Least privilege on the AI Agents track. The agent should hold the smallest permission that finishes the task. A read-only research agent does not get a write token. A refund agent gets refund, not 'admin'.
This lesson assumes you already worked through Safe retries.
The idea in practice
Issue short-lived credentials per run, scoped to the tools in that run. Drop them when the run ends. Log the scope.
A concrete check
goal = {
'track': 'AI Agents',
'lesson': 'Least privilege',
}
checks = [
'input available at decision time',
'score matches the real decision',
'failure case written down',
]
print(goal['lesson'])
for item in checks:
print('-', item)
Run the sketch locally if you have Python. The printout is a reminder of the checks, not a trained model. Replace the strings with the real inputs from your own example before you treat it as a design.
What usually goes wrong
A long-lived admin key in the agent process turns a prompt injection into a full breach. When this happens, stop adding parameters or tools. Fix the check, the data, or the permission, then run the same example again.
What to write down
- The input you are allowed to use at decision time.
- The output and the score or pass rule.
- One failure you will test on purpose.
- What you will not claim the system can do.
Practice
For a support agent, list read scopes and write scopes. Justify each write.
Self-check
- Say Least privilege in one sentence that mentions an input and an output.
- Name the failure mode in this lesson and the check that would catch it.
Done when: you can explain this lesson without the page open, and you have a written failure case.