THE SHORT ANSWER

Give an AI agent its own identity, the minimum permissions and data needed, explicit action boundaries, approval gates for consequential steps, spending and rate limits, complete logs, monitoring, revocation and a named human owner. Never treat autonomy as accountability.

Model authority as capabilities

Agent capability review
CapabilityControl question
ReadWhich records and fields are necessary?
WriteWhat can be created or changed?
CommunicateWho may receive a message or publication?
SpendWhat amount, rate and counterparty are allowed?
DelegateMay the agent call another tool or agent?

Use least privilege and separate credentials

Do not give an agent a person's broad session or shared administrator account. Use scoped service identity, short-lived authorization where supported, explicit allowlists and revocable credentials.

Evidence & context: Model Context Protocol

Reserve human approval for consequential actions

Approval can protect payments, external publication, deletion, access changes and sensitive communication. Show the proposed action, evidence, destination and effect—not a vague ‘continue?’ prompt.

Evidence & context: NIST AI Resource Center

Name the owner before execution

  • Who approves the purpose and permissions?
  • Who receives alerts and exceptions?
  • Who can stop and revoke the agent?
  • Who investigates harm and corrects affected records?
  • Who decides whether it returns to service?

Continue with the detailed agent security guide.

Sources & further reading

  1. Generative Artificial Intelligence Profile (NIST AI 600-1)

    NIST. Risk-management guidance, including confabulation. It does not establish a universal error rate.

  2. Model Context Protocol authorization

    Model Context Protocol. Official authorization requirements and security considerations. Authentication and authorization remain implementation responsibilities; protocol support is not permission to expose a capability.

  3. AI Risk Management and Human-AI Interaction

    NIST AI Resource Center. Official guidance on different human and AI decision roles and oversight. Appropriate reliance depends on context, consequence and system evidence.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