THE SHORT ANSWER
Give an AI agent its own identity, the minimum permissions and data needed, explicit action boundaries, approval gates for consequential steps, spending and rate limits, complete logs, monitoring, revocation and a named human owner. Never treat autonomy as accountability.
Use least privilege and separate credentials
Do not give an agent a person's broad session or shared administrator account. Use scoped service identity, short-lived authorization where supported, explicit allowlists and revocable credentials.
Evidence & context: Model Context Protocol
Reserve human approval for consequential actions
Approval can protect payments, external publication, deletion, access changes and sensitive communication. Show the proposed action, evidence, destination and effect—not a vague ‘continue?’ prompt.
Evidence & context: NIST AI Resource Center
Name the owner before execution
- Who approves the purpose and permissions?
- Who receives alerts and exceptions?
- Who can stop and revoke the agent?
- Who investigates harm and corrects affected records?
- Who decides whether it returns to service?
Continue with the detailed agent security guide.
Sources & further reading
- Generative Artificial Intelligence Profile (NIST AI 600-1)
NIST. Risk-management guidance, including confabulation. It does not establish a universal error rate.
- Model Context Protocol authorization
Model Context Protocol. Official authorization requirements and security considerations. Authentication and authorization remain implementation responsibilities; protocol support is not permission to expose a capability.
- AI Risk Management and Human-AI Interaction
NIST AI Resource Center. Official guidance on different human and AI decision roles and oversight. Appropriate reliance depends on context, consequence and system evidence.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