verifiedagents.ai
All posts

5 min readAI Agents · Privilege Changes for AI Agents

What Can Your AI Agent Access Right Now? The Ten-Minute Check

By Michelle Savage, Experience Design Director, PayPal

Hero: What Can Your AI Agent Access Right Now? The Ten-Minute Check

TL;DR: Ask what your AI agent can access, not what it can do. The job describes the work. The access describes the blast radius. Run the ten-minute check: pick one agent and time how long it takes your team to list what it reaches. If the answer takes longer than ten minutes, that's the finding.

Last updated October 5, 2026. Rebuilt for verifiedagents.ai as a ritual you can run this week, with the numbers that say why.

Why is "what can it access" the better question?

"What can this agent do?" describes a job. "What can this agent access?" describes how much of the business is exposed when the agent does something nobody planned. A support agent that reads one order table is a small problem. The same agent with write access to billing is a very different afternoon.

Here's how it usually goes wrong: the team scopes the job and skips the access. The agent gets built to answer refund questions, and somewhere in setup it gets handed a credential that opens far more than refunds. Nobody chose that. The credential was already sitting there, and it worked.

The scale makes it urgent. Machine identities now outnumber humans 109 to 1, and 79 percent of those are AI agents, per Palo Alto Networks' 2026 Identity Security Landscape. A year earlier the ratio was 82 to 1. Your company hired a workforce it never interviewed.

How many companies have already been burned?

Most of them, by their own account. SailPoint and Dimensional Research found 80 percent of companies saying their agents have already done things they weren't supposed to do: reached systems never meant for them, shared data they shouldn't have, sometimes leaked credentials on the way through.

Now the two numbers that tell the whole story. Ninety-two percent say governance is critical. Forty-four percent have any agent policy at all. Almost everyone knows. Fewer than half have done anything. And nobody's waiting on a product to ship. This is a decision that hasn't been made yet.

What does treating an agent like a privileged user look like?

Treat every agent the way you'd treat a contractor with a badge. Four things, and you should be able to name all four for any agent that's running today:

  1. Access scoped to the job, nothing extra.

  2. Credentials that expire on their own.

  3. A record of every action it takes.

  4. A way to shut it off in seconds.

You'd never hand a new hire a master key on day one. Most AI agents get less scrutiny than the summer intern, and they work all night. The scoping method is in how much access an AI agent should get, and the off switch is in how to build an AI agent kill switch.

Why isn't a rogue agent the real threat?

Because the real threat is a perfectly obedient agent doing exactly what you let it do. It didn't break a rule. There wasn't one. We didn't lose control of these systems. We handed over the keys and forgot to ask for them back.

Take the AI out of the sentence and none of this is new. Identity, access, privilege, accountability: the same problems security has worked for years, multiplied by machines that take thousands of actions before a person finishes reading the first alert. The controls are familiar. The speed isn't.

How do you run the ten-minute access check?

Pick one agent and ask your security team what it can access right now. Time the answer.

Answer

Verdict

"Reads these two tables, writes to none, credential expires every 24 hours, off switch is this console"

That's an answer

"It uses the service account"

That's the finding

Longer than ten minutes

Nobody holds the list, and that's the finding too

Run it on your customer-facing agent first, because that's where a bad afternoon becomes a call from a regulator.

What can you do this week?

  • Pick the agent closest to your customers and run the check.

  • Write down how long the answer took.

  • Put every system it reads and writes on one page.

  • Set credential expiry if there isn't any.

  • Name the person who can shut it off, and confirm they can actually do it today.

Frequently asked questions

Isn't this just normal access management?

Mostly, and that's the good news: you already have the practice and the people. What's different is volume and speed, and that's what breaks a manual process.

Who owns the access question?

The team that built the agent answers it. Security verifies it. If the builder can't produce the list, the agent isn't ready for production.

What if the agent needs broad access for its job?

Split the job. Most "needs everything" agents are doing several tasks on one credential. Scope each task separately, and if one path truly needs a wide credential, put a human approval in front of it.

Does this apply to agents we bought?

Yes, and vendor agents are often harder to answer for. Ask four things: what it reads and writes, how credentials rotate, who at the vendor sees your data, and how you shut it off without calling support. No answers means you have your board finding.

Key takeaways

  • Access is the blast radius. Scope it to the job and let credentials expire.

  • 109 machine identities per human, 79 percent of them agents.

  • 80 percent of companies report agents doing things they shouldn't. 44 percent have a policy.

  • Four contractor-badge basics: scoped access, expiring credentials, full logs, fast shutoff.

  • The ten-minute check turns all of this into one timed question.

Know the answer before your agents decide for you

The free ATF assessment takes about ten minutes, fittingly, and shows where your access answers run thin.

The question costs nothing to ask. The unasked version is the one with the price tag.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.