Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Limit an AI agent by restricting the tools it can call, the resources and operations those tools permit, and the files, credentials, and network available to its runtime. Enforce those limits in the connected services and infrastructure—not just in the agent’s instructions. Use a distinct identity, separate read from write access, require fresh human approval for consequential actions, and review and test the controls as the system changes.

What should you control?

An agent’s access is the combined reach of its tools, credentials, and execution environment. A chat interface may appear limited while its connected shell, browser, API, plugin, MCP server, or delegated agent can act on files or business systems. Map the whole route from the agent to the data or action, including indirect access.

  • Tools: Which capabilities can it invoke—such as file search, shell commands, email, CRM updates, database queries, publishing, or account administration?
  • Resources: Which directories, records, accounts, endpoints, or datasets can each tool reach?
  • Operations: Can it read, create, edit, delete, send, purchase, deploy, or change permissions?
  • Identity and credentials: Whose authority does it use, and what can its tokens or secrets authorize?
  • Runtime and network: What files and destinations can code running for the agent access?
  • Oversight: Which actions require additional validation or human approval, and what is recorded for review?

NIST’s Center for AI Standards and Innovation (CAISI) groups agent tools by what they do and by constraints such as read-only, constrained write, or write, as well as whether they operate in trusted or untrusted environments. Its examples include retrieval-augmented generation, browser use, application-specific APIs, coding agents, and computer use. These categories help describe capability; they are not a universal risk score.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to restrict an agent step by step

1. Inventory every route to action

List the agent’s direct tools and the systems behind them. Include shell and filesystem access, APIs, MCP servers, plugins, browser or computer-use capabilities, and any tools another agent can invoke. For each, record the available operations and target resources. A tool name such as “CRM” is not a permission description: establish whether it can read a particular set of records, edit fields, export data, or administer users.

#1 Best Overall
Sale
Magicmoon 2-Pack 24 Inch Computer Privacy Screen Filter for 16:9 Monitor
  • Compatible Model(s): Magicmoon brand filter only for 24 inch -diagonally measured - widescreen monitor - aspect ratio 16:9 - filter size: width: 20 15/16", Height: 11 13/16" (531mm x 298mm)
  • Superior Privacy: The computer privacy filter makes the screen appear dark when looking at it from an angle (the angle is about 30 to 60 degree), but bright when looking directly at it. To change the privacy level - simply adjust your monitor’s brightness accordingly
  • Eye and Screen Protection: Privacy Filter does not only protect your private life but also protects your eyes by blocking 30% of blue light , blocking the harmful blue light between 380 to 495 nm, it filters out the blue light and relieves eye strain
  • Perfect For Open Workspaces: Great for maintaining screen privacy in open work spaces
  • Includes Two Options: Option 1 uses clear adhesive strips that securely attach to any computer screen. Option 2 (for computer screens with a raised bezel only) uses slide mount tabs that easily stick to the display frame, allowing you to slide the privacy screen filter on and off as needed

2. Start with no access, then add only what the task needs

Remove tools that are not required, then scope the remaining capabilities as narrowly as the task allows. For files, use specific directories and operations rather than broad filesystem access or wildcard shell commands. For business systems, limit both the permitted records and the permitted actions.

Make read and write separate capabilities where practical. An agent that only needs to find a document should not also receive permission to overwrite or delete it. If a workflow genuinely needs writes, constrain which records or fields it can change and prefer reversible operations where possible. OWASP’s AI Agent Security Cheat Sheet advises granting only the minimum tools required for a task and scoping tool access.

