# What is least privilege for AI agents?

Least privilege for AI agents means giving an agent only the access its current task needs, e.g. a scoped token, and nothing that outlives the task.

Last updated September 29, 2026, 8 min read

## Learning objectives

After reading this article you will be able to:

-   Define least privilege
-   Explain how it applies to tools, files, tokens, and network
-   Identify the access a coding agent needs

## Related content

-   [What is a sandbox for AI agents?](https://specstory.com/learning/environments/ai-sandbox)
-   [What is approval fatigue in coding agents?](https://specstory.com/learning/environments/approval-fatigue)
-   [What is prompt injection in coding agents?](https://specstory.com/learning/environments/prompt-injection-in-coding-agents)
-   [What is the difference between containers, gVisor, and microVMs?](https://specstory.com/learning/environments/containers-vs-gvisor-vs-microvms)

## What is least privilege for AI agents?

Least privilege for AI agents is the security principle that an agent gets only the tools, files, credentials, and network access its current task requires. That access ends when the task ends. A [coding agent](https://specstory.com/learning/ai-coding/coding-agent) acts with whatever access it holds, so that access caps the damage a wrong or injected command can do.

Jerome Saltzer and Michael Schroeder stated the principle in [a 1975 paper](https://doi.org/10.1109/PROC.1975.9939). Their wording was "Every program and every user of the system should operate using the least set of privileges necessary to complete the job." They wrote that it mainly limits damage from an accident or error.

The US National Institute of Standards and Technology (NIST) glossary [defines least privilege](https://csrc.nist.gov/glossary/term/least_privilege) as giving users, and processes acting for users, only the access their tasks need.

Least privilege does not stop [prompt injection](https://specstory.com/learning/environments/prompt-injection-in-coding-agents), but it limits what an injected instruction can do. The Open Worldwide Application Security Project (OWASP) lists excessive agency among its [top 10 risks](https://genai.owasp.org/llm-top-10/) for language model applications. One cause is excessive permissions, e.g. a tool that only reads a database but connects with an identity that can also delete rows. Teams enforce least privilege with permission rules, a [sandbox](https://specstory.com/learning/environments/ai-sandbox), and scoped credentials.

## How does least privilege work for a coding agent?

Least privilege for a coding agent starts from the task, not from the developer's account. A typical setup has five steps:

1.  A developer states the task, e.g. a fix for one failing test.
2.  The developer or a team policy lists the tools, files, tokens, and hosts the task needs.
3.  The software that runs the agent starts it with only that access and a credential that expires with the task.
4.  When the agent calls a tool outside the grant, the call fails or waits for a person's approval, which is a [human-in-the-loop](https://specstory.com/learning/ai-coding/human-in-the-loop) check.
5.  When the task ends, the credential expires, and the environment is deleted or reset.

The grant limits four kinds of access:

-   **Tools.** The agent can call only the commands and tools the task uses, e.g. the project's npm scripts, which the Claude Code allow rule `Bash(npm run *)` matches. That rule also allows any script the agent adds to `package.json`. Each [Model Context Protocol](https://specstory.com/learning/ai-coding/model-context-protocol) (MCP) server adds tools, so a task gets only the servers it uses.
-   **Files.** The agent can change only a working copy of the project, and it cannot read files that hold secrets, e.g. SSH keys. Some agents also offer a read-only mode, e.g. the Codex `read-only` sandbox mode, in which the agent can inspect files but not edit them without approval.
-   **Tokens.** Each credential works on one resource, allows the fewest actions, and expires soon after the task, e.g. a token for one repository.
-   **Network.** The agent can reach only the hosts the task needs, usually the package registry, the code host, and the model's API. This limit is called [egress control](https://specstory.com/learning/glossary#egress-control).

## What is an example of least privilege for an agent?

Here is an illustrative example. Acme Co. sells furniture online. A developer at Acme asks a coding agent to "Let customers edit their delivery address during checkout." The developer's account can push to every Acme repository, and the developer's `.env` file points at a shared staging database. The agent gets a smaller grant:

1.  The developer starts the agent in a [dev container](https://specstory.com/learning/environments/docker-vs-devcontainer-vs-vm) with a fresh clone of the web store and a test database of fake customers.
2.  The clone has no `.env` file, and the agent's rules allow the project's npm scripts.
3.  The container's token can push branches and open pull requests on `acme/web-store` only, and expires after 1 hour.
4.  A network proxy allows only the package registry, the code host, and the model's API.
5.  A test fails on stale data, and the agent runs `npm run db:reset`. Without a `.env` file, the command clears the test database, the only database the container can reach.
6.  The agent opens a pull request, which needs a reviewer's approval to merge.
7.  The developer deletes the container, and the token stops working when its hour ends.

