Least Privilege: Give the Minimum Access
The most useful safety idea in this course has an ugly name: least privilege. It means giving an agent only the access it needs for the job at hand, and nothing more.
In practice this looks like small choices. Point a file agent at one folder, not your whole computer. Connect a read-only version of an app when reading is enough. Use a separate account with limited access, rather than your main login, for anything an agent will be signed into. Give it a spending cap on any service that bills by usage.
Ask two questions each time you set something up. What is the worst thing this could do with this access? And do I need it to have this access, or is it just convenient? If the worst case would be painful, narrow the access or keep a person in the loop for that step.
You can always widen access later, once the agent has earned it. It is much harder to undo a mistake made with too much access at the start.
Takeaway: give an agent the smallest folder, the read-only version, and the lowest limits that still get the job done. Widen later if it earns it.
Tools, prices and features in this area change quickly. Last reviewed September 2026.