Lesson 18 / 26
Least Privilege for Tools and MCP Servers
Limit what an agent can do, not only what it says.
Scope, approve, log
The damage an agent can do is bounded by its tools. Give each agent the smallest set of tools, use credentials with the narrowest permissions (read-only where possible), restrict MCP servers to the tools the workflow needs, and require approval for actions that write, send, pay or delete. Log every tool call with its parameters and result. Review third-party MCP servers like any dependency: who maintains it, what data it sees, and what it can do.
A tool permission review
Fill one row per tool.
tool access approval needed data exposed
get_order_status read no order id, status
issue_refund write, money yes (> 100) order, amount
send_email external yes customer email
crm (MCP server) read only no name, plan
file search read no public policy docsSeparate read and write tools
Split update_order into get_order and change_order so most agents only receive the read tool.
Quick check: Which action should usually require approval?
- Issuing a refund or sending an external email
- Reading a public FAQ
- Looking up order status
- Formatting a reply
Answer
Issuing a refund or sending an external email — Gate actions that change the world.