Least privilege & action approval
Publication dates and source age
Sources counted: 3
Newest dated source: 2026-08-20
At least one source was published within the 18-month window.
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Some publication dates are unknown; the newest dated source may not be the newest source overall.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Open in the glossary Reading notes · Structured record
In plain language
Give an application only the access needed for its task. [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
Limits & distinctions
A prompt asking an agent to behave is not the same as an enforced access boundary. Limited access still needs testing and oversight. [3]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
A fuller explanation
Restrict available tools, operations and credentials to the minimum required. Check authorization in connected systems and require approval for consequential actions where appropriate. [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
How it relates to the map
A practical design choice about access and consequences, rather than an ideology or a position on frontier training pace. [2]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
Share this page
https://theaiatlas.org/ideas/least-privilege/
Download a share image · Vector image
Image previews are summaries. Keep the page link so readers can check the evidence.
Sources and what we read
1. LLM06:2025 Excessive Agency
Publication dates and source age
Sources counted: 1
Publication dates are unavailable.
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Some publication dates are unknown; the newest dated source may not be the newest source overall.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Read agency definition, excessive functionality/permissions/autonomy, external authorization, approvals and monitoring limits. The 2025 label identifies the edition; the page does not establish its original publication date.
2. Guidelines for secure AI system development: Secure design
Source is over 18 months old.
Publication dates and source age
Sources counted: 1
Newest dated source: 2023-11-27
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Read threat modelling, task suitability, model selection, restricted actions and least privilege. Date follows the containing guideline publication. Used for design principles, not a certificate that any configuration is safe.
3. Managing the cyber risk of agentic AI
Publication dates and source age
Sources counted: 1
Newest dated source: 2026-08-20
At least one source was published within the 18-month window.
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Read autonomy, model safeguards, oversight, sandbox boundaries, network and credential restrictions, observability and emergency response. The publisher labels this interim practical advice based on its research; formal guidance may supersede it.
Edition and machine-readable evidence
Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.
Pinned complete dataset · Complete evidence page · Agent consumption guide