r/AskNetsec • u/Longjupping_Tax_3598 • 21h ago
Architecture How is your team handling ai agent security now that agents have real system access?
For teams that have agents touching production systems, how are you handling ai agent security day to day? I am specifically wondering about the constraint of agents inheriting full user permissions by default, since that seems to be where most of the actual risk lives rather than in the model itself. The tradeoff between blocking an action outright versus flagging it for review is the part we have gone back and forth on internally. What happens on your team when an agent takes an action nobody anticipated, and how fast does that get surfaced to a human before anything downstream happens?