AI agent permissions and least privilege explained
Short answer
Least privilege for an AI agent is not a paragraph in the system prompt. It is a unique identity, the smallest set of tools that can do the job, per-tool scopes (read versus write, specific paths), authorization the model cannot skip, and a separate promotion when you later need write. OWASP’s AI Agent Security Cheat Sheet is the engineering language. Microsoft’s least-privilege pattern is the identity language. Both say the same thing: never rely on the model to enforce permissions.
This page is the permissions cut of AI agent security for business (safeguards 4–6). It is not a CMMC or FedRAMP certificate. Model Context Protocol (MCP) is a way to expose tools. It is not, by itself, a permission model.
What the prompt can and cannot do
Instructional: write the intended scope (“this agent may retrieve tickets in project X; it may not delete; it may not mail customers”). Put it in the inventory and the acceptable-use policy so a human can audit it.
Technical: the agent identity does not have the Graph permission, the MCP tool is not registered, the orchestrator rejects send without an approval record, and the downstream API re-checks the token. If any of those is missing, the prompt is decoration.
July 2026 lab disclosures (OpenAI ExploitGym evaluations; Anthropic cybersecurity CTF evaluations) are specialized tests, not ChatGPT-at-work. They are still the object lesson: a model told it is in a box will test the box. Containment is infrastructure. Detail and primary links live on the pillar, not here.
What OWASP actually asks for
The cheat sheet (retrieved August 2026) groups tool access under least privilege:
- Grant the minimum tools required for the specific task.
- Per-tool permission scoping — read-only versus write, specific resources.
- Separate tool sets for different trust levels (internal versus user-facing).
- Explicit tool authorization for sensitive operations.
- Human-in-the-loop for high-impact actions; do not let agents make those decisions unsupervised.
That is the control set. It is not a product SKU and it is not a certificate.
MCP permissions caution
OWASP publishes a good/bad pair. Do not ship the bad one.
| Pattern | What it is | What to do |
|---|---|---|
| Bad | execute_command with allowed_commands: "*" | That is an unrestricted shell. Do not give it to a production agent. |
| Good | file_reader with allowed_paths, allowed_operations: ["read"], blocked secret patterns | Scope path and operation. Block .env, keys, PEM, *secret*. |
MCP servers advertise tools. Someone still has to decide which tools this agent may call, on which identity, with which scopes. Connecting Claude or Cursor to a company MCP endpoint without that decision is how a coding assistant becomes a write path. Zoom’s MCP setup is a worked example of OAuth and scopes in Connect Claude AI agents to Zoom MCP; the permission rule is the same on any MCP server.
Read before write
Promote capability in order, the way you would promote a new vendor integration:
- Retrieve only. Search, summarize, cite. Log every retrieval (source, scope, correlation ID).
- Draft only. The agent may write a ticket body or an email draft that a human sends.
- Write a named action. Create-or-update on one object type. Not delete. Not admin. Not bulk, unless a human approved the bulk.
- Send / pay / delete only with orchestrator-enforced approval and a tested stop.
Microsoft’s ticket example is the same sequence: separate the read role from the write role; allowlist create-or-update; block delete and admin; require human approval for bulk updates; log writes with role, scope and correlation IDs. An agent that can read a contract should not, on day one, be able to file it, mail it, or pay against it.
Effective access, not the role name
Microsoft warns about two ways least privilege dies in practice:
- Permission creep — broad roles granted to unblock a pilot, never narrowed.
- Stacked “narrow” roles — each looks fine; together they are tenant-wide.
Review aggregate and effective permissions across tools and downstream systems. Ask: if this agent is prompt-injected, what can it actually do end-to-end? If the answer includes export, delete, or privilege change, those actions need an allowlist plus approval or JIT elevation.
Approval that cannot be skipped
Microsoft: human-in-the-loop enforced in orchestrator logic, not in the prompt. OWASP: explicit approval for financial, administrative, or externally visible operations. Implementation shape:
- The tool adapter refuses send/write/pay/delete unless an approval record exists.
- The model never sees a “send anyway” tool.
- The audit log records who approved, what, and under which correlation ID.
If a developer can comment out the gate in a prompt template, it was never a gate.
OAuth grants and unsanctioned local agents are how write paths appear without a design review. The Shadow AI Assessment is a private first pass; the inventory article is the living list the allowlist should match.
Frequently asked questions
Can the system prompt be the permission system?
No. A prompt is instructional. Least privilege is technical: identity, allowlisted tools, per-tool scopes, and authorization checks in code or policy engines that the model cannot skip. Microsoft says to re-validate at every hop and not to rely on the orchestrator alone.
What does read-before-write mean for an agent?
Give the agent a retrieval role first. Only after that path is logged and reviewed do you grant a separate write role for a named action (create ticket, draft but not send). OWASP calls this per-tool permission scoping. Microsoft’s ticket example separates the read role from the write role and blocks delete and admin by default.
Why is unrestricted MCP dangerous?
OWASP’s bad example is an execute_command tool with allowed_commands: "*". That is a shell. The good example is a file_reader limited to a path, read-only operations, and blocked secret patterns. MCP is a way to expose tools; it is not a permission model. You still have to scope what each tool may do.
Does least privilege certify us for CMMC or FedRAMP?
No. Scoping tools is risk management, not a certificate. It does not make the organization CMMC Level 2 certified or FedRAMP authorized.
Is human-in-the-loop a prompt instruction?
No. Microsoft’s secure-agentic guidance requires deterministic human-in-the-loop in orchestrator logic. OWASP requires explicit approval for financial, administrative, or externally visible operations. If the model can skip the gate, there is no gate.
Should developers and customer-facing agents share a tool set?
No. OWASP: use separate tool sets for different trust levels (for example internal versus user-facing). A debug shell that is fine in a lab is not fine behind a customer chat.
What about aggregate permissions?
Microsoft warns that many “narrow” roles stacked together can create overly broad effective access. Review the agent’s end-to-end capability across tools, not each role in isolation.
Where does this sit in the 12 safeguards?
Safeguards 4 (least privilege in the platform), 5 (read before write), and 6 (approval in the orchestrator) of AI agent security for business. The Microsoft 365 cut is How to secure AI agents connected to Microsoft 365.
Related articles
- AI agent security for business: 12 safeguards — the pillar.
- How to secure AI agents connected to Microsoft 365 — Entra roles, OAuth, Purview as available.
- How to build an enterprise AI inventory — the list the allowlist should match.
- What separates production-ready agents from demos? — architecture behind HITL and kill switch.
References
- OWASP Cheat Sheet Series — AI Agent Security— minimum tools, per-tool scoping, MCP good/bad examples, HITL. Retrieved August 2026.
- Microsoft Learn — Least privilege for AI agents— identity, aggregate permissions, allowlists, re-validate at every hop, kill-switch metric.
- Microsoft Learn — Secure autonomous agentic AI systems— deterministic HITL in orchestrator logic, not the prompt.
Managed network and communications services, SDVOSB. Least privilege is an identity and tool-allowlist problem. This page is not a CMMC or FedRAMP certificate. Support: (888) 989-4872 · support@adampulse.us