kaal:claim:7314479-033
At commit 2d920ce per-agent tool access is not yet implemented, so granting an agent access to a single Vault box grants it the ability to invoke every installed tool, and the user approves permissions tool by tool without ever seeing their composition.
Source quote, verbatim
The permission model records that per-agent tool access and per-agent internet access are not yet implemented, and that consequently all tools are available to all agents. Granting an agent access to a single Vault box therefore grants it the ability to invoke every installed tool, whose union of declared domains defines the true outbound surface. The user approves permissions tool by tool and receives their composition without ever seeing it.
From
Cite as
Holds when
Classification
empiricalsupport: evidencedconsensus-and-securityai-and-agentsgovernance-design
Verify
Positions extending this scholarly claim