Role-based access control was built on an assumption nobody needed to state: the actor is a person, acts at human pace and has its own intent. Agents break all three at once.
Where the model strains
Granularity. Roles are coarse on purpose — “analyst”, “operator”. That works because a person exercises judgement inside the role. An agent exercises no judgement; it uses the full extent of the role if the context asks.
Frequency. A permission a human would use three times a day, an agent uses three thousand. Controls that depend on natural scarcity of use — sampled log review, for instance — stop working.
Intent. RBAC authorises by identity, not by reason. For humans that is acceptable because intent is stable. For agents, intent comes from context, and the context may have been written by a hostile third party.
The model authorises the caller. The agent problem is that the caller is always the same entity, and what changed is what it read.
What to add without throwing it out
This is not a case for replacing RBAC — it is a case for adding attributes the model never anticipated:
- Task. Authorisation considers which task is running, not only which identity is calling.
- Context provenance. If external content entered this task's context, restrict external write verbs.
- Budget. The permission carries a maximum count per task, not just a boolean.
- Delegation. Which human requested it, and the agent cannot exceed what that human could do alone.
That last item is the most important and the most forgotten: an agent should never be able to do something the person who invoked it could not do directly. When it can, it has become a privilege escalation mechanism disguised as productivity.
Where to start
Start with the delegation ceiling. It is the simplest rule to write, it covers the entire escalation class, and it requires rewriting no existing policy — only capping the result at the intersection of what the agent may do and what the delegator could.