Watchlight AI
Back to Blog
Agent Runtime GovernanceAuthority Blast RadiusLeast PrivilegeAI Agent SecurityCISO

Your AI Agents Hold Authority They Never Use. Now You Can See It.

Aldo PietropaoloSeptember 29, 20266 min read
Share

When people change jobs, their old access usually stays behind. That is why companies run access reviews: nobody trusts the list of who can do what.

AI agents have the same problem, only faster. An agent can be set up in minutes, and it is often given more access than it needs, "just in case." Then it works on its own, around the clock, and nobody checks which of its permissions it actually uses.

In an incident, a security leader asks one question above all: "If someone took over this agent, how much damage could they do?" Today, the honest answer is usually a guess.

It doesn't have to be. Our new 30-second recording shows how Watchlight AI Beacon answers that question for any agent, with evidence. Watch the authority blast radius demo.

Every agent gets a risk rating, with the reasons shown

In May we introduced Authority Blast Radius. Beacon rates every agent by how much damage it could do if an attacker took control of it. There are four ratings, from Constrained (the lowest risk) to Custodial (the highest).

The rating is based on simple facts about the agent that anyone on the security team can check:

  • Can it change data?
  • Can it hand work to other agents?
  • Can it act without a person approving?
  • Can it reach the internet, financial systems, personal data, or anything that deletes or destroys?

The team can see every one of these facts and challenge any of them. The exact score behind the rating stays private, so nobody can tune their agent to game it.

The demo opens on a research agent rated Constrained, with all the facts behind the rating shown underneath.

The map: what the agent uses, and what it doesn't

What's new is the blast radius map. For one agent, it shows who gave the agent its access and every tool the agent can touch, sorted into three groups:

  • Given and used. Access the agent needs to do its job.
  • Given but never used. Access the agent has but has never needed.
  • Never given, but reached. Tools the agent got to anyway, plus every attempt that was blocked.

In the recording, the agent was given two tools and used only one. Half of its access was sitting idle.

That idle access matters. It does nothing for the business, but if an attacker takes over the agent, the attacker gets it. So it is pure risk. Beacon turns it into a clear to-do list: access you can remove, based on what the agent really did, not on what someone guessed it might need.

What the agent reached that it was never given

The map also shows where the agent went beyond the access it was given. In the demo, it reached three tools that were never on its list, and three of its attempts to use one of them were blocked.

The blocked attempts are good news: the agent tried, and the controls stopped it.

The other tools deserve a look. The agent could reach them because a company policy allowed it, even though the application never listed them as tools it uses. Usually that is something like an AI model service that someone approved in a policy but never recorded against the application. It does not mean the agent was hacked. It does mean the agent can do more than its own description says, and that kind of quiet gap is how access creeps up over time.

What this means for security and business leaders

  • Access reviews with real evidence. Instead of asking an agent's owner, "Does it still need all this access?", you can show them exactly which access it has never used.
  • Faster answers in an incident. If an agent might be compromised, the map shows what it could reach and what it actually touched.
  • Proof for auditors. The rating, the facts behind it, and the map show how each agent's access was decided and why.

Four questions to ask about your own agents

  1. For each agent you run, can you see which of its access it has never used?
  2. Can you rank your agents by how much damage each could do if taken over, and explain why?
  3. Would you know if an agent reached a tool it was never given?
  4. Can the people who own an agent challenge its risk rating, without being able to game it?

If the answers come from a spreadsheet or a quarterly review, you are guessing.

See it for yourself

Watch the 30-second authority blast radius demo to see a real agent rated and mapped.

Then bring your own agents. Request a demo and see Watchlight AI Beacon show what each of your agents can reach, what it actually uses, and what you can safely take away: watchlight.ai/demo

Subscribe to Watchlight Insights

Get new writing on Agent Runtime Governance, AI agent security, agent identity, and delegated authorization, delivered when we publish. No noise, just the new posts.

Unsubscribe anytime. We never share your email.

Found this useful? Share it with your network.
Watchlight AI Beacon

Put runtime governance in front of every agent action

Watchlight AI Beacon is available now, fully on-premises and air-gapped. Request a demo to see it in your environment.

Request a Demo
Recommended Workshop

Agent Governance Readiness Assessment

Evaluate your governance posture against the 12 principles. Get a maturity score and roadmap.

2-3 days · Download one-pager (PDF)

We value your privacy

We use cookies for analytics and to remember your preferences. Learn more ·