Least-privilege checklist for AI agents
16 checks, one agent at a time. Tick what's in place; you'll get the gaps with a fix for each. Nothing you tick leaves your browser.
The checklist in full
Identity
- Each agent has its own identity, not a person's account or a shared service account. Create a dedicated identity per agent so its actions can be traced and revoked on their own.
- Each agent has a named human owner. Name an owner who answers for the agent's access and reviews it.
- The agent uses short-lived tokens or workload federation, not static keys. Move to OAuth tokens, managed identities or OIDC federation; rotate any static key that must remain.
Scopes
- Granted scopes match the agent's task, and unused grants were removed in the last 90 days. Compare granted and used permissions (the permission diff on this site) and remove the difference.
- No admin, owner, wildcard or tenant-wide scopes (for example Directory.ReadWrite.All or s3:*). Replace each broad grant with the specific actions the agent calls.
- Read-only access wherever the task only reads. Downgrade write scopes the agent never uses to their read-only form.
- Access is limited to specific resources (folders, repositories, mailboxes, tables), not everything. Use resource-level conditions, selected repositories or site-specific permissions.
- Delegated access (acting on behalf of users) covers only the users and data needed. Restrict delegated or domain-wide access to named users, groups or scopes.
Tools and actions
- The agent has only the tools its task needs. Remove unused tools and MCP servers from the agent's configuration.
- Actions that send, pay, delete or change access need a person's approval. Enforce approval in the tool or gateway, not with a sentence in the prompt.
- Spend and rate limits are enforced outside the model. Set per-action and per-day limits in the payment or API layer.
- Outbound destinations (email recipients, URLs, webhooks) are allow-listed. Block sending to destinations that aren't on an allow-list.
Runtime and evidence
- Every tool call is logged with the agent's identity. Log who (which agent), what, when and the result for every tool call.
- The agent can be switched off at once, with its credentials revoked. Document and test a one-step way to disable the agent and revoke its tokens.
- Separate identities are used for development, staging and production. Create one identity per environment; never reuse production credentials in testing.
Review
- Permissions are reviewed at least quarterly and whenever the agent's task changes. Put a recurring review on the owner's calendar and re-run the permission diff.
To check the scopes item with real data, use the permission diff.
Sources
- OWASP LLM06:2025 Excessive Agency
- NIST CSRC glossary: least privilege
- Checked 28 September 2026.