Least privilege gets harder with agents
Traditional least privilege limits a user or service to what it needs. Agents make the problem more dynamic: they may select tools, create arguments, and move through multi-step workflows on behalf of a person.
Make boundaries specific
Useful boundaries can be applied at the tool and action level: separate read from write access, scope access to the task, require approval for sensitive operations, and avoid exposing upstream credentials directly to the agent.
Short-lived authority is easier to reason about
Where the surrounding system supports it, scoped or revocable credentials reduce the blast radius of an action. Audit records then connect the request, decision, approval, and outcome.
Least privilege is not a single switch. It is a way to make agent authority explicit, bounded, and reviewable.
The right question is not “Can this agent reach the system?” It is “What is the smallest action authority this task requires?”