Internal Bot Audit Reveals AI Agents Run With Far More IAM Access Than Needed
Careless_Sabfey_4906 · reddit · 2026-09-21
An internal agent that only reads one table and posts to Slack was running under a broad IAM role with keys far beyond read-only scope — and nobody had ever audited it. The author's takeaway: agent frameworks inherit the developer's identity by default, so an agent's blast radius is the union of everything that identity can reach. Least privilege is a discipline for humans; for agents it's still the wild west. The post asks how teams handle scheduled identity audits and scoping at creation.
More from coding & agent
- Tencent open-sources T-Mem, a memory architecture that anticipates instead of archiving — blaizedsouza · 2026-09-21
- Ingesting 100k papers into an LLM wiki: user seeks editorial policy for AI knowledge synthesis — gintrux · 2026-09-21
- Chat On Steroids: open-source Codex-style agent that runs on your ChatGPT subscription quota — CurieuxExplorer · 2026-09-21
- Vibe coding as the next abstraction layer above the compiler — binarybits · 2026-09-21
- Compiler analogy debate: is vibe coding automation or losing the loop? — binarybits · 2026-09-21
- 3 Engineers Shipped a Product from Empty Repo in 72 Hours with Grok Bot: 433 PRs, Notes Open-Sourced — CurieuxExplorer · 2026-09-21