Engineering Least-Privilege Agentic AI Workflows: Patterns, Anti-Patterns, and Practitioner Guidance
Rajat Khanna, Jatin Nandal
DOI: http://dx.doi.org/10.15439/2026F6361
Citation: Rajat Khanna, Jatin Nandal (2026). Engineering Least-Privilege Agentic AI Workflows: Patterns, Anti-Patterns, and Practitioner Guidance. In M. Bolanowski, M. Ganzha, M. Grzegorowski, L. Maciaszek, M. Paprzycki, A. Paszkiewicz, D. Ślęzak (eds), Proceedings of the 21st Conference on Computer Science and Intelligence Systems. ACSIS, Vol. 48, pages 93–97.
Abstract. €”Enterprise deployment of agentic AI systems is accelerating sharply --- Gartner projects that 40\% of enterprise applications will embed task-specific AI agents by the end of 2026, up from fewer than 5\% in 2025 [1]. Unlike deterministic software, AI agents execute autonomous tool-call chains, each carrying implicit privilege that classical IAM and RBAC frameworks were not designed to govern. We contribute six engineering patterns and five anti-patterns for applying least-privilege principles to production agentic workflows built on Model Context Protocol (MCP)-based tool-call architectures, grounded in enterprise deployment experience. The patterns address gateway-mediated tool access, ephemeral credential minting, scope declaration manifests, sub-agent permission ceilings, human-in-the-loop circuit breakers, and immutable audit trails, with each pattern explicitly mapped to the corresponding MCP primitives. We characterise the threat model motivating each pattern, illustrate the architecture with two technical diagrams, and catalog the anti-patterns most commonly encountered in enterprise deployments. This contribution fills a documented gap: no prior peer-reviewed work provides a practitioner-oriented engineering pattern catalog for least-privilege agentic systems.
References
- Gartner, Inc., “Gartner Predicts 40 Percent of Enterprise Apps Will Feature Task-Specific AI Agents by 2026, Up from Less Than 5 Percent in 2025,” Press release, Aug. 26, 2025. [Online]. Available: https://www.gartner.com/en/newsroom/press-releases/ 2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025
- U. Uchibeke, “Before the Tool Call: Deterministic Pre-Action Authorization for Autonomous AI Agents,” arXiv preprint https://arxiv.org/abs/2603.20953, Mar. 2026. [Online]. Available: https://arxiv.org/abs/2603.20953
- Z. Ji, D. Wu, W. Jiang, P. Ma, Z. Li, Y. Gao, S. Wang, and Y. Li, “Taming Various Privilege Escalation in LLM-Based Agent Systems: A Mandatory Access Control Framework,” arXiv preprint arXiv:2601.11893, Jan. 2026. [Online]. Available: https://arxiv.org/abs/2601.11893
- C. J. Agostino and N. D’Souza, “ALARA for Agents: Least-Privilege Context Engineering Through Portable Composable Multi-Agent Teams,” arXiv preprint arXiv:2603.20380, Mar. 2026. [Online]. Available: https: //arxiv.org/abs/2603.20380
- K. Tallam, “Authorization Propagation in Multi-Agent AI Systems: Identity Governance as Infrastructure,” arXiv preprint arXiv:2605.05440, May 2026. [Online]. Available: https://arxiv.org/abs/2605.05440
- A. Chhabra, S. Datta, S. K. Nahin, and P. Mohapatra, “Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges,” arXiv preprint arXiv:2510.23883, Oct. 2025 (v3 Apr. 2026). [Online]. Available: https://arxiv.org/abs/2510.23883
- E. Debenedetti, J. Zhang, M. Balunović, L. Beurer-Kellner, M. Fischer, and F. Tramèr, “AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents,” in Proc. 38th Conf. Neural Information Processing Systems (NeurIPS), 2024. arXiv:2406.13352. [Online]. Available: https://arxiv.org/abs/2406.13352
- A. Dehghantanha and S. Homayoun, “SoK: The Attack Surface of Agentic AI – Tools, and Autonomy,” arXiv preprint arXiv:2603.22928, Mar. 2026. [Online]. Available: https://arxiv.org/abs/2603.22928
- Anthropic, “Introducing the Model Context Protocol,” Nov. 2024. [Online]. Available: https://www.anthropic.com/news/model-context-protocol
- OWASP Foundation, “OWASP Top 10 for LLM Applications and Generative AI v1.1,” 2025. [Online]. Available: https://genai.owasp.org/ llmrisk/llm01-prompt-injection/
- European Parliament and Council of the European Union, “Regulation (EU) 2024/1689 (Artificial Intelligence Act),” Official Journal of the European Union, Jul. 2024. [Online]. Available: https://digital-strategy. ec.europa.eu/en/policies/regulatory-framework-ai
- National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, Jan. 2023. [Online]. Available: https://doi.org/10.6028/NIST.AI.100-1
- J. H. Saltzer and M. D. Schroeder, “The Protection of Information in Computer Systems,” Proc. IEEE, vol. 63, no. 9, pp. 1278–1308, Sep. 1975. https://dx.doi.org/10.1109/PROC.1975.9939
- Open Policy Agent Project (CNCF), “Open Policy Agent,” 2023. [Online]. Available: https://www.openpolicyagent.org/
- SPIFFE Project (CNCF), “SPIFFE: Secure Production Identity Framework for Everyone,” CNCF Graduated Project, Sep. 2022. [Online]. Available: https://spiffe.io/docs/latest/spiffe-about/overview/
- MITRE Corporation, “MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems,” 2025. [Online]. Available: https: //atlas.mitre.org/
- Amazon Web Services, “AWS Well-Architected Generative AI Lens — GENSEC05-BP01: Implement Least Privilege Access and Permissions Boundaries for Agentic Workflows,” 2026. [Online]. Available: https://docs.aws.amazon.com/wellarchitected/latest/ generative-ai-lens/gensec05-bp01.html