Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An AI agent should have a distinct, accountable identity, only the permissions its job requires, and a limited path to the data and systems it can reach. Treat “guest, not a tenant” as a security principle—not a formal identity category: give each agent a defined role, constrain its working environment, and assign someone to review and revoke its access.

What “guest, not a tenant” means for an AI agent

An agent can read information, use tools, and take actions on a person’s or organization’s behalf. If it inherits broad access from an employee account or can reach more files and services than its task needs, a mistake or manipulation can have a much larger impact.

A safer design makes the agent separately identifiable and limits what it can do and reach. That does not mean every agent must use the same technical setup: controls depend on the identity provider, the applications involved, the agent’s capabilities, and the sensitivity of the data. The goal is to make an agent’s access attributable, bounded, reviewable, and removable.

Give the agent an identity that matches its job

A distinct identity helps administrators attribute activity and grant or withdraw permissions without treating the agent as a human employee. Microsoft Entra documents several ways to assign agent identities to applications; these are Microsoft-specific patterns, not universal requirements for every identity provider or service.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Choose an authorization pattern the application supports

First define the task and the minimum access needed to complete it. Then confirm which authorization pattern the target application supports. Microsoft describes these options:

  • OAuth permission scopes: consent an agent identity or service principal to the scopes the application exposes.
  • Application roles: assign an agent identity or service principal a role when the application recognizes service-principal roles.
  • Agent users for some SAML applications: where an application requires users, augment the agent identity with agent users—but confirm that the application supports this pattern.

These patterns and the application-support caveat are described in Microsoft’s Entra documentation on assigning agent identities to applications. An identity is not least privilege by itself: administrators still choose the permissions, and a permission suitable for one task may be excessive for another.

Make access attributable and removable

Record who owns the agent, what work it is permitted to perform, which applications and data it can access, and how that access will be reviewed and revoked. Keep its identity separate enough that activity can be associated with the agent rather than disappearing into a shared human account. This gives administrators a practical way to investigate unexpected activity and end access when the task or owner changes.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Limit what the agent can reach at runtime

Identity permissions govern access to applications; execution boundaries can further limit the files, credentials, and network destinations available while an agent runs. These controls complement each other. A narrowly permissioned identity can still be exposed to risky files or tools, while an isolated environment does not make an overprivileged application account safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Containment patterns vary by product

Anthropic describes different containment designs across its products: an ephemeral server-side container, a local human-in-the-loop sandbox, and a virtual-machine-based Cowork design. In its account, Cowork limits visible host files to selected mounts and keeps credentials in the host keychain rather than inside the guest. Anthropic also says its local coding sandbox allows reads and workspace writes while denying network access by default, reducing the number of approval prompts. These are descriptions of Anthropic’s systems, not proof that the same design is sufficient for every agent or organization. See Anthropic’s explanation of how it contains Claude across products.

Approval prompts and containment control different things

Control What it limits What it does not settle on its own
Action-by-action approval Whether a person permits a particular action when asked. What the agent can reach between prompts, whether a person can judge each request reliably, or whether approvals become routine.
Environment-based containment Reachable resources, such as mounted files or network access, when the boundary is correctly configured. Whether an allowed resource or destination can be misused, or whether the agent’s application permissions are appropriately scoped.
Identity and application authorization Which application permissions are granted to an identifiable agent or service principal. Whether the runtime exposes risky files, tools, or network capabilities outside those application permissions.
Inventory, logging, and lifecycle controls Who owns deployed agents, what activity is recorded, and how access is reviewed or retired. Whether an agent is safe during an individual action unless runtime and permission controls also constrain it.

