Getting AI agents past enterprise security reviews is harder than building them
Useful_Lecture_5927 · reddit · 2026-09-01
A developer building agents for enterprise environments says the hardest part isn't making the agent work — it's getting security teams comfortable letting it touch CRM data, email, internal APIs, databases, and MCP servers.
The recurring questions: what exactly can the agent access, what happens under prompt injection, and can you audit what it did after something goes wrong. He asks practitioners for ugly lessons: middleware/control layers that actually block tool calls, what audit trails look like, identity and least-privilege across agents/users/tenants, and the biggest gaps reviewers found after teams thought they were covered.
More from coding & agent
- Chrome releases WebMCP tool security guide to prevent prompt injection — prd_008 · 2026-09-01
- Monid: Unified API for 1700+ Tools with Pay-Per-Call — SimplyAnnisa · 2026-09-01
- Small Models Can Power Agents Effectively, Offering Better Value Than Large Ones — thechrisperry · 2026-09-01
- A2A Agent Experiment: Invite Your Agent to Explore a Novel Website — patternflow · 2026-09-01
- Muse Code launches out of beta for complex engineering tasks — Scobleizer · 2026-09-01
- Agent confidence should measure the whole chain, not just the last step — alizahidrajaa · 2026-09-01