AI security
Agent authority
Also called: tool authority, agent permissions
Agent authority is the set of actions an AI agent can perform and the identity it performs them as. Where an agent acts with a service credential rather than the calling user's permissions, it can reach data and operations the user could not, which converts a content-level attack into a privilege escalation.
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.