CrowdStrike announced continuous per-action authorisation for AI agents, with a zero standing privilege approach in which the agent carries no broad credential and requests authorisation for each operation.
The design responds directly to what the period's incidents showed. An agent inheriting the credentials of whoever configured it reaches everything that person reaches, and none of the documented episodes required sophisticated technique: using already-available permission was enough.
Zero standing privilege is a familiar security concept and hard to apply, because each additional check costs time and interrupts flow. The bet is that for an automated agent, that cost is acceptable, since no person is waiting in front of a screen.
In the same period, another company partnered with an identity provider to let customers govern assistant use and access to tool providers, a sign that identity control for agents became a product category.
For smaller operations, the applicable version of the principle needs no new product: narrowly scoped credentials, short lifetimes, and a fixed list of what the agent may reach.