The controls address different failure modes, so an organization should combine them according to the task and its risk rather than treating prompts or isolation as a complete safety solution.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Allowlisted destinations can still create risk

A network allowlist only says which destinations the agent may contact; it does not establish that every capability available through an allowed destination is safe. Anthropic describes an incident in which a malicious workspace file led an agent to upload files using an attacker-controlled key through a destination permitted by the egress allowlist. Anthropic says it mitigated the incident with a proxy that checks for the VM-provisioned session token and rejects attacker-embedded keys. This is Anthropic’s account of its incident and mitigation, not independent verification.

File boundaries need careful implementation

A mounted workspace may still be damaged by a compromised or misbehaving agent, and broad connector access increases exposure. Anthropic also warns that symbolic links can undermine filesystem path checks if a system validates a path before resolving symlinks. A boundary is only useful when its implementation accounts for how paths resolve and what capabilities mounted files or connected tools expose.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use human review where it adds judgment

Approval prompts can help a person review consequential actions, but repeated prompts are a weak sole barrier if users click through without evaluating them. Anthropic reports that users approved roughly 93% of permission prompts in its telemetry. It also reports an 84% reduction in permission prompts after shipping an OS-level sandbox for Claude Code. Both figures describe Anthropic products and telemetry in its 2026 account; they are not industry-wide measurements or independently validated comparisons. Anthropic’s article describes the figures and the containment designs behind its discussion.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Use prompts when a person can meaningfully assess an action and when the action’s consequences justify the interruption. For routine or low-risk work, enforce access limits in the identity, application, and runtime instead of relying on a stream of approvals. For high-impact actions, retain human review and make sure the person receives enough context to decide what is being authorized.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Build governance around ownership and the agent lifecycle

Runtime restrictions do not answer who approved an agent, which data it may handle, whether it is still needed, or who disables it when its owner leaves. Microsoft Digital describes an approach combining embedded governance, IT oversight, and user education. It differentiates retrieval-only builders, which it describes as lower risk, from task-completion and workflow-automation tools with connectors and external channels, which have greater risk potential.

In its May 21, 2026 account, Microsoft Digital describes agent inventory, activity logging, lifecycle management, data classification, oversight, and isolation so agents do not cross data boundaries. These are Microsoft’s practices and perspective, not a requirement to adopt Microsoft products or reproduce its framework. The transferable work is to:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
  • Classify agents by what they can do, which connectors they use, and the sensitivity of accessible data.
  • Assign an owner and keep an inventory of deployed agents.
  • Review sharing, permissions, and connected applications as an agent’s purpose changes.
  • Log activity in a way that supports investigation and oversight.
  • Define how to retire an agent and revoke its identity, permissions, and connected access.

Microsoft Digital’s account is available in “Governing AI agents at scale: Lessons from our journey at Microsoft.”

Understand shared responsibility when using a cloud sandbox

A cloud sandbox can provide an isolated runtime, but buying or enabling one does not transfer responsibility for the agent’s configuration or behavior. Alibaba Cloud’s AgentBay security whitepaper describes a shared-responsibility model: the provider secures its platform and isolated runtime, while customers remain responsible for configuration, data, agent logic, and behavior. It describes VM-backed and session isolation and recommends least-privilege access policies, credential protection, data classification, and network rules. These are vendor-stated features and recommendations, not neutral test findings. See the AgentBay Security Whitepaper.

A practical review before deployment

  1. Define the task. Specify what the agent must do, what data it needs, and which actions could cause material harm.
  2. Choose a distinct identity and supported authorization method. Grant only the required scopes or application roles, and verify the target application supports the chosen pattern.
  3. Reduce runtime reach. Limit mounted files, tools, connectors, credentials, and network destinations to what the task needs. Treat allowed destinations as capabilities to assess, not automatic guarantees of safety.
  4. Set review points by risk. Require a person to assess consequential actions; do not make repeated prompts the only effective control.
  5. Assign ownership and record activity. Put the agent in an inventory, identify its owner, classify its data access, and make activity review possible.
  6. Plan for change and retirement. Review access when the task, data, connectors, or owner changes, and revoke the agent’s identity and permissions when it is no longer needed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.