Permissions
Least privilege
Give each agent only the capabilities needed for its task.
Lesson overview
Least privilege
Define the minimum read and write permissions for every workflow. Scope access by user, tenant, resource, and action.
Avoid generic tools such as unrestricted SQL or shell access when a narrow domain tool can express the same capability.
Learning path
Theory → Example → Code → Practice → Quiz → Challenge → Completion
Step 1
Theory
Least privilege
Define the minimum read and write permissions for every workflow. Scope access by user, tenant, resource, and action.
Avoid generic tools such as unrestricted SQL or shell access when a narrow domain tool can express the same capability.
Step 2
Example
Example
Apply Least privilege to a realistic production scenario and trace the decision step by step.
Step 3
Code
Code
Add implementation notes or a runnable example for this concept.
Step 4
Practice
Practice
Write down the inputs, expected output, constraints, and one failure case for Least privilege.
Step 5
Quiz
Quiz coming soon.
Step 6
Challenge
Challenge
Design a production-ready solution for Least privilege and explain one important trade-off.
Complete every stage
Work through every step in order, then the lesson will be marked complete.
Each chapter and subtopic has its own public URL under /ai-agent.