SecurityAgenticMedium complexity

Agent Permissions & Prompt-Injection Defence

Agents connected to e-mail, CRM and code repositories can be steered by instructions hidden in a document or web page they read, and act with whatever access they were given.

How we approach it

Inventory every agent, its tools and the credentials behind them. Scope each tool to least privilege, separate read from write, and require human approval for payments, deletions and external sends. Treat retrieved content as untrusted input. Red-team each agent with injected instructions before go-live and after every tool change, and log every tool call to the SIEM.

Business value

Agents that can act without becoming a way in

Technology stack

  • MCP gateway
  • OAuth scopes
  • policy engine
  • red-team harness
  • SIEM

Related service

AI Audit & Risk Assessment

Further reading

Related use cases