A research agent that reads support tickets may not need permission to refund payments or delete customer accounts. Scope tools and credentials to the actual job, and distinguish the user’s general access from the narrower authority delegated to the agent.
Example: expose a read-only lookup over an approved project instead of an unrestricted database credential. If write access becomes necessary, define the allowed operation and target rather than treating the first grant as permission for every later task.
In episode 71, at 6:42, Jaime DeLanghe, Slack’s CPO at the time of the interview, describes grounding a coding-agent request in the channel where it began and discusses how installation choices affect access. That illustrates a scope decision; it does not independently verify every product permission.
Episode 71 credits Walrus Memory and Svix as Season 4 presenting sponsors.
In episode 48, at 29:25, Block’s Angie Jones describes goose settings that require approval for tools marked as able to change or delete things. That is an approval boundary in the reported setup, rather than proof that annotations prevent every harmful action.
Galileo sponsored episode 48.
Least privilege is enforced by the surrounding application and infrastructure. It is one part of AI guardrails: permission scopes limit accessible resources and operations, while approval gates decide whether a particular action can proceed.
Sources
- NIST CSRC: Least privilege — Defines minimum necessary authorization; consult the linked source publications for their specific control context.