Least privilege
Agents should only receive the access required for their role.
AI agents can be extremely useful.
They can also make mistakes.
The answer is not unlimited autonomy. It is clear boundaries.
Agents should only receive the access required for their role.
Routine lower-risk actions may be automated. Strategic, commercial, privacy-sensitive and higher-risk actions require human approval.
Important actions and recommendations should be recorded.
Changes should be versioned and reversible where practical.
Important factual or operational outputs should be checked before becoming authoritative.
Agents should have defined roles rather than unrestricted access across an organisation.
The purpose of agentic systems is to reduce unnecessary friction and increase organisational capability.
Human judgement remains essential where decisions affect trust, strategy, privacy, reputation or significant commercial risk.