The instinct is to ask “what does this user have access to?” and extend that same logic to the agent acting on their behalf. But that’s the wrong question. An agent doesn’t need a copy of someone’s permissions, it needs access scoped to a specific task, for a specific reason, for as long as that task takes. Anything broader creates exposure that wasn’t there before.
The usual fallback is to try to handle this with traditional tools: more roles, more groups, more granular permissions for every possible scenario. In this video, Immuta Field CTO Paul Myres explains why that approach falls apart fast, and what actually has to change about how organizations think about access once agents enter the picture.