On the developer's laptop, the same command would have read the `.env` file and cleared the shared staging database. This example is simplified. A real project would also review the grant whenever a task needs another outside service.

## What are scoped and short-lived credentials?

A scoped credential is a token or key that works only on named resources and for named actions, e.g. read access to one repository. A short-lived credential expires minutes or hours after it is issued, so a copy that leaks soon stops working. An agent needs both, because an injected instruction can expose any credential the agent holds.

A developer's personal token is usually the opposite. It can do everything the developer can do and often lasts until someone revokes it. Common tools issue credentials of both kinds:

-   **Code host tokens.** A GitHub App installation token can be limited to chosen repositories and permissions, and it expires after 1 hour.
-   **Workflow tokens.** In [GitHub Actions](https://specstory.com/learning/ci-cd/github-actions-checks), an agent's job gets a `GITHUB_TOKEN` that works only on the workflow's repository and expires when the job finishes or reaches its maximum lifetime. The workflow's `permissions` key can narrow it further.
-   **Cloud credentials.** A workflow can use OpenID Connect (OIDC) to get a cloud access token that is valid for a single job, instead of storing a cloud key. Outside a workflow, an agent can get temporary credentials from a cloud role instead of a developer's access key.

A separate credential also gives the agent its own identity, so logs show which actions the agent took. If a credential still ends up in the code, [secret scanning](https://specstory.com/learning/glossary#secret-scanning) can find it in the diff so someone can revoke it.

## What are the limits of least privilege?

Least privilege limits what a mistake or an attack can reach, not whether the agent's work is correct. It also has these limits:

-   **Allowed access can still be misused.** A token that can push branches lets an injected instruction push a backdoor.
-   **Read access can leak.** A read-only agent can still read secrets and send them to any host the network allows.
-   **Agent rules are not an operating system boundary.** [Claude Code's documentation](https://code.claude.com/docs/en/permissions) says a deny rule for shell commands matches the command text the agent writes and "isn't a security boundary around the program." A command wrapped in `sh -c` can get past it. A sandbox applies its limits to every process inside it.
-   **The right grant is hard to set in advance.** A grant that is too narrow stops the agent often, and people then approve prompts without reading them, a pattern called [approval fatigue](https://specstory.com/learning/environments/approval-fatigue).
-   **Grants grow over time.** Access added for one task tends to stay until someone reviews the grants and removes it. This is called privilege creep.

## How is least privilege different from sandboxing?

Least privilege is a principle about how much access to grant. A sandbox limits which files and hosts code can reach, so it applies least privilege to files and the network. Least privilege also covers what each credential can do, which a sandbox does not limit. A token inside the sandbox works on the code host the same way it does outside.

The two meet in the sandbox's settings, because each folder, secret, and host let into a sandbox is a grant. How strictly the sandbox holds those limits depends on its isolation type, e.g. a [container](https://specstory.com/learning/environments/containers-vs-gvisor-vs-microvms) shares the host's kernel.

## FAQs

### Should an agent use a developer's own credentials?

An agent should usually not use a developer's own credentials, because they can do everything the developer can do and often last until someone revokes them. A separate credential for the agent, e.g. a temporary one from a cloud role, can be limited to the task and expire with it. The agent's actions then show under its own identity.

### What is the principle of least privilege?

The principle of least privilege is a security rule that every user and every program should work with the smallest set of access rights its job needs. The rule predates AI agents by decades. Its main effect is to limit the damage that an accident or an error can cause.

### How does least privilege limit prompt injection?

Least privilege limits prompt injection by shrinking what an injected instruction can do, not by stopping the injection. An agent with no production credentials cannot delete production data directly, even when it follows planted text. An agent that can reach only approved hosts cannot send data to other hosts.

### Can an agent be given read-only access?

An agent can be given read-only access, e.g. a token that can read one repository but not push to it. Some coding agents also have a read-only mode that blocks file edits. Read access still lets the agent read secrets, so it works best with limits on where the agent can send data.

---

Source: [Least privilege for AI agents | SpecStory](https://specstory.com/learning/environments/least-privilege-for-ai-agents)
