Designing tool permissions for AI agents

Updated

A padlock on a door as an access control symbol

Least privilege for non-humans: scopes, approvals and audit trails for every tool an agent can touch.

Agents inherit the permissions you grant them and none of the judgment you assume. Design accordingly.

The short answer

Scope every tool, separate reads from writes, require named approval for writes, log everything. Start deny-by-default and open named paths deliberately.

The permission table

Tool classDefaultApprovalAudit
Search and readScoped to user visibilityNone, loggedQuery plus result count
Draft and summarizeScoped to sessionNone, labeled draftInput hash plus output
Ticket and record writesNamed approverHuman confirmsBefore and after values
Data queriesRow-scoped, cappedOwner for new scopesQuery plus rows returned
Access and config changesDeniedTwo named approversFull change record

Worked example: the over-permissioned assistant

A fictional assistant (fictional) ships with wiki admin scope and writes a corrected policy page directly. Nobody approved; the edit history shows the agent. The fix takes an afternoon: user-scoped reads, draft-then-approve writes, full call log. The next review finds three blocked overreach attempts in the log, which is the system working. The RAG decision post sets the retrieval baseline; the AI-assisted post sets the review rule.

Checklist: agent permissions

  1. No tool runs with broader scope than its named users.
  2. Writes require a named approver and land in a log.
  3. Deny-by-default with named, dated exceptions.
  4. Weekly review of blocked attempts for the first month.

Straight answers

Frequently asked questions

Why do agents need permissions?

Because tools act: read documents, write tickets, query data. Without scopes, a helpful agent becomes an unreviewed admin.

What is the minimum setup?

Per-tool scopes, read-before-write separation, human approval for writes, and a log of every call with agent, tool, arguments and result.

Who approves agent writes?

A named human per tool class, before the write lands. Approvals are logged, revokable and reviewed weekly at first.

Bu sayfanın Türkçesi