enough?

No. A tool may expose multiple resources and actions. Authorization normally needs actor, capability, resource, context and policy.

Should agents use human OAuth tokens?

Only where the delegated-user model is intentional. Autonomous machine work is usually clearer with a distinct workload identity and scoped delegation.

Where should approval happen?

At the boundary before a high-impact capability is authorized, with enough context for a human to understand the proposed change.