3. Enforce authorization at the service boundary

Do not treat a system prompt, tool description, or the model’s decision to comply as an access-control check. Before executing a call, the relevant service, API, gateway, or tool server should verify the initiating person or workload identity, the requested operation, the target resource, and the applicable scope. Reject an unauthorized request even if the agent asks confidently or the user’s prompt appears to authorize it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
[2 Pack] 24 Inch Computer Privacy Screen Filter for 16:9 Widescreen Monitor
  • 【24 PRIVACY FILTER DIMENSIONS】 Width: 20 15/16" (20.9 inches/532 mm), Height: 11 13/16" (11.8 inches/299 mm) - 16:9 Aspect Ratio. Mamol computer privacy filters are designed to be perfectly compatible with HP, Samsung, Dell, Lenovo, Acer, Asus, LG, ViewSonic and other brands of monitors. Please check the width and height dimensions of your computer screen before ordering. If you have any questions about the dimensions, please contact us.
  • 【ENHANCED PRIVACY PROTECTION】Mamol 24 inch computer privacy filter keeps your electronic information confidential, making it excellent for use in high traffic areas. the computer privacy screen 24 inch is designed with advanced microlouver technology to block visibility at around 30 degrees and black out screens completely near 60 degrees.
  • 【EYES PROTECTION】 This blackout privacy screen greatly reduces eye strain and minimizes potential hazards to vision. It filters 99.9% of UV rays and suppresses 98% of blue light. As a reversible 24-inch privacy screen filter: The glossy side of the protector provides extra clarity and greater privacy, and the matte side minimizes glare and distracting reflections. Satisfy your different daily uses as needed.
  • 【BETTER HD CLARTIY】Mamol 24 inch computer privacy screen Shield adds an extra layer of AR Ultra HD light transmission compared to others. It maintains the high definition of the screen without sacrificing too much screen brightness. It won't reduce the brightness and cause eye fatigue because of the privacy screen installed on the screen.
  • 【ANTI SCRATCH & WASHABLE 】Our privacy anti-glare Monitor film has a surface enhancement layer to protect the privacy filter from scratches and fingerprints. It is washable and reusable. Even after prolonged use, you will get a brand new privacy screen for your desktop computer monitor after cleaning. Very Durable!

Validate tool inputs against strict schemas, and validate outputs where appropriate. For MCP servers, OWASP’s MCP Security Cheat Sheet recommends authorization on protected requests and scoped credentials for each server. Inspect tool names, descriptions, parameters, and schemas; do not pass unrestricted model-generated paths or raw shell commands to a privileged executor. Schema validation can catch malformed input, but a well-formed request still needs an authorization decision for that user, resource, and action.

4. Give each agent a distinct identity and narrow credentials

Avoid letting an agent act through a shared, all-purpose human account or a standing credential with broad access. Prefer a distinct identity for each agent or workload, separate credentials for different tools, and narrow OAuth scopes. Use short-lived or task-scoped tokens when the platform supports them, and review and revoke access that is no longer needed.

A secret available to code or tools in the agent’s environment is exposed to that environment. Keep long-lived credentials in a secrets manager and broker access outside the sandbox where feasible; do not assume a secrets manager protects a secret after it has been injected into an agent-accessible process. OpenAI’s API documentation on sandbox security warns that agent-generated code can access files, credentials, and network resources available to its environment, and advises keeping the application key outside that environment. AWS and Microsoft publish vendor-specific guidance on least-permission roles, scoped access, and agent identities; their service examples are not universal platform requirements.

Rank #3
SightPro 24 Inch 16:9 Computer Privacy Screen Filter for Monitor - Privacy Shield and Anti-Glare Protector
  • 【Privacy Filter Dimensions】- Width: 20 15/16" (532 mm), Height: 11 13/16" (299 mm), Diagonal: 24" (609.6 mm) - SightPro Blackout Privacy Screen Filter is engineered to be compatible with HP, Dell, Samsung, Lenovo, LG, Acer, ASUS, ViewSonic, and other monitor brands. Please verify your computer screen's width and height measurements before ordering. It's not recommended to make your selection based solely on your computer screen's diagonal size.
  • 【Two Attachment Options】- Installs in minutes. Option 1 uses clear adhesive strips that securely attach to any computer screen. Option 2 (for computer screens with a raised bezel only) uses slide mount tabs that easily stick to the display frame, allowing you to slide the privacy screen filter on and off as needed.
  • 【Superior Privacy and Anti Glare】- Our advanced multi-layered film filter blacks out your computer screen when viewing from the side, while maintaining a crystal clear screen straight-on. It also protects your eyes from harmful glare, UV, and blue light. [Note: It does not block visibility directly behind you, regardless of the distance.]
  • 【Perfect for Travel and Open Workspaces】- Our computer screen privacy filter is the ideal solution for healthcare providers, mobile workers, commuters, students, and business travelers. Now you can stay compliant and safeguard sensitive corporate information while working in airplanes, subways, airports and public areas.
  • 【Package Contents】- Each package includes one privacy screen shield filter, two sets of clear adhesive strips, two sets of slide mount tabs, and a microfiber cleaning cloth. Buy with confidence – located in the US, Sight Pro specializes in providing best-in-class privacy solutions to individuals, small businesses, corporations, government, and educational institutions. Our privacy screens are Section 889 and TAA compliant.

