Security · · 7 min read
Giving AI agents roles and permissions: a practical model
Broad access makes agents risky and hard to review. A role-based model — clear scope, specific tools, human approval points — makes agent work trustworthy.
As agents move from answering questions to taking actions, the question shifts from "is the answer good?" to "what is this agent allowed to do?" The answer should be specific.
Start with a role
A role describes what an agent is for. A research agent gathers and summarizes sources. An engineering agent proposes and implements code changes. A security reviewer inspects changes for risk. Each role implies a different set of tools and a different level of trust.
Naming the role makes the agent's work easier to evaluate. Reviewers know what to expect, and deviations stand out.
Grant capabilities, not blanket access
Instead of connecting an agent to everything, grant the narrowest set of capabilities its role needs:
- Scope access to a specific workspace or project.
- Allow specific tools rather than whole systems.
- Separate read access from write access.
- Require human approval for actions that are hard to undo.
Keep an audit trail
Every meaningful action an agent takes should be attributable: which agent, under which role, at whose request, with what result. That history is what lets a team trust agents with more over time.
How RelayRealm approaches this
RelayRealm is designed around scoped agent identities, explicit permissions, and human approval for sensitive actions. Security is being designed into the architecture from the beginning rather than added later.