Devs battle-test AI agent permissions: IAM, middleware or human approval?
SXOTW · reddit · 2026-10-03
A developer running AI agents in production asks how others handle permissions when agents can modify data, call internal APIs, send emails, issue refunds, or deploy code — and recently got burned.
The post lays out the main options and asks about their maintenance cost:
- Relying on IAM / service accounts
- Enforcing policies at the tool or API layer
- Custom middleware for fine-grained control
- Human approval for risky actions
- Adopting an existing permissions product
The author also wants to know why teams that rolled their own made that choice, and whether it's an ongoing headache or simple enough that a separate solution isn't worth paying for. It's a widely-hit pain point in agent engineering with few standard answers; the discussion is useful reference for teams shipping agents.
Related event: Practitioners Grapple with Governing AI Agents in Production(2 posts)→
More from coding & agent
- Agents Take Over the Full Ticket Lifecycle: From PRD to Fixing CI/CD, With Embedded Governance — Pavan_Belagatti · 2026-10-05
- Enable Claude Code's you-should-know plugin to surface missed context — daniel_mac8 · 2026-10-05
- TAHI: Test-Time Adaptive Agents That Fit Individual Experts in Tens of Tasks — AkariAsai · 2026-10-05
- JEV-27B decision-making demo space trends on Hugging Face — autotrust · 2026-10-05
- JEV-9B decision demo with MCP server trends on Hugging Face — autotrust · 2026-10-05
- Claude Code skill forces three design directions and self-critique to kill AI-slop UIs — PrajwalTomar_ · 2026-10-05