Least Privilege for Coding Agents

A practical guide to coding agent least privilege: decisions, setup, failure modes, review evidence, and a repeatable acceptance test for engineering teams.

Technical signal map for Least Privilege for Coding Agents

Grant a coding agent the smallest set of repository, filesystem, command, network, and service capabilities needed for one task, for one run.

This guide focuses on the engineering decision behind coding agent least privilege: what to standardize, what to constrain, and what evidence a reviewer should expect before accepting the result.

The core decision

Break the broad idea of ‘developer access’ into concrete permissions: read repository, write one branch, read selected issues, download packages, call a test service, or open a pull request. Most tasks do not need organization administration, default-branch writes, production credentials, or unrestricted cloud APIs.

A workflow that holds up in review

Create task profiles with known capability bundles and approval rules. Log denials as product feedback: repeated legitimate denials may indicate a missing narrow tool, while one-off requests should not automatically broaden the profile.

The failure mode to design around

A read-only token is not enough if the agent can execute arbitrary code with a powerful workload identity. Evaluate effective authority across all tools and networks, not each credential in isolation.

Implementation checklist

  • Enumerate capabilities, not roles.
  • Scope writes to one branch or artifact.
  • Use short-lived identities.
  • Review effective combined authority.

Turn the checklist into operating controls

  • Enumerate capabilities, not roles: name the owner, the evidence that proves it happened, and the condition that should stop the run.
  • Scope writes to one branch or artifact: name the owner, the evidence that proves it happened, and the condition that should stop the run.
  • Use short-lived identities: name the owner, the evidence that proves it happened, and the condition that should stop the run.
  • Review effective combined authority: name the owner, the evidence that proves it happened, and the condition that should stop the run.

The list becomes useful when every item produces visible evidence. Store that evidence with the task or pull request rather than in a private chat. A future reviewer should be able to tell which repository revision was used, which permission profile applied, what stopped or failed, and who accepted the remaining risk. For coding agent least privilege, a short, complete record is more valuable than a long narrative that cannot be reproduced.

Move from one run to a repeatable practice

Test the control with a safe adversarial exercise before relying on it. Attempt an out-of-scope file edit, a denied network request, a fake instruction in repository content, and access to a canary credential. Confirm that prevention or detection produces an actionable event with a named owner. Retest after adding tools, integrations, or repositories because effective authority changes when capabilities are combined. Record accepted residual risk and its review date.

Before expanding the workflow, ask three review questions:

  • What evidence shows that enumerate capabilities, not roles was satisfied, and would that evidence survive a rerun from the recorded commit?
  • What evidence shows that scope writes to one branch or artifact was satisfied, and would that evidence survive a rerun from the recorded commit?
  • What evidence shows that use short-lived identities was satisfied, and would that evidence survive a rerun from the recorded commit?

Write the answers in the same place as the code review. That creates a compact decision record and lets the team compare later runs without relying on memory.

A practical acceptance test

Run the workflow from a clean checkout at a recorded commit. Give the agent only the documented task packet and the intended permission profile. Then ask a reviewer who did not launch the run to reproduce the important checks, explain the changed behavior, and identify the rollback path. The task passes only when the artifact, evidence, and repository state agree. Keep the failed examples as regression cases; they are more useful than a polished demo because they reveal where instructions, environment, permissions, or tests need improvement.

Related reading

Primary references

Vendor features, limits, preview labels, and pricing can change. Recheck the linked first-party documentation for the current state before making a purchase or rollout decision.

Previous dispatch
Next dispatch