Definition · AI agents
Least privilege
Least privilege is the security principle that every program and every user should hold only the access needed to complete the job, and nothing more. Saltzer and Schroeder stated it in 1975. Least privilege mainly limits damage rather than preventing failure: an accident or error can only use the access that was granted.
Last reviewed
Key points
- Saltzer and Schroeder stated the principle in 1975: "Every program and every user of the system should operate using the least set of privileges necessary to complete the job."
- Its main job is limiting damage rather than preventing failure. A mistake can only use the access that was granted.
- NIST's security control catalogue, SP 800-53, makes it control AC-6, and applies it to processes acting on behalf of users as well as to the users themselves.
- For an AI agent it means scoping the tools and what each tool can reach. OWASP's example is an email summariser that needs to read mail, not send or delete it.
- It gets hard when the job is not known in advance. A 2026 NIST draft paper asks how to set least privilege for an agent whose actions might not be fully predictable.
How it works
Least privilege sizes each grant of access to the job at hand. Saltzer and Schroeder’s 1975 paper on computer protection states it as: “Every program and every user of the system should operate using the least set of privileges necessary to complete the job.” They give the military rule of “need-to-know” as an example of the principle.
One person can need different amounts of access for different jobs. Saltzer and Schroeder describe a user trusted with valuable information who, to prevent accidents, may choose to work under a second identity that cannot reach it when doing something unrelated. NIST’s SP 800-53 control AC-6 applies the principle to “users (or processes acting on behalf of users)”, so a program acting for someone is held to it too. One of its optional enhancements, AC-6(2), has users of privileged accounts switch to non-privileged accounts or roles for work outside their security duties.
Why it matters
Least privilege is mainly about damage, not prevention. Saltzer and Schroeder write: “Primarily, this principle limits the damage that can result from an accident or error.” It also makes improper uses of privilege less likely, and means fewer programs to audit when a privilege is misused.
It shrinks what a confused deputy can be tricked into doing, because the deputy has less authority to misuse.
The same reasoning carries over to AI agents. Anthropic recommends least-privilege credentials so that “compromising an agent does not yield broad access to organizational systems.” In its words, scoping a tool’s reach “shrinks both the input surface an attacker can exploit and the blast radius if something goes wrong.”
In practice
For AI agents, three of OWASP’s mitigations for excessive agency apply least privilege at different levels:
- Minimise tools. An app that never needs to fetch a URL should not be offered a fetch tool.
- Minimise tool functionality. A mailbox summariser may only need to read email. It should not be able to delete or send.
- Minimise tool permissions. A product-recommendation agent “might only need read access to a ‘products’ table”, with no other tables and no insert, update or delete, enforced by the database permissions of the identity the tool connects as.
OWASP adds that actions taken for a user should run in that user’s context “with the minimum privileges necessary”, rather than through one shared privileged identity. Anthropic applies the same idea inside a tool: “An agent that needs to read email does not necessarily need to read all email”.
OWASP’s agentic Top 10 expands on least privilege with Least-Agency: avoid autonomy the task does not need. Meta places its Agents Rule of Two alongside the principle rather than in place of it: the rule is “a supplement — and not a substitute — for common security principles such as least-privilege.”
Trade-offs
Least privilege assumes you know the job in advance, and an agent’s job may not be fixed. The National Cybersecurity Center of Excellence (NCCoE), part of NIST, lists it as an open question in its 2026 draft paper on agent identity: “How do we establish ‘least privilege’ for an agent, especially when its required actions might not be fully predictable when deployed?”
Anthropic calls how narrowly to scope an agent’s tools a design choice that “trades capability against exposure”. In its words, “An agent built for a single workflow can be provisioned tightly. An agent meant to handle whatever the user throws at it needs broader reach by design, and the security weight shifts to other layers.” It adds that protocol support for fine-grained scoping “is uneven today”.
Identity is the other gap. OWASP says an agent without a distinct, governed identity of its own “operates in an attribution gap that makes enforcing true least privilege impossible”. One common example it gives of agentic identity and privilege abuse is a manager agent handing a narrow task to a worker agent along with its own full access.
Questions and answers
What is the principle of least privilege?
The principle of least privilege says every program and every user should hold only the access needed to do the job, and nothing more. Saltzer and Schroeder stated it in 1975. Its main purpose is to limit the damage an accident or error can do, because a failure can only use the access that was granted.
How does least privilege apply to AI agents?
For an AI agent, least privilege means giving it only the tools the task needs, only the functions within each tool that the task needs, and only the permissions each tool needs on other systems. OWASP's example is an email summariser that can read mail but cannot send or delete it. Actions taken for a user should run in that user's context with the minimum privileges necessary, not through a shared privileged account.
What is the difference between least privilege and least agency?
Least privilege limits what access a program or user holds. OWASP's Least-Agency, from its Top 10 for Agentic Applications, expands on it for AI agents: it also advises against giving an agent autonomy where the task does not need it, because extra autonomy gives an attacker more to work with and adds nothing in return.
Sources
- The Protection of Information in Computer SystemsProceedings of the IEEE, Sep 1975
- Glossary: least privilegeNIST Computer Security Resource Center
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and OrganizationsNIST, Sep 2020
- LLM03:2026 Excessive AgencyOWASP GenAI Security Project, 4 Aug 2026
- OWASP Top 10 for Agentic Applications 2026OWASP GenAI Security Project, 9 Dec 2025
- Re: Request for Information: Security Considerations for Artificial Intelligence Agents, Docket No. NIST-2025-0035Anthropic, 9 Mar 2026
- Accelerating the Adoption of Software and AI Agent Identity and Authorization (concept paper, draft)NIST National Cybersecurity Center of Excellence, 5 Feb 2026
- Agents Rule of Two: A Practical Approach to AI Agent SecurityMeta, 31 Oct 2025