Agent permissions should expire before an agent's context does
Future_AGI · reddit · 2026-09-08
Future AGI argues that approvals in long-running agent sessions dangerously become standing permissions: an agent approved to deploy, times out, resumes 30 minutes later — but the artifact or environment may have changed. The post proposes binding grants to specific actions with four checks — precise scope, expiry, replay protection, and audit records — and treats retries as the hardest part: migrations and force-pushes with ambiguous outcomes need an explicit "unknown outcome" state and explicit retry/approval decisions. Their gateway applies policy to each MCP tool call and arguments.
More from coding & agent
- Google GTIG: threat actors now run agentic AI attacks, harvesting credentials in under 6 hours — ChuckDBrooks · 2026-09-08
- Someone got Claude Opus 5 to play Ultima Online — mariofilhoml · 2026-09-08
- Dev hacks a Codex usage chart to watch rate limits plummet in real time — gpt2chatbot · 2026-09-08
- Agentic software factories: AI speeds coding but bottlenecks shift to review and ops — Pavan_Belagatti · 2026-09-08
- Turn PRs into RL environments at scale — startups already raised seed rounds on this repo — lvwerra · 2026-09-08
- Self-Improving AI's First Payoff Is Cheaper, Not Smarter: Ben Lorica on the Harness Advantage — bigdata · 2026-09-08