Give the Agent the Smallest Useful Toolset
Explain how the principle of least privilege applies to tool selection and permission scope for agents.
Least privilege means giving the agent the smallest set of powers that still lets it do the job well. For agents, that usually means designing in layers: read first, then draft, then write, then send or execute. Each additional layer changes the cost of a mistake. A wrong draft can be reviewed. A wrong database write or outbound message becomes a business event. This principle works because language models are good at plausible action. If the permissions are too broad, the model does not need malicious intent to create harm. It only needs one weak inference, one stale record, or…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in