Permissions and approvals
Least-privilege tool access and **human approval** gates for risky agent actions.
What it is
Least-privilege tool access and human approval gates for risky agent actions.
Why it matters
An agent with send-email + delete-db credentials is an incident waiting to happen.
How it works (plain)
Classify tools by risk → default deny → allowlist by role → confirm irreversible actions → audit logs.
Try it
List your agent’s tools in three buckets: auto / confirm / never.
Myths
- ⚠️ Myth: A polite system prompt replaces permissions.
- ✓ Reality: Enforcement beats instructions under attack.
Sources
- Course 10 tool-use; Course 19 security; OWASP LLM Top 10
- https://owasp.org/www-project-top-10-for-large-language-model-applications/ ↗
