Lesson 18 / 26

Least Privilege for Tools and MCP Servers

Limit what an agent can do, not only what it says.

Scope, approve, log

The damage an agent can do is bounded by its tools. Give each agent the smallest set of tools, use credentials with the narrowest permissions (read-only where possible), restrict MCP servers to the tools the workflow needs, and require approval for actions that write, send, pay or delete. Log every tool call with its parameters and result. Review third-party MCP servers like any dependency: who maintains it, what data it sees, and what it can do.

A tool permission review

Fill one row per tool.

tool                 access        approval needed   data exposed
get_order_status     read          no                order id, status
issue_refund         write, money  yes (> 100)        order, amount
send_email           external      yes                customer email
crm (MCP server)     read only     no                 name, plan
file search          read          no                 public policy docs

Separate read and write tools

Split update_order into get_order and change_order so most agents only receive the read tool.

Quick check: Which action should usually require approval?

  • Issuing a refund or sending an external email
  • Reading a public FAQ
  • Looking up order status
  • Formatting a reply
Answer

Issuing a refund or sending an external email — Gate actions that change the world.