5. Isolate the runtime and restrict network access

Run agent-generated code in an environment suited to the task’s risk, such as a dedicated virtual machine or restricted container. Mount only the paths it needs, avoid sharing data between workloads that should be isolated, and block outbound network connections unless the task requires them. If network access is needed, allow only approved destinations where your infrastructure supports that control.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Isolation reduces the potential reach of a mistake or attack, but it does not compensate for a tool that is itself over-permissioned. Review how data moves through connected tools as well as what the runtime can see. OWASP’s MCP guidance also recommends sandboxing local servers, restricting directories, and disabling network access when it is unnecessary; in MCP deployments, treat servers as separate trust domains and monitor changes to their tool definitions.

6. Put a specific approval gate in front of consequential actions

Classify operations by impact and reversibility. A controlled read-only lookup may not need an approval for every call. Deleting data, changing permissions, sending an external message, purchasing, deploying, or exporting sensitive records warrants additional validation or fresh human approval.

Rank #4
Peslv 2-Pack 24 Inch 16:9 Computer Monitor Privacy Screen, WxH:532 * 299mm
  • 【PRIVACY FILTER DIMENSIONS】- Width: 20 15/16" (532 mm), Height: 11 13/16" (299 mm), Diagonal: 24" (609.6 mm) - Peslv Dark 24 inch Privacy Screen Filter is engineered to be compatible with 24in Dell, HP, Samsung, Lenovo, LG, Acer, ASUS, Toshiba, ViewSonic, Aoc, Sceptre, PHILIPS, ViewSonic and other brands monitors with 16:9 aspect ratio. Please verify your computer screen's width and height measurements before ordering. It is not recommended to select a size based solely on the diagonal.
  • 【HIGH-CLASS PRIVACY ABLE】Peslv collected suggestions from more than 2000 computer users and performed 22188 anti-peep angle corrections on the micro-blind optical technology to ensure that any line of sight beyond +-30° facing the screen will be shielded. With a Peslv computer privacy screen 24 inch, Protect the privacy of your computer monitor screen and no longer leak any confidential data.
  • 【2 MOUNTING OPTIONS FOR EASY INSTALLATION】The Peslv 24 inch privacy screen for monitor supply 2 installation options, Various installation options, are Compatible with both 24" computer monitors with raised bezels and full-screen 24" computer monitors without raised bezels, and convenient installation allows you to complete the installation in 9 seconds. NOTE: Monitors without raised bezels are only available with mounting option 2.
  • 【EXCLUSIVE DOUBLE-SIDED TECHNOLOGY】24-inch monitor privacy filter has a double-sided surface technology developed by Peslv. Matte or Glossy. With the matte surface facing outward, you can experience the advanced AG anti-glare technology from Germany while maintaining a 30-degree privacy angle, softening the strong light outdoors, and making the screen content clearly visible. With the glossy side facing outward, you can get a super anti-peeping effect with a privacy angle of 26 degrees.
  • 【PROTECT SCREEN ALSO EYES】Filtering optical materials imported from Japan can reduce 92% of blue light and 98% of UV light, and filter all harmful light emitted from the screen to protect your eyes. The high-transparent and reinforced built-in protective layer not only presents high-definition picture quality but also protects your screen from scratches. Hurry up and place an order, own a privacy screen for a computer monitor 24 inch, and protect your monitor screen and your eyes.

Show the approver the actual proposed action and its parameters: for example, which records will be changed, what message will be sent, or what amount will be spent. Bind approval to that specific action rather than treating a general instruction or earlier consent as permission for later actions. The execution path must enforce the approval; the agent should not be able to skip it by generating a different response or invoking another tool.

7. Log, review, and test the boundaries

Record tool calls and denied attempts with enough identity and scope context to investigate them, while avoiding plaintext secrets and unnecessary sensitive payloads. Review identities and permissions periodically, remove unused access, and monitor for behavior outside the intended workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test realistic abuse cases before deployment and after changes to tools, credentials, prompts, or policies. Include prompt injection in a document or other untrusted content, path traversal, an unauthorized write, data exfiltration, and an attempt to bypass an approval step. OWASP recommends adversarial testing and release checks when high-risk tool policies or scopes change. Narrow permissions reduce the possible impact of prompt injection or other misuse; they do not guarantee the agent will behave correctly.

