# Over-Broad Tools, Permissions and Autonomy — LLM Application Security

Source: https://www.geekswithgeeks.com/en/llm-security/a-scope

> Recognise the three kinds of excess and how to trim them.

## Too much functionality, permission or autonomy

Excessive agency has three forms. **Excess functionality**: the tool can do more than the task needs (a "manage mailbox" tool where "read subject lines" would do; a generic "run SQL" tool). **Excess permissions**: the tool's credentials are broader than needed (an admin database login for a read-only lookup; one shared API key for every user). **Excess autonomy**: the assistant takes high-impact actions with no human check. Fixes: expose **narrow, purpose-built tools** with validated arguments; give each tool the **minimum credentials**, ideally scoped to the **current user** rather than a super-account; remove tools that are not used; and apply **approval gates** for anything irreversible, costly, external or security-relevant. Review the tool list like you review firewall rules: every entry needs a reason.

## Power should be earned, narrow and approved

The more an assistant can do, the more a successful attack can do; give tools narrowly, authorise per user, and approve risky actions.

![Four controls: scope, policy, approval, audit.](assets/figures/llm-security/section-4-map.svg) — Figure 4.1 — Scope, policy, approval and audit.

## Trimming a tool set

Before and after for a customer-support assistant.

```text
BEFORE (excessive)                      AFTER (narrow)
run_sql(query)  -- any SQL, admin login   get_order(order_id) -- one fixed query, read-only account, current user only
send_email(to, body) -- any recipient     draft_reply(order_id) -- returns text; a human clicks Send
file_tool(path) -- whole disk             (removed; not needed for support)
refund(order, amount) -- no limit         propose_refund(order, amount<=5000) -- queued for human approval
autonomy: acts immediately                autonomy: reads freely; every write needs approval
```

## Review tools like firewall rules

Every tool should have a written reason to exist and an owner.

**Quiz:** Which is an example of excess permissions?

- [ ] A human approval step
- [ ] A tool that reads one order for the current user
- [ ] A tool with a clear schema
- [x] An admin database login used for a read-only lookup

*Answer:* An admin database login used for a read-only lookup. Credentials broader than the task widen the blast radius.
