WORK · 2026-09-21 · agents · permissions
Blast radius
A way to judge AI agents by how far each step can reach — not by how many tools they have, or how pretty the answer looks. If the product has to ask permission in the middle of a job, the design already failed.
Most AI agents are sold on a tool list. The problem is not how many tools they have. It is what happens after a tool runs.
A job starts as an intent — “summarise this inbox.” The agent calls a tool. The tool has a side effect: mail is read, a message is sent, a file is written. That side effect has a radius: how much of the world just became reachable. The radius is the number that matters. Tool count is a brochure.
If the product has to pop up a permission dialog in the middle of the job, it already confessed. The graph is wider than the intent. Runtime protection is useful as a last ring. It is not a design.
Least privilege has to survive composition. A card that says read-only dies the moment a second plugin can talk to the first. An audit log that lists tool names and not “what could this path touch” is a confused deputy with good diction.
Offboarding is the test most platforms skip. Treat the job’s identity like a deploy key: scoped when the job starts, used in order, revoked when the job ends, evidence of the revoke in the log. If it stays connected, you did not finish the program.
The short versions of this live on X. This page exists because a post cannot carry the three figures.
Said shorter on Xpermission mid-jobradius per stepcompositionoffboarding