Internal Bot Audit Reveals AI Agents Run With Far More IAM Access Than Needed

Careless_Sabfey_4906 · reddit · 2026-09-21

An internal agent that only reads one table and posts to Slack was running under a broad IAM role with keys far beyond read-only scope — and nobody had ever audited it. The author's takeaway: agent frameworks inherit the developer's identity by default, so an agent's blast radius is the union of everything that identity can reach. Least privilege is a discipline for humans; for agents it's still the wild west. The post asks how teams handle scheduled identity audits and scoping at creation.

Original post →

More from coding & agent

coding & agent channel →