Best Value
ZOEGAA [2-Pack Computer Privacy Screen Protector 24 Inch 16:9 Aspect Ratio
  • [How To Determine The Screen Size]: Before Purchasing Our 24 inch privacy screen for monitor, Please Measure The Size Of Your Computer Screen First. Our computer privacy screen 24 inch Is Suitable For Computer Screens With A Width Of 20.92 Inches (53.13 Cm), A Height Of 11.77 Inches (29.89 Cm), And A Diagonal Length Of 24 Inches (60.96 Cm). (It Is Not Recommended To Choose The Size Only Based On The Diagonal Length.) The ZOEGAA 24-Inch 16:9 computer privacy screen Is Compatible With HP, Samsung, Dell, Lenovo, Acer, ASUS, Viewsonic And Other 24-Inch 16:9 Computer Monitors. Welcome To Your Purchase!
  • [Outstanding Privacy Effect]: The Engineer Team Of ZOEGAA Has Collected Suggestions From Over 5,000 Computer Users And Corrected The Anti-Peep Viewing Angle Of The Micro-Blind Optical Technology For 35,462 Times To Ensure That The View Beyond ±30 Degrees Will Be Hidden. People On Your Left And Right Will See A Black Screen.
  • [How To Install]: ZOEGAA 24 inch monitor privacy screen Supports 2 Installation Methods. The First One Is The Insert Type Installation, Which Is removable. The Second One Is The Mounting Adhesive Installation, Which Is Non-Detachable. For Detailed Installation Methods, Please Refer To The Pictures Or Videos In The Listing.
  • [Better Clarity]: ZOEGAA privacy screen 24 inch monitor. It Has Added An AR High-Definition Light-Transmitting Layer, Which Enables The computer monitor privacy screen To Maintain Its Original Clarity While Achieving The Anti-Spy Effect; It Will Not Cause Eye Fatigue Due To The Installation Of The privacy screen for monitor.
  • [Reversible Glossy And Matte Surfaces]: The 24 in privacy screen for monitor Of ZOEGAA Has Two Different Surface Textures - The Glossy Surface Offers Better Anti-Peeping Effect, While The Matte Surface Provides Better Anti-Glare Performance. The Matte Surface Is Suitable For Use In Strong Light Environments. This 24 inch monitor privacy screen Also Has Anti-scratch And Anti-Fingerprint Functions, Ensuring That You Won't Worry About Being Damaged By sharp Objects During Use. It Is Washable And Can Achieve A Brand-New Appearance After Being Washed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to choose the right access level

Choose the least capable arrangement that completes the business task. Assess operation, resource scope, environment, identity, and impact together rather than treating access as simply enabled or disabled.

Control dimension Narrower arrangement Broader arrangement Practical decision
Operation Read-only or constrained write Unrestricted write Grant write only when the workflow requires state changes; separate it from read access where feasible.
Resource scope Specific paths, record sets, or approved endpoints Broad directories, datasets, or endpoints Identify the smallest usable scope for each tool, not just for the agent overall.
Environment Curated trusted data and restricted execution Untrusted web or user-supplied content with broad execution access Account for the possibility that external content can try to influence tool use.
Identity and credentials Distinct identity, narrow scopes, and short-lived grants where supported Shared account or broad standing credentials Use separate identities and credentials by workload or tool when practical.
Impact and oversight Reversible, low-impact calls with proportionate checks Destructive, financial, or externally visible actions without a separate gate Require specific validation or fresh approval as impact rises.

NIST CAISI’s examples illustrate how context changes a classification: it places retrieval-augmented generation in a read-only, trusted-environment category; application-specific GUI or API use as constrained write in a trusted environment; and computer use as write in an untrusted environment. These are illustrative placements in its taxonomy, not classifications that apply to every implementation.

What access controls can—and cannot—guarantee

  • Prompt instructions are not authorization. They can guide behavior, but the connected system must decide whether a requested operation is permitted.
  • A valid request is not necessarily an authorized one. Schema checks help validate form; the service still needs to check identity, resource, operation, and scope.
  • A sandbox only limits what it does not expose. Code in the environment can access the files, credentials, and network made available there.
  • Least privilege limits blast radius, not every failure. An agent may still misuse an allowed capability, so consequential actions need appropriate checks and monitoring.
  • More restrictions can also constrain a useful workflow. Establish the actual task requirements, then grant narrow permissions deliberately rather than adding broad access preemptively.

The guidance here draws on OWASP’s AI Agent and MCP Security Cheat Sheets, NIST CAISI’s “Lessons Learned from the Consortium: Tool Use in Agent Systems” (released August 5, 2025; updated August 7, 2025), AWS Prescriptive Guidance, OpenAI’s sandbox security documentation, and Microsoft Learn’s identity and least-privilege guidance (last updated August 1, 2026). Platform-specific setup and available controls vary, so apply each vendor’s examples only to the services they describe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.