Security & safety

Least Privilege

The principle of giving an AI agent only the access and permissions its current task needs, and nothing more.

Broad accessgranted just in caseRead, send and delete all emailWrite to the whole file systemAdmin API key that never expiresLeast privilegeonly what this task needsRead-only access to one folderHuman approval before sendingNarrow, short-lived keyIf the agent is tricked, the damage it can do is capped by the permissions it holds.

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/least-privilege

In plain terms

You give a house-sitter the key to the front door, not the safe combination and the car keys as well. The same goes for an agent: if the job is to read last month's invoices, it gets read access to that one folder, not write access to the whole finance drive.

Why it matters

With agents you have to assume that sooner or later the model will make a mistake or be manipulated. Least privilege decides how much that day costs. It is the cheapest and most dependable AI security control, and the one most often skipped, because broad access makes demos work faster.

Example

A meeting-scheduling agent could be given full access to the mailbox. Instead it gets permission to read calendars and create draft invitations. When a malicious invitation tells it to forward the CEO's emails, it simply lacks the ability.

Most often confused with

Least Privilege vs. Guardrails

Least PrivilegeRemoves abilities in advance
GuardrailsChecks behaviour as it happens

A guardrail watches what the agent does and tries to catch the bad cases. Least privilege means the agent never had the ability in the first place. Guardrails can miss; a permission that was never granted cannot be misused.

Under the hood

Applied to agents: scope each tool narrowly (read-only variants, single resources, row-level filters), separate read tools from write tools, issue short-lived credentials per task instead of standing ones, run the agent under its own identity and never under an administrator's or the user's full account, and narrow permissions further when untrusted content enters the context. Review tool lists as you would access-control lists. The OWASP name for the opposite condition is excessive agency: more functions, permissions or autonomy than the task requires.

Written by Mehmet Erkek · Last updated: