Devs battle-test AI agent permissions: IAM, middleware or human approval?

SXOTW · reddit · 2026-10-03

A developer running AI agents in production asks how others handle permissions when agents can modify data, call internal APIs, send emails, issue refunds, or deploy code — and recently got burned.

The post lays out the main options and asks about their maintenance cost:

The author also wants to know why teams that rolled their own made that choice, and whether it's an ongoing headache or simple enough that a separate solution isn't worth paying for. It's a widely-hit pain point in agent engineering with few standard answers; the discussion is useful reference for teams shipping agents.

Related event: Practitioners Grapple with Governing AI Agents in Production(2 posts)→

Original post →

More from coding & agent

coding & agent channel →