An agent with the fewest rights possible

Complete plan

An AI agent often acts with your own rights. Give it only the rights the task needs, have a human approve anything that can't be undone, and keep a record of every action, with an owner and an off switch.

  • 2 min
  • 3-question check
  • English · Français
  • Attestation

You will be able to

  • Understand that an agent connected with your account acts with all your rights, and spot the three excesses: too many tools, too many rights, too much autonomy
  • Give an agent its own identity, read-only by default, only the access it needs, and test it first without real data
  • Have a human approve any irreversible action (pay, delete, send outside, change rights), log every action, name an owner and plan an immediate stop

The module

2 min
  1. An agent with the fewest rights possible 2 min
  2. Knowledge check

    3 questions, pass mark 80 %. Explanations after each answer; you can try again.

  3. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Sources
  • OWASP Top 10 for LLM Applications 2025, LLM06 Excessive Agency : trois causes, « excessive functionality, excessive permissions, excessive autonomy » ; mesures : réduire les extensions, leurs fonctions et leurs droits au strict nécessaire, approbation humaine des actions à fort impact ; la journalisation limite les dégâts, elle ne les empêche pas
  • Google, Google's Approach for Secure AI Agents, mai 2025 : les agents agissent pour des humains « en héritant de leurs droits » ; confirmation humaine explicite pour les actions critiques ou irréversibles (suppression de gros volumes de données, transactions financières importantes, réglages de sécurité) ; journaliser les outils appelés et leurs paramètres
  • Anthropic, Our framework for developing safe and trustworthy agents (4 août 2025) : approbation humaine avant les décisions à fort enjeu, possibilité d'arrêter l'agent à tout moment (exemple de Claude Code) ; Beyond permission prompts (20 oct. 2025) : le risque de « approval fatigue »
  • Microsoft, Best practices for Microsoft Entra Agent ID (27 mars 2026) : une identité par agent, un responsable nommé, le moindre privilège, des tests hors production, un arrêt d'urgence (« kill-switch »)
  • À retenir : un agent a sa propre identité, ou à défaut une connexion limitée au strict nécessaire (jamais un compte administrateur), la lecture seule par défaut, les seuls accès utiles ; il prépare, un humain valide l'irréversible ; chaque action est journalisée et relue ; un responsable nommé peut l'arrêter et retirer ses accès tout de suite

Version 1 · updated October 6, 2026