Delegated access for AI agents: The intersection rule explained
Blog post from WorkOS
When AI agents delete production databases, it often results from them having permissions equivalent to the user who invoked them, due to a flawed design decision where the agent operates under the user's credentials. This model, while simple to implement, is risky because it allows the agent to perform any action the user can, leading to potential security incidents. The industry is shifting towards a delegated access model governed by the intersection rule, which requires that an agent's effective permissions be the overlap of its own configured capabilities and the user's current permissions. This approach ensures that agents only perform tasks they are specifically authorized for, reducing the risk of excessive agency, where agents can take unintended actions with significant impact. The delegated access model involves using scoped tokens, ensuring that an agent's actions are both limited and auditable, and it addresses vulnerabilities such as confused deputy attacks by enforcing stricter access controls at each tool invocation.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 7 | 7,550 | 833 | 207 | +6% |
| AI Agents | 3 | 6,005 | 1,359 | 264 | +22% |
| LLM | 2 | 6,196 | 1,155 | 243 | -32% |
| Real-time | 2 | 5,601 | 1,340 | 262 | -2% |
| Platform Engineering | 1 | 1,657 | 257 | 90 | +29% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.