Recommended Free Tools
To audit an AI agent’s permissions, trace the identity behind each tool or API call, then compare its effective access with the task it is meant to perform. An agent may act with a user’s delegated access, with its own application or service identity, or with a mixture of identities. Do not assume it has only the permissions of the person who started it: app-only grants and permissions accumulated across tools can give it broader access.
What to establish before reviewing permissions
Start with the agent’s full call path, not just its chat interface. Identify who or what authenticates each step: the initiating user, the agent runtime, a connected tool, and the downstream service. A workflow can switch identities between steps, so there may not be one permission set that describes the whole agent.
For every agent, record its business purpose, accountable owner, environment, connected tools and plugins, credentials, identities, target resources, and data scope. Microsoft’s least-privilege guidance for AI agents recommends documenting the agent’s purpose, approved data access, tool dependencies, and operating environment, and inventorying deployed or planned agents and integrations.
Follow the identity used at each call
The key question is whether an operation runs with delegated user permissions or with permissions assigned to the agent or application. Microsoft distinguishes these access patterns in its AI agent access-pattern guidance:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
| Access pattern | Whose authority is used | What to check |
|---|---|---|
| Delegated access | The application acts on behalf of a signed-in user. The downstream service can authorize the operation in that user’s context. | Which user is represented, which delegated scopes were consented to, and whether each downstream service enforces that user’s access. |
| App-only access | The application acts as itself, without a signed-in user, using application permissions or another service identity’s grants. | Which app roles, cloud IAM/RBAC assignments, resource boundaries, and trust policies apply. Limit grants to the agent’s actual task requirements. |
| Mixed access | Different steps use different identities or authorization models. | Trace every tool and API call separately; do not infer one call’s authority from another’s identity. |
Delegated access is generally the appropriate pattern when an agent works with user-owned data and should not exceed what that user may access. Microsoft states: “Don’t use a backend identity to bypass user permissions.” Background work may require app-only access, but that does not justify broad grants; scope them to the smallest set needed.
AWS advises that when an agent acts for a user, it should carry user context as token claims rather than assume the user’s role or credentials. Its Agentic AI Lens guidance on permissions warns that assuming a human role can blur attribution and expose the user’s full permissions for the session. AWS also states: “Identity propagation alone isn’t enough when agents act on behalf of users.” Check authorization at the downstream service as well as propagating identity.
Compare effective access with the intended task
Inspect permissions across the complete path: OAuth scopes and consent, application roles, cloud IAM or RBAC assignments, role trust policies, resource and tenant boundaries, available tool actions, and authorization checks in downstream services. Assess how these grants combine. Several individually narrow roles or tools can create broader effective authority when used together.
For each tool, check whether its permissions match the specific task and data it handles. Where possible, separate read access from write access, constrain resources and fields, and allowlist actions. Pay particular attention to operations that can delete or export data, change privileges, or write beyond the task’s scope. For sensitive or irreversible actions, establish whether approval or just-in-time elevation is required and whether the downstream service independently checks authorization.
Free tools Windows power users keep installed
One-click scans. No signup required.
Verify logs, revocation, and review procedures
Permission configuration shows what an agent could access; attributable logs help establish what it actually did. Review whether records identify the agent, the “on behalf of” user where applicable, the effective scope, action, resource, and correlation ID. Evidence should cover tool actions and authorization decisions—not merely the agent’s chat response. AWS recommends distinct agent and human identities so their actions can be distinguished in audit records.
Test the controls that limit or end access. Confirm you can disable the agent, rotate its credentials, invalidate tokens, remove stale permissions, and verify that downstream services deny access after revocation. Reassess permissions when the tools, workflow, data scope, or deployment environment changes. Microsoft recommends periodic access reviews; its Entra-specific agent identity best-practices page suggests sponsor attestation every 6–12 months. Treat that interval as Entra guidance, not a universal requirement; AWS says review cadence should match risk.
Quick Recap
Best Value
Use this checklist for each agent
- Is there a distinct, named agent identity and an accountable owner?
- What identity and credential does each tool call actually use?
- Which grants are delegated user scopes, and which are app roles or service-identity permissions?
- Do permissions from different roles, tools, and systems combine into broader access than intended?
- Are resource, tenant, repository, site, and data boundaries explicit?
- Can the agent invoke unreviewed tools, delete or export data, change privileges, or write outside its task scope?
- Do downstream services re-check authorization for each call?
- Can logs identify the agent, user context, action, resource, scope, and correlation ID?
- Have credential revocation and stale-grant removal been tested?
- Is access reviewed after meaningful changes and at a cadence appropriate to the risk?
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

