Agent OAuth Scope Drift Detection
Added May 2026
Monitor AI agents’ OAuth permissions (scopes). Alert when permissions exceed the authorized set or arrive outside the formal approval process.
Objective
Prevent privilege escalation (an agent gaining more access than approved) by detecting when the scopes, or permissions, on an AI agent's OAuth access tokens grow beyond what was authorized.
Maturity Levels
Initial
OAuth tokens for AI agents are not inventoried; scope changes are not detected.
Developing
An inventory of agent OAuth tokens exists but is reviewed manually and infrequently.
Defined
Authorized scopes for each agent are documented at provisioning; automated alerts fire when live scopes diverge from the authorized set.
Managed
Scope drift is tracked as a metric; reports are reviewed by security on a defined cadence; unexplained drift triggers an access review.
Optimizing
Scope drift triggers automatic token revocation for expansions not on an approved list; agents must re-authorize through the formal provisioning process.
Evidence Requirements
What an auditor or assessor would expect to see for this control.
- —Agent OAuth token inventory with authorized scope baselines, provisioning dates, and approving humans
- —Configuration of automated scope drift detection (spotting unapproved permission growth) and alert thresholds
- —Alert history showing detected scope deviations and their disposition (accepted with justification, or revoked)
- —Agent deployment pipeline configuration confirming scope manifest requirement before go-live
- —Periodic access review records for agent OAuth tokens
Implementation Notes
Key steps
- Inventory all OAuth tokens (digital keys letting an agent act in another system) held by AI agents, including tokens obtained through connected tools (calendar, email, CRM, code repositories).
- For each token, document the authorized scope set at provisioning (when access was granted) and the approving human.
- Implement a daily or continuous scan that compares live token scopes against the authorized baseline; log and alert on any deviation.
- Treat any unrecognized scope as a potential security event, investigate before accepting or revoking.
- Add scope checks to agent deployment pipelines (the automated release process) so no agent goes live without a documented, approved scope manifest (list of permitted scopes).
Example Implementation
Sales automation agent with calendar, email, and CRM integrations
Agent OAuth Scope Baseline: Sales Automation Agent v2
| Integration | Authorized scopes | Provisioned | Approved by |
|---|---|---|---|
| Google Calendar | calendar.readonly | 2026-03-01 | T. Nguyen (Security) |
| Gmail | gmail.send, gmail.readonly | 2026-03-01 | T. Nguyen (Security) |
| Salesforce | read, write (Opportunities) | 2026-03-01 | T. Nguyen (Security) |
Drift alert, 2026-05-14: Live token shows gmail.modify added. Disposition: Not in baseline. Token revoked. Root cause: agent tool update silently requested broader scope. Vendor notified.
