Permissions
Permissions
Design least-privilege agent capabilities and keep authorization outside the model.
flowchart TD U[Authenticated user] --> I[Trusted identity] I --> T[Tenant/resource lookup] M[Model request] --> V[Validate arguments] V --> P[Authorize] T --> P P -->|Allowed| X[Execute] P -->|Denied| D[Reject]
Lesson overview
Permissions
Agent permissions are an application security problem. A model can suggest an action, but it must never become the authority that decides whether a signed-in user is allowed to perform it.
Trusted identity
Every tool execution needs an identity derived from authentication. Do not allow model output to choose the tenant, user or role that controls access.
Capability boundaries
Give the agent only the capabilities required for the task. A support agent may read orders and create tickets but have no access to billing exports or administrative settings.
Resource-level authorization
Checking that a user is logged in is not enough. The application must verify access to the exact resource being requested, including tenant ownership where applicable.
Risk levels
Low-risk reads can usually be automated after authorization. Medium-risk changes may require confirmation. High-risk financial, deletion, identity or external-communication actions may require explicit approval.
Defense in depth
Enforce permissions in the tool registry, business service, database policies and infrastructure identity where appropriate. Multiple layers reduce blast radius when one layer is bypassed.
Never use a system prompt as the only authorization mechanism. “Only access the user's data” is guidance, not access control.
Learning path
Theory → Example → Code → Practice → Quiz → Challenge → Completion
Step 1
Theory
Permissions
Agent permissions are an application security problem. A model can suggest an action, but it must never become the authority that decides whether a signed-in user is allowed to perform it.
Trusted identity
Every tool execution needs an identity derived from authentication. Do not allow model output to choose the tenant, user or role that controls access.
Capability boundaries
Give the agent only the capabilities required for the task. A support agent may read orders and create tickets but have no access to billing exports or administrative settings.
Resource-level authorization
Checking that a user is logged in is not enough. The application must verify access to the exact resource being requested, including tenant ownership where applicable.
Risk levels
Low-risk reads can usually be automated after authorization. Medium-risk changes may require confirmation. High-risk financial, deletion, identity or external-communication actions may require explicit approval.
Defense in depth
Enforce permissions in the tool registry, business service, database policies and infrastructure identity where appropriate. Multiple layers reduce blast radius when one layer is bypassed.
Never use a system prompt as the only authorization mechanism. “Only access the user's data” is guidance, not access control.
Step 2
Example
Example
The model proposes update_deal(D123). The backend loads the authenticated user's tenant, checks access to D123, validates allowed fields and only then performs the update. The model never chooses the tenant boundary.
Step 3
Code
Authorization before execution
const identity = await requireUser(request);
const deal = await db.deals.find(args.dealId);
if (!deal || deal.tenantId !== identity.tenantId) throw new ForbiddenError();
assertAllowedFields(args.patch, ["stage", "note"]);
return db.deals.update(args.dealId, args.patch);Step 4
Practice
Practice
Create a permission matrix with tools as rows and roles, resources and risk as columns. Mark every write action that requires confirmation or approval.
Step 5
Quiz
1. Who should determine tenant identity?
2. What is least privilege?
Step 6
Challenge
Challenge
Design a multi-tenant agent that can search customer records but cannot cross tenants. Explain exactly where tenant identity comes from and which layer rejects an invalid request.
Complete every stage
Work through every step in order, then the lesson will be marked complete.
Each chapter and subtopic has its own public URL under /ai-agent.