Learning/AI Agents — Complete Guide/Lesson 16
Chapter 6·Lesson 1 of 3·10 min

Permissions

Permissions

Design least-privilege agent capabilities and keep authorization outside the model.

Concept diagram
flowchart TD
U[Authenticated user] --> I[Trusted identity]
I --> T[Tenant/resource lookup]
M[Model request] --> V[Validate arguments]
V --> P[Authorize]
T --> P
P -->|Allowed| X[Execute]
P -->|Denied| D[Reject]

Lesson overview

Permissions

Agent permissions are an application security problem. A model can suggest an action, but it must never become the authority that decides whether a signed-in user is allowed to perform it.

Trusted identity

Every tool execution needs an identity derived from authentication. Do not allow model output to choose the tenant, user or role that controls access.

Capability boundaries

Give the agent only the capabilities required for the task. A support agent may read orders and create tickets but have no access to billing exports or administrative settings.

Resource-level authorization

Checking that a user is logged in is not enough. The application must verify access to the exact resource being requested, including tenant ownership where applicable.

Risk levels

Low-risk reads can usually be automated after authorization. Medium-risk changes may require confirmation. High-risk financial, deletion, identity or external-communication actions may require explicit approval.

Defense in depth

Enforce permissions in the tool registry, business service, database policies and infrastructure identity where appropriate. Multiple layers reduce blast radius when one layer is bypassed.

Never use a system prompt as the only authorization mechanism. “Only access the user's data” is guidance, not access control.

Learning path

Theory → Example → Code → Practice → Quiz → Challenge → Completion

0/6 done

Step 1

Theory

Permissions

Agent permissions are an application security problem. A model can suggest an action, but it must never become the authority that decides whether a signed-in user is allowed to perform it.

Trusted identity

Every tool execution needs an identity derived from authentication. Do not allow model output to choose the tenant, user or role that controls access.

Capability boundaries

Give the agent only the capabilities required for the task. A support agent may read orders and create tickets but have no access to billing exports or administrative settings.

Resource-level authorization

Checking that a user is logged in is not enough. The application must verify access to the exact resource being requested, including tenant ownership where applicable.

Risk levels

Low-risk reads can usually be automated after authorization. Medium-risk changes may require confirmation. High-risk financial, deletion, identity or external-communication actions may require explicit approval.

Defense in depth

Enforce permissions in the tool registry, business service, database policies and infrastructure identity where appropriate. Multiple layers reduce blast radius when one layer is bypassed.

Never use a system prompt as the only authorization mechanism. “Only access the user's data” is guidance, not access control.

Step 2

Example

Example

The model proposes update_deal(D123). The backend loads the authenticated user's tenant, checks access to D123, validates allowed fields and only then performs the update. The model never chooses the tenant boundary.

Step 3

Code

Authorization before execution

typescript
const identity = await requireUser(request);
const deal = await db.deals.find(args.dealId);
if (!deal || deal.tenantId !== identity.tenantId) throw new ForbiddenError();
assertAllowedFields(args.patch, ["stage", "note"]);
return db.deals.update(args.dealId, args.patch);

Step 4

Practice

Practice

Create a permission matrix with tools as rows and roles, resources and risk as columns. Mark every write action that requires confirmation or approval.

Step 5

Quiz

1. Who should determine tenant identity?

2. What is least privilege?

Step 6

Challenge

Challenge

Design a multi-tenant agent that can search customer records but cannot cross tenants. Explain exactly where tenant identity comes from and which layer rejects an invalid request.

Complete every stage

Work through every step in order, then the lesson will be marked complete.

Each chapter and subtopic has its own public URL under /ai-agent.