Control Packs · IDN-001 · v1.0.0

Least Authority for Automated Tools

Constrain automated tool calls to the minimum resources, operations, and approval scope required by the confirmed design.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Limit automated tools by operation, resource, environment, actor, and time, with explicit approval for privileged actions.

  • Excess authority on an automated toolA tool can read, change, or administer resources beyond the action and scope confirmed by an authorized person.
Versioned applicability rule
{
  "all": [
    {
      "characteristic": "TOOL_ACCESS",
      "equals": true
    },
    {
      "any": [
        {
          "characteristic": "PRIVILEGED_ACTION",
          "equals": true
        },
        {
          "characteristic": "CONSEQUENTIAL_ACTION",
          "equals": true
        }
      ]
    }
  ]
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • Which operations and resources may the automated tool access?A tool grant should be a bounded scope rather than an implicit administrator role.IDN-001-Q1 · scope

Requirements for the coding agent

  • IDN-001-R1Use allowlisted operations and resources, separate read and write authority, require explicit approval for privileged changes, and expire temporary grants.

Tests and evidence to retain

  • TOOL_AUTHORITY_TESTVerify allowlists, denied operations, privileged approval, and grant expiry.
  • configuration_or_policy
  • implementation_location
  • test_result
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • AC-6 · Least PrivilegeNIST_SP_800_53_5_2_0 · partially addressesOperation, resource, environment, and expiry allowlists operationalize least authority for tools; they do not cover the full access program.
  • AC-3 · Access EnforcementNIST_SP_800_53_5_2_0 · partially addressesDenied operations and explicit approval support access enforcement at the tool boundary; they do not establish complete enforcement.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review