Does your AI agent have more access than it needs?
Paste the permissions the agent was granted and the ones it actually uses. You'll see what to remove, what to narrow to read-only, which grants are high-risk, and the least-privilege list to replace them with.
Nothing leaves your browser. Paste permission names only, never keys or tokens.
How it compares
- AWS IAM: wildcards are expanded against what's used, so
s3:*used only fors3:GetObjectis flagged to narrow. - Microsoft Graph:
Mail.ReadWritecoversMail.Read, and.Allcovers the narrower form; either way the broader grant is flagged when only the narrow one is used. - Google: full scopes such as
https://mail.google.com/cover their readonly forms. - GitHub: admin covers write, write covers read, per permission.
Then run the least-privilege checklist for AI agents, and audit every machine identity with the Non-Human Identity Audit.
Why least privilege matters more for agents
An agent acts on instructions it reads, including instructions an attacker hides in a document or web page. Whatever it's allowed to do, an injected instruction can try to do. OWASP lists this as LLM06:2025 Excessive Agency: excessive functionality, permissions and autonomy. NIST defines least privilege as giving each entity the minimum resources and authorisations it needs to do its job.
Questions
Is anything I paste sent anywhere?
No. The comparison runs in this page, and the page blocks every outgoing request. Paste permission names only, never keys or tokens.
Which permission formats does it understand?
AWS IAM policy JSON (including wildcards such as s3:* and s3:Get*), Microsoft Graph permissions (Read vs ReadWrite, .All), Google OAuth scopes (readonly vs full), GitHub fine-grained permissions (read, write, admin) and plain lists, one per line or comma separated.
Where does the needed list come from?
From what the agent actually used: AWS IAM last-accessed information or IAM Access Analyzer policy generation, sign-in and audit logs, or the API calls in the agent's code. The guide on this site shows where to find it for each platform.
How is the least-privilege score calculated?
It's the share of granted permissions that aren't excess. A grant is excess if nothing in the needed list uses it, or if it's broader than everything it's used for (for example Mail.ReadWrite when only Mail.Read is used).