What permissions to give an AI agent in your company and how to monitor what it does
Equipo Tecnea
Tecnea
An AI assistant answers. An agent also acts: it reads email, creates an order in the ERP, replies to a customer, moves a case file to another status. That difference is what makes agents useful, and also what forces you to think carefully about what you let them do.
The subject went from theoretical to urgent in a few weeks. In the summer of 2026, agents from several major AI labs left their test environments during cybersecurity exercises and reached real systems; the most cited case was OpenAI agents accessing Hugging Face. In September, Nvidia launched an open platform to contain agents and isolate them when they try to step outside their limits, and MIT Technology Review asked the question many companies are already asking: who is liable when an agent does what it should not.
These were lab agents pushed to the limit, not the assistant that handles a company's invoices. But the lesson applies to any agent: the risk is not in what it knows, but in what it can do.
Three ways of giving too much power
OWASP, the reference organisation for application security, has its own category for this in its list of risks for AI systems: "excessive agency". It explains it with three causes, and they work as a guide for any company:
- Too much functionality: the agent has tools it does not need for its job.
- Too many permissions: the tools it does need can do more than is essential.
- Too much autonomy: it does important things without anyone confirming them.
The four rules below correct each one.
1. Only the tools it needs
An agent that records supplier invoices needs to read the invoice inbox and prepare a draft journal entry. It does not need to send emails, delete documents or see the payroll. Every tool you give it is one more door.
And there are tools best avoided almost always: open-ended ones, such as "run any command" or "open any web page". They are convenient for building the agent and very hard to control afterwards.
2. Its own user, with minimum permissions
The agent should access your systems with its own user, never an administrator's or a team member's. That way its permissions can be trimmed to what is needed and everything it does is recorded under its name.
Two details make the difference:
- It acts with the permissions of whoever is using it. If an employee cannot see a document, the agent should not see it either when working for that employee.
- Control sits in the system, not in the agent. Whether an operation is allowed is decided by the ERP, the CRM or the document manager, not by the instructions given to the agent. Instructions can be tricked; system permissions cannot.
3. What always goes through a person
Not every action carries the same weight. A practical way to sort them is into three groups:
- It can do it alone: read, classify, summarise, search, prepare drafts.
- It proposes and a person confirms: sending something to a customer, creating an order, posting an entry, changing customer or supplier data.
- It never does it: payments and transfers, deleting data, changing permissions or signing on someone's behalf.
The assistant on this very website follows that scheme. It can guide the visitor and prepare an appointment, but the appointment is only created when the visitor clicks "Confirm". Of the calendar it only knows the free slots: it does not see anyone's meetings.
4. Quantity limits
Even what is allowed should have a ceiling: number of operations per day, maximum amount, number of messages per conversation. If something fails — a design error, a manipulation attempt — the limit decides how much damage it can do before someone notices.
On the website assistant, for example, there is a daily cap on model calls, another per visitor, automatic blocking when someone tries to manipulate it, and a switch to turn it off without touching the code.
How to monitor what it does
An agent without a log is a black box. The minimum that should be recorded:
- Who asked it what, and when.
- Which tool it used, with what data and with what result.
- What a person confirmed and what the agent did on its own.
That log should be stored out of the agent's reach, so it cannot modify it, and someone should review it periodically at the start. It is worth adding alerts for anything odd: an unusual volume of operations, repeated attempts at something it is forbidden to do, or access at strange hours.
What the regulation says
The European AI Regulation (AI Act) requires effective human oversight for high-risk systems (Article 14). Most agents a company uses for administrative tasks do not fall into that category, but documenting what the agent does, with what data and who supervises it is good practice that also makes any future review easier. If it processes personal data, the GDPR also applies.
There is more on how that oversight is graded in What human oversight means in an AI system (in Spanish).
Five questions for whoever installs an agent for you
- Exactly which tools will it have, and what can it do with each one?
- Which user does it use to access our systems, and what permissions does that user have?
- Which actions does it take alone, which does it propose, and which are forbidden?
- What quantity limits does it have, and who can switch it off?
- Where is the log of what it does kept, and who reviews it?
If you want to see how we approach it: Private AI that complies with the law · AI agents for administrative processes (in Spanish)
This article is informational and does not constitute legal advice. Tecnea develops AI agents for companies, so we have a commercial interest in the topic. The five questions work for evaluating any proposal, including ours.
Sources
- MIT Technology Review, "Who's liable when AI agents go rogue?" (28 September 2026): technologyreview.com
- TechCrunch, "Nvidia launches new platform for reining in rogue AI agents" (28 September 2026): techcrunch.com
- OWASP, "LLM06:2025 Excessive Agency": genai.owasp.org
- Regulation (EU) 2024/1689 (AI Act), Article 14: eur-lex.europa.eu
¿Te ha resultado útil este artículo?
Publicamos análisis sobre IA y tecnología empresarial. Sin spam — solo cuando escribamos algo que valga la pena leer.
Did you like this article?
Tell us what you'd like to automate in your company and we'll tell you, with no strings attached, where to start.
