Tenable: Agents pile up permissions like service accounts; sandbox them and keep humans approving

TechNadu · x · 2026-08-14

Ben Mudie, Field CTO APJ at Tenable, told TechNadu that for community-built open-source security agents, open source itself is not the core risk — undefined access is.\n\nHe noted that agents can accumulate permissions much like service accounts, and teams should require:\n- Code review\n- Short-lived access credentials\n- Sandboxing\n- Monitoring of MCP activity\n- Human approval for high-stakes actions\n\nThe guiding principle: scope agents to least privilege, pair it with isolation, logging and continuous permission reviews, rather than letting their access grow unchecked.

Related event: Tenable: Key Risk in Security Agents Is Undefined Permissions(2 posts)→

Original post →

More from coding & agent

coding & agent channel →