What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Give an AI agent only the identity, tools, data, and actions required for one defined workflow—and enforce those limits in the connected services and runtime, not just in the model’s tool list. Separate reading from writing, gate consequential actions, and make the agent’s access observable and revocable.
What least privilege means for an AI agent
Least privilege is a system-design rule: an agent should be able to do only what its assigned workflow requires. Its effective capability depends on more than which tools appear in its configuration. It also depends on the credentials it uses, the data those credentials can reach, the actions the connected service permits, and the environment in which the agent runs.
- Identity: Which agent or workflow is making the request?
- Tools and actions: Which operations can it invoke, and are they read-only, narrowly writable, or broadly writable?
- Data: Which records or information can each operation access, and what information is sent to external services?
- Execution: What can the agent reach or affect from its runtime, especially if it encounters untrusted content?
NIST’s August 5, 2025 workshop article, Lessons Learned from the Consortium: Tool Use in Agent Systems, treats tool use as a set of dimensions that includes function, access patterns, risk, reliability, modality, monitoring, and autonomy. It distinguishes read-only, constrained-write, and write access, including in trusted and untrusted settings. NIST also notes: “Some agent implementations may access untrusted resources like the open internet, whereas others are designed for deployment in sanitized settings.” The access policy should reflect which kind of environment your agent actually encounters.
Start by defining the workflow and its access needs
Before adding tools or credentials, describe the task in terms of required operations and data. “Help with customer support” is too broad to authorize safely; “retrieve the status of a ticket and draft a response for an employee to review” is more actionable.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Write down the workflow’s outcome. Specify what the agent may complete on its own and what must remain with a person.
- List the required operations. Name the specific reads and writes the task needs. Do not grant a general-purpose account simply because it is convenient.
- Identify required data. Limit access to the records and fields necessary for those operations, where the service supports that scope.
- Classify consequences and reversibility. Consider what could happen if an operation is invoked incorrectly, and whether the result can be undone.
- Choose a control for each operation. Decide whether it can run automatically, should be narrowly constrained, or needs approval before execution.
Separate read access, constrained writes, and high-impact actions
| Access mode | Appropriate use | Control to apply |
|---|---|---|
| Read-only | Retrieval or analysis workflows that do not need to change records. | Expose only the required read operations and limit which data they can return. |
| Constrained-write | A narrow, defined change, such as updating a specific field as part of a workflow. | Restrict the available operation and its scope at the service boundary; validate inputs and outputs. |
| Write or consequential action | Actions with broad effects, significant impact, or difficult reversal. | Keep unavailable unless required. If required, use explicit approval and a clear record of what was authorized and executed. |
Prefer read-only access whenever it is sufficient. For writes, make the allowed change as specific as the service permits. Treat deletion, financial or access changes, external communication, and other consequential actions as candidates for human approval based on your workflow’s risk—not as ordinary tool calls.
Enforce permissions beyond the tool list
A tool list controls what the agent is offered, but it does not necessarily control what the connected account can do. A safe design uses multiple enforcement points:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Agent configuration: Expose only the operations needed for the task.
- Connected service: Use an account or authorization scope that limits what the service itself will permit. Do not assume hiding a tool removes the underlying account’s broader authority.
- Runtime: Restrict the agent’s access to other systems and resources, and isolate execution where possible.
- Approval and monitoring: Require review for designated actions and retain records that let operators understand what the agent attempted and did.
As one API-specific example, the OpenAI API reference describes configuration for allowed tool names, a read-only filter keyed to a tool’s readOnlyHint, and configurable approval rules. These settings filter the MCP tool set exposed to the model. They do not, by themselves, establish that the remote service enforces the user’s authorization. The principle is general; the configuration details are specific to that API.
Give the agent a scoped, revocable identity
Use a distinct identity for an agent or workflow rather than sharing a broad human account by default. Bind its credentials to the intended work, keep their scope narrow, and decide how to update or revoke them before deployment.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
NIST NCCoE’s 2026 concept paper, Accelerating the Adoption of Software and AI Agent Identity and Authorization, raises agent identification and authentication, key issuance, updates and revocation, zero-trust authorization, delegation, and human-in-the-loop authorization as areas for exploration. It asks: “How do we establish "least privilege" for an agent, especially when its required actions might not be fully predictable when deployed?” The paper is a concept paper, not a finalized standard. Its question highlights a practical design challenge: define the expected workflow in advance, but also plan for how access will be constrained or withdrawn if behavior or requirements change.
Limit data exposure, including to external connectors
Grant each tool only the information needed for its operation, and avoid sending unrelated or sensitive context to an integration. Treat every external tool or MCP server as a separate recipient: assess its access practices and data handling rather than assuming it follows the policies of the agent platform.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
OpenAI’s platform documentation states that data sent to remote MCP servers is subject to those services’ own retention policies. Check the relevant provider’s current terms and retention practices, and minimize what the agent sends to that provider. A tool’s presence in an agent configuration is not evidence that its data handling matches your organization’s requirements.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Contain untrusted input and unexpected behavior
Agents may process content that is misleading or hostile, including material from external sources. That content should not be allowed to expand the agent’s authority. NIST-hosted 2026 presentation material gives mitigation guidance that includes sandboxing, validating input and content entering persistent memory, monitoring for drift or unexpected tool use, applying rate limits and segmentation, and keeping provenance logs. Treat these as risk-reduction practices, not as mandatory requirements established by a standard.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
- Use a sandbox or other isolation boundary appropriate to the agent’s job.
- Validate what enters persistent memory; do not let untrusted content silently become trusted instructions or durable facts.
- Watch for unexpected tool calls or changes in behavior, and set rate limits or segmentation to constrain their reach.
- Keep provenance records that help an operator trace tool activity and investigate an incident.
Review the design before deployment
Use this checklist for each agent workflow, and revisit it when the workflow, tools, data, or operating environment changes.
- Is the workflow specific enough to identify necessary operations and data?
- Can the task work with read-only access? If not, are writes limited to the smallest useful scope?
- Are high-impact or difficult-to-reverse actions approval-gated?
- Does the connected service enforce a narrow identity or authorization scope, independently of the agent’s tool configuration?
- Can you update or revoke the agent’s credentials and access?
- Are untrusted input, runtime isolation, monitoring, rate limits, and provenance logging addressed for the deployment environment?
- Have you checked each external connector’s access and data-retention practices?
NIST’s 2025 tool-use article and 2026 NCCoE concept paper frame these issues as design and exploration topics; neither should be presented as a complete, finalized recipe for agent authorization. Apply the controls to the actual workflow and service boundaries in your deployment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

