FDE Foundations · Module 8: Agents & Tools
Permissions and Approval Flows
Agents act with someone's authority. Bind every action to an identity, apply least privilege per tool, and require explicit human approval for the actions you cannot afford to get wrong.
10 min reading
Objectives
- Bind agent actions to user identity and least privilege
- Gate sensitive actions behind explicit approval
- Log every decision point for audit
Identity and least privilege
The agent never holds a god account. Each tool call executes with the permissions of the requesting user or a narrowly scoped service identity, so "the agent could do it" never becomes "the agent did it beyond the user's rights". Credential scope per tool, audited, rotating.
Approval gates
Classify actions: safe (read), reversible (draft, stage), sensitive (send money, delete, email customers). Sensitive actions pause for explicit approval with a human-readable summary of what will happen. Design the approval UI as part of the system, not an afterthought: what is being proposed, on whose behalf, and the two buttons that decide.
The audit trail
Log the full chain: user request, tool calls with arguments, results, approvals with approver identity, final effects. This trail answers the only two questions that matter after an incident: what did the agent do, and who allowed it.
Failure drill
Rehearse the failure: the agent misroutes a refund to the wrong order. With gates and logs, it is a caught error and a fix. Without them, it is an unexplained customer call. The drill, run as a tabletop exercise with the customer, sells the architecture better than any diagram.
Quick check
An optional 2-3 question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Exercise
Design the permission and approval plan for a fictional expense-report agent: identity binding, the three action classes with examples, the approval summary line, and the audit log fields.
Pass criteria
Identity binding stated, three classes with concrete examples, approval summary includes amount and target, and audit fields allow reconstructing any decision.