TL;DR: Before you hand over the keys to your AI stack, ask one question: “What can this person break that I can’t fix in five minutes?” If the answer is “a lot,” they get a limited role.
The Hook
You’re setting up a new agent for a client. It’s 11 PM. The client’s intern is eager, smart, and asks for “full access” so they can tweak the prompt. You’ve been here before. You know that giving an intern the admin key is like giving a teenager the car keys and saying, “Just don’t drive it into a lake.”
But you’re tired. You click “Grant.” Three days later, the agent is emailing the wrong customer list, and you’re explaining to a furious account manager why the invoice sat unanswered for 11 days.
The Pattern
I used to run everything with one master key. It felt efficient. Then a well-meaning contractor “cleaned up” a workflow and deleted the audit log. We spent a weekend rebuilding trust, not features.
Now, I treat access like a building pass. The contractor gets the lobby and the meeting room. The senior operator gets the server room. The owner gets the master key—and even that one is on a leash.
Here’s the practice: for every agent we deploy, we define roles by blast radius. What’s the worst thing this person could do? If it’s “send a test email,” fine. If it’s “delete the client’s entire CRM,” they get read-only.
The shift came when we started using scoped tokens and read-only modes as the default. The friction is tiny. The peace of mind is huge. And when someone asks for more, we ask: “What’s the task?” If they can’t answer without saying “just in case,” they don’t need it.
Companies that resist doing more—launching every new feature, saying yes to every request—tend to survive longer as this piece on competitive restraint notes. Access is the same. Saying no to the key is a feature, not a bug.
The Takeaway
- Default to least privilege. Read-only is the starting point. Edit is a conversation. Admin is a ceremony.
- Audit monthly. Revoke keys for anyone who hasn’t logged in for 30 days. It’s boring, but it’s the difference between a system and a mess.
- Make it easy to ask. When someone needs more access, they shouldn’t have to hack. A quick request that gets a quick answer builds trust—the kind that starts with clear human-AI boundaries.
We run our own agents on this principle at hub.sqs.chat. The key is a tool, not a trophy. Treat it that way.
by Jonas Reyes — the builder’s desk, Side Quest Studios
AI-assisted, curated for Side Quest Studios.
References
- as this piece on competitive restraint notes — https://www.fastcompany.com/91600011/why-the-most-competitive-companies-resist-the-urge-to-do-more
- that starts with clear human-AI boundaries — https://www.fastcompany.com/91602084/trust-in-ai-starts-with-human-ai-boundaries
- hub.sqs.chat — https://hub.sqs.chat