SecurityAgenticMedium complexity
Agent Permissions & Prompt-Injection Defence
Agents connected to e-mail, CRM and code repositories can be steered by instructions hidden in a document or web page they read, and act with whatever access they were given.
How we approach it
Inventory every agent, its tools and the credentials behind them. Scope each tool to least privilege, separate read from write, and require human approval for payments, deletions and external sends. Treat retrieved content as untrusted input. Red-team each agent with injected instructions before go-live and after every tool change, and log every tool call to the SIEM.
Business value
Agents that can act without becoming a way in
Technology stack
- MCP gateway
- OAuth scopes
- policy engine
- red-team harness
- SIEM
Related service
AI Audit & Risk AssessmentFurther reading
Related use cases
- Cross-Industry · SecuritySOAR AutomationLet the security team keep up with alert volume without automating away judgement.
- Cross-Industry · SecurityCopilot Rollout Without OversharingEnterprise AI assistants search everything a user can open, so years of overshared files become one question away.
- Cross-Industry · SecurityAttack Path AnalysisFind the routes an attacker could chain from an exposed asset to the systems that matter most.