A team gave its agents production DB access and now cannot audit them
Alessandro_Lena_410 · reddit · 2026-07-22
- An engineering team built several internal agents for ticket triage, reporting, and nightly reconciliation.
- To ship quickly, they gave the agents broad service credentials, including read/write access to a production database.
- The author is now worried because there is no real ownership, offboarding, or audit trail comparable to what a human employee would have.
- The question is what a sensible operational pattern looks like beyond the obvious advice to use short-lived tokens.
More from coding & agent
- Cheaper OpenAI Agents API alternative: sandbox service undercutting E2B by 46% — airesearch12 · 2026-09-11
- His agent kill switch ran for months before he found it was wired to nothing — AnvilandCode · 2026-09-11
- Kernel's Browser Agents Can Now Pay Online Using Aliases, Never Touching Card Data — jeff_weinstein · 2026-09-11
- OpenAI opens up agent sandboxes: BYO or pick from Cloudflare, E2B, Modal, Vercel and more — threepointone · 2026-09-11
- SocialCrawl MCP lets agents search Reddit, YouTube, TikTok, X with one API key — dooddyman · 2026-09-11
- Astra builds a surprisingly polished Catan game in three.js, reusing past UI and 3D assets — FinanceYF5 · 2026-09-11