Try one task →
← All toolkit resources
Builders deploying connected tools · 20-minute exercise

Agent Permission Map

A least-privilege map of reading, proposing, changing and executing actions.

  1. List each integration and action, not just each tool name.
  2. Give read-only access where a draft is sufficient; separate proposal from execution.
  3. Require actual technical approval controls for send, pay, delete and access changes.
  4. Test prompt injection and accidental action attempts with a restricted test account.
  5. Document audit events, budget limits, revocation and recovery. Keep the human owner explicit.

Your worksheet

No confidential information. Filling this sheet does not send data to an AI provider. Blank prompts can be copied separately.

Tab-only state. Nothing is stored after you leave. Keep your downloaded worksheet somewhere appropriate.

Optional prompt · use only approved inputs

Turn this proposed workflow into a least-privilege permission map. Distinguish what the tool can read, propose and execute. Identify controls that must exist outside the prompt. Include non-destructive injection tests, human approval, audit, spend limits and revocation. Do not claim controls have been implemented.

Using this prompt in another service sends your inputs to that service. Check its settings first. It is not a tested guarantee of output quality.

Before you use the result

  • Are dangerous capabilities absent until explicitly needed?
  • Can approval be bypassed through another tool?
  • Can you revoke access and recover without the agent?