Steward Agent blast-radius intelligence
Identitysales_bot
Owner
Talia Brooks, Revenue Operations
Review state
pending
Effective accessDirect + delegated
  • read_crm direct grant
  • send_external_email direct grant
Granted vs. NeededLLM-assisted signal

Declared need

  • reads sales account notes and opportunity context from CRM
  • sends email messages to external recipients

Concrete grant gap

No tool-ID-level gap was asserted. Treat capability inferences as review context, not a fact.

Cited findings

Why this card needs attention

high risk 54/100 Segregation of duties LLM-generalized

AI-generalized toxic capability combination: Read CRM account context + Send email outside the company

The SalesBot agent can both read CRM account context and send email outside the company, creating a direct path to expose customer information to external recipients. This combination can lead to unauthorized data disclosure, regulatory non‑compliance, reputational damage, and potential financial loss.

Recommended actionSeparate the read_crm and send_external_email permissions, enforce a dual‑approval workflow for any external email that includes CRM data, and implement continuous monitoring and audit of combined usage.
Evidence agentsales_bot toolread_crm toolsend_external_email
Control frameworks context, not certification NIST SP 800-53 Rev. 5 · AC-5 Separation of Duties SOC 2 Trust Services Criteria (2017) · CC6.3 Access modification and segregation of duties ISO/IEC 27001:2022 · A.5.15 Access control ISO/IEC 27001:2022 · A.5.18 Access rights SOX ITGC · SoD Segregation of duties over financial processes EU AI Act (Regulation (EU) 2024/1689) · Art. 14 Human oversight
Identity governance — Model-identified segregation-of-duties candidate