Home/Security & Governance/Tool-Level Token Scopes
SECURITYTOOL-LEVEL TOKEN SCOPES

Tool-Level Token Scopes. Least privilege, per action.

Every tool an agent can use carries its own token scope — so a workflow that reads claims can't touch payroll, and every action answers "who, from what, reviewed by whom".

How it works

Permissions attach to tools, not to agents: an agent composes narrowly-scoped capabilities rather than inheriting a role's broad access. Write scopes are separate from read scopes, granted per workflow, and exercised only after the relevant gate.

Provenance is the twin guarantee: every deliverable records who — or what — produced it, from which inputs, reviewed by whom. That chain is queryable per artifact and exportable as a full audit trail on request.

Guarantees

Per-tool scoping

Access granularity at the action level, not the agent level.

Read/write separation

Writing anything is a distinct, gated privilege.

Provenance per artifact

Producer, inputs and reviewers recorded on everything.

Audit trail on request

Evidence packs assembled from live records, not reconstructed.

Pick your function. Own the intelligence behind it.

Discover one opportunity, engineer one capability, deliver one measurable outcome — then scale.