Steward Agent blast-radius intelligence
Identityaccess_bot
Owner
Priya Nair, IT Identity
Review state
pending
Effective accessDirect + delegated
  • grant_access direct grant
  • request_access direct grant
Granted vs. NeededLLM-assisted signal

Declared need

  • submits an application access request for an employee

Concrete grant gap

  • grant_access
Cited findings

Why this card needs attention

high risk 44/100 Segregation of duties Deterministic check

Self-granting privilege path

AccessBot possesses both the request_access and grant_access capabilities, creating a self‑granting privilege path. This enables the agent to request and immediately approve access to applications without independent review, allowing unauthorized privilege escalation across the organization’s systems. The blast radius includes potential exposure of sensitive data, violation of compliance requirements, and the ability for an attacker who compromises the bot to obtain unrestricted access to any application the bot can request.

Recommended actionSegregate duties by removing the direct grant of the grant_access tool from AccessBot. Implement an approval workflow that requires a separate, privileged role to approve access requests. Apply least‑privilege principles to the agent, enforce monitoring of any grant actions, and conduct periodic reviews of agent permissions.
Evidence agentaccess_bot toolgrant_access toolrequest_access
Control frameworks context, not certification NIST SP 800-53 Rev. 5 · AC-5 Separation of Duties SOC 2 Trust Services Criteria (2017) · CC6.3 Access modification and segregation of duties ISO/IEC 27001:2022 · A.5.15 Access control ISO/IEC 27001:2022 · A.5.18 Access rights SOX ITGC · SoD Segregation of duties over financial processes EU AI Act (Regulation (EU) 2024/1689) · Art. 14 Human oversight
Identity governance — segregation of duties (access request versus access grant)