Taking a least privilege mindset to MCP

Bill Doerrfeld | September 15, 2026

Does your agent really need access to every tool call under the sun?

You can't just tell an agent, "Don't touch production."


We've already seen plenty of examples of what happens when AI agents accidentally have too many privileges: deleted databases, destructive code commits, business disruption, and more.


And industry reports and case studies demonstrate that agents are routinely overprivileged, with a growing visibility gap around what they can actually access. Call it what you want: multi-agent privilege drift, permission sprawl, shadow MCP servers.


One important guardrail is least privilege.


My latest for the Zuplo blog makes the case for applying least privilege to agentic tool calls:


The reason? Agents are tenacious. They'll use or try whatever tools and means are at their disposal to unblock themselves. Sometimes that goes haywire.


But, of course, we can't take away all the "autonomy" from agents. Otherwise, they wouldn't be that "autonomous," would they? ๐Ÿ˜‰


The answer is somewhere in the middle: carefully curating what you expose and making smart access decisions in the moment.

Read: Why Agentic Tool Calls Need Least Privilege

Other Blog Posts

By Bill Doerrfeld September 8, 2026
I'll be writing a weekly series for The New Stack this fall covering Kubernetes, cloud native, and everything happening on the road to KubeCon in November.
By Bill Doerrfeld September 1, 2026
I'm teaming up with Dan Barahona and AI Security University to put together the MCP Security Conference, a free half-day virtual event dedicated to MCP security .
By Bill Doerrfeld August 27, 2026
My latest DirectorPlus edition interviews Shopify's head of engineering, Farhan Thawar, on their unique internal engineering culture.
By Bill Doerrfeld August 24, 2026
Neoclouds promise cheaper GPUs and AI-optimized infrastructure, but can they really challenge hyperscalers? My feature on InfoWorld explores their advantages, risks, and likely role in AI compute.
By Bill Doerrfeld July 29, 2026
My latest for LeadDev interviews IBM's Neel Sundaresan on how to prevent a decades-old issue in software engineering.
By Bill Doerrfeld July 13, 2026
The latest advancement in identity and access management (IAM) is something called zero standing privilege. It's a response to new agentic AI risks.
By Bill Doerrfeld July 7, 2026
Big surprise: it's way easier to generate new code with AI than to reuse old code. But what are the long-term effects?
By Bill Doerrfeld June 25, 2026
Agentic coding tools have become the default. "When we've taken that away accidentally from people, they scream."
By Bill Doerrfeld June 17, 2026
My latest for LeadDev considers how engineering leaders should respond in the wake of uncertainty in the AI model market.
By Bill Doerrfeld June 10, 2026
I'm working with Zuplo on some new content around their MCP Gateway release. First up: a deep comparison of MCP gateways on the market!