Steward Agent blast-radius intelligence
Identityreport_bot
Owner
Noah Williams, Analytics
Review state
pending
Effective accessDirect + delegated
  • delete_records direct grant
  • export_data direct grant
  • read_db direct grant
Granted vs. NeededLLM-assisted signal

Declared need

  • executes read-only queries on analytics database
  • exports analytics data to a file

Concrete grant gap

  • delete_records
Cited findings

Why this card needs attention

high risk 58/100 Over-privilege Deterministic check

Unused standing access: 2 direct grants

ReportBot holds standing privileges to delete records and export data that are never exercised. If the agent were compromised or misused, an attacker could invoke these unused grants to irreversibly remove critical data or exfiltrate sensitive information, exposing the organization to data loss, regulatory non‑compliance, and reputational damage.

Recommended actionRevoke the unnecessary delete_records and export_data grants from ReportBot and re‑certify its access against the principle of least privilege. Implement periodic review of granted versus used permissions for all agents.
Evidence agentreport_bot tooldelete_records toolexport_data
Control frameworks context, not certification NIST SP 800-53 Rev. 5 · AC-6 / AC-6(1) Least Privilege / Authorize Access to Security Functions SOC 2 Trust Services Criteria (2017) · CC6.1 Logical access security SOC 2 Trust Services Criteria (2017) · CC6.3 Access modification and segregation of duties ISO/IEC 27001:2022 · A.8.2 Privileged access rights ISO/IEC 27001:2022 · A.5.18 Access rights SOX ITGC · Least privilege Least-privilege provisioning
Least privilege — access certification using granted versus used access