Berk Bayri

An AI agent should inherit the user's permissions

A common misconception about AI governance, tested against the evidence.

The myth
If an employee can access or change something, an AI agent acting for that employee should inherit the same permissions.
The reality
A person's standing permissions describe a role. An agent's authority should describe the task it is doing now. Those are not the same security boundary.

Explanation and evidence

The argument

An employee may have access to a CRM, shared drive, finance system and code repository because their job requires different permissions across many weeks and situations.

An agent executing one task does not need all of that.

Microsoft's 2026 security guidance treats this as a core agent problem: stable agent identity can coexist with narrowly scoped, just-in-time entitlements for a specific workflow. Its defense-in-depth guidance goes further, recommending task-focused permissions where feasible because those permissions naturally expire when the work ends.

That is a different mental model from "act as me."

Identity can be stable. Authority should be temporary.

Why people believe it

User impersonation is easy to understand and convenient to implement. If the agent works for Berk, let it do what Berk can do.

But convenience hides effective authority. Combining email, files, tickets and code can let an agent take actions no single integration looked dangerous enough to justify on its own.

What the evidence says

Agent security increasingly treats identity, resource scope, tool scope, duration and auditability as separate controls. The goal is not to make the agent powerless. It is to make its authority legible.

A broad human role is often the wrong unit.

The better question

For this task, ask: Which action, on which resource, for how long, with what limit, and how can it be reversed?

Give the agent that authority. Not the user's entire digital life.

Sources

Least privilege for AI agents: Identity, access, and tool binding

Microsoft Security · 2026-07-16

Defense in depth for autonomous AI agents

Microsoft Security · 2026-05-14

Related reading