OWOnly What It NeedsAgent Security Lab
Security principle

Least privilege for AI agents

Give an agent the smallest useful context for one task—not permanent access to the complete source.

01

The agent asks; policy decides

A language model may explain what it needs and why. A deterministic policy gateway owns the decision, field limits, expiry and approval boundary.

02

A task is not an identity

The task receives a temporary context capsule. It does not inherit broad permissions merely because the same agent completed an earlier task.

03

Denial is a valid result

When the request is too broad, expired or beyond its read limit, the system stops visibly instead of silently widening access.

See the boundary work

Replay the fictional invoice.

Open the experiment →