frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Ask HN: Who is hiring? (February 2026)

236•whoishiring•9h ago•298 comments

Ask HN: Who wants to be hired? (February 2026)

95•whoishiring•9h ago•233 comments

Ask HN: Where have all the humans gone?

2•adrianwaj•41m ago•1 comments

Kernighan on Programming

140•chrisjj•9h ago•42 comments

Ask HN: What weird or scrappy things did you do to get your first users?

4•preston-kwei•1h ago•0 comments

GitHub Actions Have "Major Outage"

48•graton•5h ago•11 comments

Ask HN: Who is firing? (February 2026)

11•chalmovsky•2h ago•0 comments

Ask HN: How do you give AI agents access without over-permissioning?

5•NBenkovich•4h ago•14 comments

GitHub Incidents with Actions and Codespaces

11•jeduardo•5h ago•3 comments

Ask HN: Has anybody moved their local community off of Facebook groups?

18•madsohm•16h ago•13 comments

Google Cloud suspended my account for 2 years, only automated replies

153•andylizf•2d ago•86 comments

Why do people still talk about AGI?

36•cermicelli•22h ago•53 comments

Ask HN: Do you still use physical calculators?

32•speedylight•2d ago•89 comments

Ask HN: Junior getting lost

49•TheRegularOne•4d ago•36 comments

Ask HN: What serious task have you accomplished with Moltbot / OpenClaw?

6•lukol•1d ago•5 comments

Ask HN: Any Successful Co-Ops of Software Engineers

13•rubyn00bie•2d ago•11 comments

Task engine VM – for tasks with executable instructions (progress update)

3•tracyspacy•1d ago•3 comments

Ask HN: Any real OpenClaw (Clawd Bot/Molt Bot) users? What's your experience?

111•cvhc•2d ago•171 comments

Ask HN: Do you also "hoard" notes/links but struggle to turn them into actions?

230•item007•3d ago•213 comments

AI has failed to replace a single software application or feature

20•cadabrabra•3d ago•23 comments

Is a RAM-only PWA "Secure Camera" safe for journalists?

2•blackknightdev•2d ago•1 comments

Ask HN: How do you reset an AppleID?

13•OhMeadhbh•3d ago•27 comments

Ask HN: How do you handle auth when AI dev agents spin up short-lived apps?

4•NBenkovich•1d ago•7 comments

A simple HTTPS, HTTP/3, SSL and security headers checker I built with AI

3•dragonman•1d ago•1 comments

Waypoint 1.1, a local-first world model for interactive simulation

13•lcastricato•3d ago•0 comments

G Lang – A lightweight interpreter written in D (2.4MB)

2•pouyathe•3d ago•1 comments

Ask HN: How do you market a side project?

14•ruairidhwm•3d ago•12 comments

Ask HN: What's the Point Anymore?

67•fnoef•6d ago•82 comments

The preposterous notion of AI automating "repetitive" work

11•cadabrabra•3d ago•10 comments

Ask HN: What's your biggest LLM cost multiplier?

7•teilom•2d ago•6 comments
Open in hackernews

Ask HN: How do you give AI agents access without over-permissioning?

5•NBenkovich•4h ago
To make AI agents more efficient, we need to build feedback loops with real systems: deployments, logs, configs, environments, dashboards.

But this is where things break down.

Most modern apps don’t have fine-grained permissions.

Concrete example: Vercel. If I want an agent to read logs or inspect env vars, I have to give it a token that also allows it to modify or delete things. There’s no clean read-only or capability-scoped access.

And this isn’t just Vercel. I see the same pattern across cloud dashboards, CI/CD systems, and SaaS APIs that were designed around trusted humans, not autonomous agents.

So the real question:

How are people actually restricting AI agents in production today?

Are you building proxy layers that enforce policy? Wrapping APIs with allowlists? Or just accepting the risk?

It feels like we’re trying to connect autonomous systems to infrastructure that was never designed for them.

Curious how others are handling this in real setups, not theory.

Comments

verdverm•4h ago
If you use a cloud like AWS, GCP, or Azure... you give it an SA and you give access with very fine grained permission controls

It's more about specific apps than modern apps and how your org puts their infra together.

I don't have your problem, I can give my agents all sorts of environments with a spectrum of access vs restrictions

NBenkovich•4h ago
Agreed on cloud IAM. AWS, GCP, and Azure handle fine-grained access well.

The problem is higher-level platforms and SaaS. Once agents need feedback from deployment, CI, logs, or config tools, permissions often collapse into “full token or nothing”. Vercel is just one example.

That’s the gap I’m pointing at.

verdverm•2h ago
Maybe the problem is your SaaS choices

I don't have problems with permissions in any of those things you listed. Do mainly k8s based infra

vitramir•2h ago
terraform cloud, argocd, vercel and supabase (modern stack for micro apps), sentry (doesn't have per project permissions), sendgrid, etc...

What does your stack look like beyond Kubernetes and AWS? It’s hard to imagine everything there supports truly fine-grained permissions.

verdverm•1h ago
Actually, almost everything stays within the private cloud, health care industry

GCP (main), AWS/Azure (b/c customers), Jenkins/Argo

TF/Helm are IaC and run from containers, no hashicorp services

CloudSQL, why are you sending your db queries to a SaaS?

LGTM for observability

The vendors we do have are WIF'd (i.e. code & secops scanning)

WIF is the key, mature vendors are supporting WIF, and amazingly the hyperscalers are supporting each others WIFs for cross-cloud, so we can give a GCP SA, AWS perms and vice versa

fsflover•4h ago
Qubes OS allows to isolate any workflow with hardware-assisted virtualization.
NBenkovich•3h ago
How can it help? Could you share more details please?
fsflover•3h ago
On Qubes, all software runs in virtual machines, isolated with strong virtualization. Anything you do in one dedicated VM has no effect on all others, so any unrelated data will not be accessible by the AI agents.
NBenkovich•3h ago
It’s great but how can it help with agent’s permissions for cloud services without fine grained tokens?
imidov•3h ago
There’s no clean read-only or capability-scoped access.-> always found that to be a no brainer backend feature, somehow most platforms misses that
NBenkovich•3h ago
Yeah, agreed. Read-only and capability-scoped access feels like a no-brainer.

Most platforms were built assuming a human behind the UI. Once you introduce AI agents, the missing permission layers start to show.

vitramir•3h ago
There’s also a related issue: many services use per-project API tokens. When agents need access to multiple projects, you have to pass several tokens at once. Which often leads to confusion and erratic behavior, including severe hallucinations.
NBenkovich•2h ago
Yeah, totally. Per-project tokens make it worse. Once you hand an agent multiple tokens, there’s no clean way to say “use this one vs that one”.
ninan980805•2h ago
I am surprised vercel doesn't have fine-grained control. Supabase for example allows developer to config IAM roles and which role has read-only or read-write access to which tables. And each IAM role comes with its own token. This way people can easily configure a set of permissions agent should have access to and give that token to agent.