An agent with the fewest rights possible
Complete plan
An AI agent often acts with your own rights. Give it only the rights the task needs, have a human approve anything that can't be undone, and keep a record of every action, with an owner and an off switch.
- 2 min
- 3-question check
- English · Français
- Attestation
You will be able to
- Understand that an agent connected with your account acts with all your rights, and spot the three excesses: too many tools, too many rights, too much autonomy
- Give an agent its own identity, read-only by default, only the access it needs, and test it first without real data
- Have a human approve any irreversible action (pay, delete, send outside, change rights), log every action, name an owner and plan an immediate stop
The module
2 min-
An agent with the fewest rights possible 2 min
-
Knowledge check
3 questions, pass mark 80 %. Explanations after each answer; you can try again.
-
Attestation
One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.
Sources
- OWASP Top 10 for LLM Applications 2025, LLM06 Excessive Agency : trois causes, « excessive functionality, excessive permissions, excessive autonomy » ; mesures : réduire les extensions, leurs fonctions et leurs droits au strict nécessaire, approbation humaine des actions à fort impact ; la journalisation limite les dégâts, elle ne les empêche pas
- Google, Google's Approach for Secure AI Agents, mai 2025 : les agents agissent pour des humains « en héritant de leurs droits » ; confirmation humaine explicite pour les actions critiques ou irréversibles (suppression de gros volumes de données, transactions financières importantes, réglages de sécurité) ; journaliser les outils appelés et leurs paramètres
- Anthropic, Our framework for developing safe and trustworthy agents (4 août 2025) : approbation humaine avant les décisions à fort enjeu, possibilité d'arrêter l'agent à tout moment (exemple de Claude Code) ; Beyond permission prompts (20 oct. 2025) : le risque de « approval fatigue »
- Microsoft, Best practices for Microsoft Entra Agent ID (27 mars 2026) : une identité par agent, un responsable nommé, le moindre privilège, des tests hors production, un arrêt d'urgence (« kill-switch »)
- À retenir : un agent a sa propre identité, ou à défaut une connexion limitée au strict nécessaire (jamais un compte administrateur), la lecture seule par défaut, les seuls accès utiles ; il prépare, un humain valide l'irréversible ; chaque action est journalisée et relue ; un responsable nommé peut l'arrêter et retirer ses accès tout de suite
Version 1 · updated October 6, 2026