Five Things to Lock Down Before an AI Agent Gets Your Logins

We have not tested this. Written from published specs, prices and documentation.

The pitch for an AI agent is that it logs into things and does the boring work. Reads the inbox, updates the spreadsheet, files the ticket. To do that, it needs your credentials, and that is the part worth slowing down for.

An agent is not a person with judgment and it is not a script with a fixed path. It is somewhere in between: it decides what to do next based on text it reads along the way, and some of that text comes from outside your control. A web page can contain instructions aimed at it. An email can. A document can. The industry term is prompt injection, and the honest summary is that nobody has fully solved it.

So the question is not whether to trust the agent. It is how much it can do when something it reads goes wrong.

Five things to settle before you hand anything over.

Give it its own account, never yours. A separate login with its own password and its own permissions. When you want to know what it did, you look at one account's history rather than trying to separate its actions from yours.

Give it the narrowest permissions that still let it work. Read-only wherever reading is enough. If it only needs one mailbox folder, one spreadsheet or one project, grant exactly that. Most people hand over admin because it is one click, and then it is permanent.

Decide what it can never do without you. Sending mail to anyone outside the company, moving money, deleting anything, changing permissions, and publishing. Those five cover most of the damage that is hard to undo. If the tool cannot be configured to stop at those, that is your answer about the tool.

Turn on whatever log it has, and read it once a week for the first month. You are not auditing for theft. You are looking for the thing it did confidently and wrongly, which is the normal failure.

Write down how to revoke it. One page: which account, which keys, where to click. On the day you need it you will not want to be working that out.

None of this is exotic security work. It is the same discipline you would apply to a new contractor with a key to the office, which is a fair description of what you are setting up.

T

Tomasz Mieczkowski

Writes the saas beat for Drafted Tech. Every piece says at the top how we got the product, or that we never had it.

Comments (0)

wave

Leave a comment

wave

Comments are read before they appear. Your email address is never published.

Read next

wave

What are you looking for?

Press ESC to close.