Steward Agent blast-radius intelligence
Identitysupport_bot
Owner
Elena Rodriguez, Customer Support
Review state
pending
Effective accessDirect + delegated
  • read_customer_pii direct grant
  • send_external_email direct grant
Granted vs. NeededLLM-assisted signal

Declared need

  • reads customer contact and account information for support cases
  • sends email messages to external recipients

Concrete grant gap

No tool-ID-level gap was asserted. Treat capability inferences as review context, not a fact.

Cited findings

Why this card needs attention

critical risk 64/100 Segregation of duties Deterministic check

Critical data-exfiltration path

SupportBot can read customer PII and directly send external email, creating a direct path for confidential customer data to be exfiltrated outside the organization, exposing the firm to regulatory violations, financial penalties, and reputational harm.

Recommended actionRevoke the direct read_customer_pii and send_external_email grants from SupportBot; implement least‑privilege controls, require mediated approval for external egress, and add monitoring/auditing of any PII access and outbound email activity.
Evidence agentsupport_bot toolread_customer_pii toolsend_external_email
Control frameworks context, not certification NIST SP 800-53 Rev. 5 · AC-5 Separation of Duties SOC 2 Trust Services Criteria (2017) · CC6.3 Access modification and segregation of duties ISO/IEC 27001:2022 · A.5.15 Access control ISO/IEC 27001:2022 · A.5.18 Access rights SOX ITGC · SoD Segregation of duties over financial processes EU AI Act (Regulation (EU) 2024/1689) · Art. 14 Human oversight
Data protection — least privilege and controlled external egress