Where do you stop trusting an AI agent with write access to Salesforce, SAP and Jira?

ken_kauneki10 · reddit · 2026-09-16

The author raises a pressing question as agents move from read-only analysis to actually performing actions: where do you stop trusting an agent with direct API access? When one agent can write to Salesforce, SAP, Slack and Jira, the options include granting it its own permissions, inheriting the user's permissions, adding human approval before destructive actions, or hard-restricting tools. The thread asks practitioners which API actions should never run without human sign-off.

Original post →

More from coding & agent

coding & agent channel →