Skip to main content
AI Security Hub
05AI Security Pillar

Tool and Agent Security

Limit the systems, credentials, permissions, and actions available to AI agents.

Business focus

Control AI actions

Why it matters

Security starts with a defined business boundary

Tool and agent security applies least privilege, approval gates, scoped credentials, and action logging when AI can interact with business systems.

Business risk

A wrong answer becomes a wrong action when an AI agent can send email, change a record, share a file, create an account, or trigger another system.

What this pillar covers
  • Approved-tool allowlists
  • Permission and authorization checks
  • Human approval for higher-risk actions
  • Action logging and accountability
Operating model

Turn control ai actions into repeatable controls

A policy is only the starting point. For each AI use case, name the business owner, define the allowed boundary, configure the relevant technical controls, and decide what evidence proves those controls are working. Repeat the review when the model, data, connected tools, or business purpose changes.

Start with a single high-value workflow instead of trying to govern every experimental use at once. That makes it possible to test the controls with real users, find exceptions, and create a pattern the rest of the business can reuse.

StepDecisionEvidence to retain
1Scope the workflowOwner, purpose, approved data, users, and connected systems.
2Apply the controlsConfiguration, access rules, approval points, and test cases.
3Operate and reviewLogs, review results, exceptions, incidents, and change records.

Questions for leadership

  • Which actions can the agent perform without approval?
  • Does each tool use a separate, scoped service identity?
  • Can the business reconstruct what the agent attempted and changed?
  • Who can pause the agent when behaviour looks wrong?
Practical control checklist

Put the pillar into practice

  1. 1Allow only the tools required for the defined task.
  2. 2Give each agent and environment separate credentials.
  3. 3Apply user and business authorization before every action.
  4. 4Require approval for external or state-changing actions.
  5. 5Log tool calls, parameters, approvals, results, and errors.
Authoritative guidance

Use recognised guidance to validate the control design

These resources help teams translate AI-specific risks into documented, testable business and technical controls. Apply them to the actual data, permissions, and actions in the workflow rather than treating them as a one-time compliance exercise.

Review a real workflow

Turn this pillar into operating controls

Map the data, access, approvals, monitoring, and evidence around one important AI use case before expanding it.

Explore AI services