Designing tool permissions for AI agents
Updated

Least privilege for non-humans: scopes, approvals and audit trails for every tool an agent can touch.
Agents inherit the permissions you grant them and none of the judgment you assume. Design accordingly.
The short answer
Scope every tool, separate reads from writes, require named approval for writes, log everything. Start deny-by-default and open named paths deliberately.
The permission table
| Tool class | Default | Approval | Audit |
|---|---|---|---|
| Search and read | Scoped to user visibility | None, logged | Query plus result count |
| Draft and summarize | Scoped to session | None, labeled draft | Input hash plus output |
| Ticket and record writes | Named approver | Human confirms | Before and after values |
| Data queries | Row-scoped, capped | Owner for new scopes | Query plus rows returned |
| Access and config changes | Denied | Two named approvers | Full change record |
Worked example: the over-permissioned assistant
A fictional assistant (fictional) ships with wiki admin scope and writes a corrected policy page directly. Nobody approved; the edit history shows the agent. The fix takes an afternoon: user-scoped reads, draft-then-approve writes, full call log. The next review finds three blocked overreach attempts in the log, which is the system working. The RAG decision post sets the retrieval baseline; the AI-assisted post sets the review rule.
Checklist: agent permissions
- No tool runs with broader scope than its named users.
- Writes require a named approver and land in a log.
- Deny-by-default with named, dated exceptions.
- Weekly review of blocked attempts for the first month.
Related reading
Straight answers
Frequently asked questions
Why do agents need permissions?
Because tools act: read documents, write tickets, query data. Without scopes, a helpful agent becomes an unreviewed admin.
What is the minimum setup?
Per-tool scopes, read-before-write separation, human approval for writes, and a log of every call with agent, tool, arguments and result.
Who approves agent writes?
A named human per tool class, before the write lands. Approvals are logged, revokable and reviewed weekly at first.