I’ve been thinking about permissions a lot more as agents start doing things instead of just giving answers. An agent might have access to a database, an internal API, email, a browser, or some other system. Giving it access is easy enough. The harder question is figuring out what that access should actually look like. Should an agent have its own identity? Should it inherit the user’s permissions? Should access to certain tools only last for one task? And what happens when the agent needs to do something sensitive that normally requires a person to approve it? The audit side gets interesting too. If an agent changes a customer record or sends an email on someone’s behalf, I want to know exactly which user authorized it, which agent actually performed it, and what happened along the way. I’m wondering how teams are handling this in production. If an agent takes an action on behalf of a user, who should that action ultimately be attributed to? submitted by /u/Financial_Ad_7297
Originally posted by u/Financial_Ad_7297 on r/ArtificialInteligence
