After an agent leaked salary data, Reddit distilled a 5-step pre-launch access checklist

Wild-Lawyer8511 · reddit · 2026-10-08

A company bot meant to read only a wiki indexed everything—including an HR folder—after its setup person accepted Drive access, and answered questions with an unannounced reorg plan and salary bands; another summarizing agent inherited delete access on a shared drive and could send email as its creator. Though the original post was removed, its 70+ replies distilled into a pre-launch checklist: give the agent its own identity (and check access against the asker at query time); pull real grants from the admin console, not memory; keep reading and doing apart with separate narrow credentials; ask it questions it should refuse before launch; and test cached answers after revoking access. No new tools needed—just treat it like a smart but drunk intern.

Original post →

More from coding & agent

coding & agent channel →