Agent Permission Boundaries
Added May 2026
Define and enforce the tools, APIs, data sources, and actions each agent may use, granting only the minimum needed (least privilege).
Objective
Limit the damage from agent errors or compromise (an attacker taking control) by ensuring agents can only access what they need for their defined task.
Maturity Levels
Initial
Agents are granted broad permissions by default; no formal permission review exists.
Developing
Permission restrictions are applied informally to some agents but not consistently documented.
Defined
Every agent has a documented permission manifest; access is provisioned through a formal request and approval process.
Managed
Permissions are reviewed quarterly; unused permissions are revoked; unusual access triggers alerts.
Optimizing
Permissions adjust automatically to the task the agent is currently doing and are automatically reduced after task completion.
Evidence Requirements
What an auditor or assessor would expect to see for this control.
- —Permission manifest for each deployed agent listing permitted resources and explicit denials, signed by the Chief Information Security Officer (CISO) or designated approver
- —Access provisioning (granting) records showing formal request and approval before permissions were granted or expanded
- —Quarterly permission review records confirming unused permissions were identified and revoked
- —Permission use logs showing access events by agent identity over a sample period
- —Alert or investigation records for any permission exercised for the first time after an extended dormant period
Implementation Notes
Key steps
- Define a permission manifest for each agent: list every tool, API endpoint (connection to another system), file folder, and database it may access, and explicitly deny everything else.
- Apply task-scoped tokens (access credentials limited to one task) where possible: an agent that only reads a calendar should not hold credentials that let it edit the calendar.
- Implement permission review gates (a required sign-off step) before deploying new agent capabilities; treat capability expansion like a software release.
- Log every permission use; alert on first-use of permissions that haven't been exercised in the prior 30 days.
Example Implementation
Enterprise deploying an AI agent for internal IT helpdesk automation
Agent Permission Manifest: IT Helpdesk Agent v1.2
Agent purpose: Answer employee IT questions and create/update helpdesk tickets
| Resource | Permission | Scope Restriction |
|---|---|---|
| ServiceNow tickets | Read, Create, Update | Employee's own tickets only; no bulk operations |
| IT knowledge base | Read | Public articles only |
| Active Directory | Read | Name and department lookup only |
| Send | Reply-only; no new external threads | |
| File system | None | Explicitly denied |
| HR systems | None | Explicitly denied |
| Finance/billing | None | Explicitly denied |
Token type: Short-lived OAuth (1-hour TTL), scoped per session Permission review cadence: Quarterly Unused permission alert: Any permission not exercised in 30 days triggers review for removal Last reviewed: 2026-03-01 · Approved by: CISO Office
