Access Control
What can agents touch?
Review identity, scope, exposed actions, and approval gates before widening access.
Step 1 of 4
Identity
How does the agent act?
Pick the identity model.
What this checks
Identity
Who the agent acts as decides whether an action can be traced to a person, and whether removing that person removes the agent’s access.
- Shared token · One broad API key or bot token
- Service account · Agent acts as a service principal
- Per-user OAuth · Actions inherit the requester
- IdP groups · Okta, Entra, Google groups, etc.
- IGA-reviewed assignments · SailPoint, Saviynt, Okta IGA, Entra ID Governance
Scope
Scope is the blast radius. A broad scope turns one wrong tool call into a problem in every system the agent can reach.
- All tools available · Agent can discover/use broad toolset
- Tenant-wide scope · Same scope for everyone in tenant
- Team / project scope · Bounded to team or project resources
- Per-user scope · Limited to requester permissions
- Per-workflow allowlist · Different tools/actions per workflow
- Time-boxed elevation · Temporary access with expiry
Actions
Reading context and changing production are different risks. The review weighs production changes, data exports and identity changes most heavily.
- Read context · Tickets, docs, logs, repo, chat
- Comment / draft · Post notes, comments, drafts
- Create or update records · Issues, PRs, tickets, docs
- Trigger jobs · CI, indexing, sync, automation
- Production action · Deploy, rollback, restart, config write
- Data export · Bulk customer/company data movement
- Identity change · Invite, revoke, group or role changes
Approval
An approval only controls an action if it happens before the action runs and leaves a record. Logging afterwards is evidence, not a gate.
- No approval gate
- Chat confirmation · Human says yes in Slack/Teams/Discord
- Admin policy · Predefined allow/deny/approval rules
- HITL approval queue · Recorded approval before execution
- Break-glass path · Emergency elevation with review
- Audit only · Actions logged but not gated
How to read your result
- Open-ended
- The agent’s reach is set by whatever token it holds. Fix identity and scope before adding any write action.
- Scoped but manual
- Access is bounded, but approvals depend on people remembering to ask. Move risky actions behind a recorded policy.
- Policy-ready
- Identity, scope and approvals are in place. Widen access one workflow at a time.
Questions
Should AI agents use a service account or per-user OAuth?
Per-user OAuth when the agent acts for a person, so it inherits that person’s permissions and loses them when they leave. A tightly scoped service account is fine for background jobs, but not with a shared token behind it.
Is an audit log enough to control what an agent does?
No. An audit log tells you what happened afterwards. Production changes, data exports and identity changes need an approval that runs before the action.
What is a per-workflow allowlist?
A list of the tools and actions one job needs, and nothing else. The triage agent can read logs and post to the incident channel; it cannot deploy.

