Direct answer
What is a least-agency access review?
#A least-agency access review determines the minimum objective, context, data, tools, permissions, duration, budget, delegation rights, and side effects an agent needs for one bounded task. It also defines prohibited actions, authority checkpoints, evidence, expiration, and revocation.
- Do not give a general-purpose agent standing access because one workflow may need it.
- Prefer task-scoped and short-lived credentials.
- Separate the ability to propose an action from the authority to execute it.
Source basis: reviewed synthesis of the strategy corpus. Report-derived claims remain subject to the verification boundary in the source library.