Hand-writing permissions for every AI agent is becoming the real production tax

Prestigious-Run-1954 · reddit · 2026-09-13

A Reddit discussion on a growing operational cost of running many AI agents in production: hand-writing a role/permission scope for every new agent is becoming an ongoing tax—not runtime failures, but the work of defining what each agent is allowed to do.

The author asks teams running multiple agents: are new roles genuinely bespoke or mostly copy-pasted patterns? At what agent count does this become real overhead? Has anyone auto-generated roles from an agent's declared tools/scope?

A separate related question: has anyone seen an injected prompt or weird input get an agent to fetch data or take action it should have been blocked from—bypassing the permission check entirely rather than misconfigured permissions—or is that still theoretical?

Original post →

More from coding & agent

coding & agent channel →