The control boundary collapses. If the same session can both inspect and mutate identity infrastructure, the agent can turn ordinary exploration into administrative change without a meaningful checkpoint. That creates a larger blast radius, weaker accountability, and harder incident reconstruction because intent, approval, and execution all sit in one place.
Where the boundary collapses
The failure is not just broader access, it is loss of separation between seeing and changing. Read-only discovery is supposed to let an AI agent inspect identity state, dependencies, and policy without becoming a control plane actor. Once the same session can also write, every observation becomes a possible trigger for mutation, which is why AI Agent Authorisation Guide treats task-scoped access and per-action approval as distinct controls.
That separation matters because discovery usually touches the same objects that administration changes, such as roles, grants, tokens, approvals, and ownership records. If the agent can both read and write those records in one trust context, there is no meaningful checkpoint between assessment and execution, and the control boundary becomes procedural rather than technical.
How mixed read-write access changes the security model
With separate read-only and write paths, a discovery workflow can enumerate state, propose a change, and hand off to a distinct approval or enforcement step. With mixed access, the agent can turn a diagnostic action into an administrative one without a fresh decision point. That undermines least privilege, weakens accountability, and makes it harder to prove whether a change was intended, tested, or simply the by-product of exploration.
This is especially important for identity infrastructure because discovery often reveals high-value routes, stale credentials, overbroad grants, and cross-environment relationships. A session that can inspect and mutate the same substrate can create changes that are hard to unwind, because the system may only show the final mutated state, not the original investigative intent.
For agentic systems, the practical design rule is to keep discovery tools on a separate authority path from state-changing tools. The difference is not cosmetic. It changes whether the agent is observing the environment or exercising delegated power over it, and that distinction is central to Zero Trust for AI Agents and MCP Security Guide, both of which emphasise policy checks and token handling that do not assume every tool call deserves the same trust.
Why incident reconstruction gets harder
When inspection and mutation share one session, logs tell you that the agent acted, but not cleanly whether it was still in discovery mode or had crossed into administrative action. That blurs event classification, reduces evidentiary value, and complicates rollback because the sequence no longer shows a clean handoff from observe to change. The result is weaker attribution for operators and a larger ambiguity window for responders.
The operational consequence is that even a benign mistake can resemble an authorised change, while a malicious or compromised agent can hide harmful actions inside normal exploration. A control boundary that is not enforced in tooling, policy, and audit leaves incident teams trying to reconstruct intent from outcomes alone, which is the least reliable way to diagnose agent behaviour.
Risk and Threat Considerations
Mixed read-write access creates a single compromise path from observation to mutation. If the agent is tricked, mis-scoped, or hijacked, the same trust path that discovers sensitive identity state can also modify it, turning reconnaissance into privilege abuse, destructive change, or silent persistence.
Failure mechanism: The agent uses one authenticated context for both discovery and admin actions, so a prompt, tool, or policy failure can immediately convert read-only insight into writeable control over identity records, credentials, or approvals.
Impact: Blast radius expands, because one session can enumerate targets, alter permissions, and obscure attribution in the same workflow. That raises the chance of overprivilege abuse, unauthorized change, and slower containment during incident response.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Mixed read-write agent access enables unauthorized privilege use and state change. |
| Recommendation — Separate read-only discovery from write-capable actions and require step-up approval for mutations. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The issue is overbroad authority that lets discovery become mutation. |
| AU-2 — Event Logging | Clear reconstruction depends on audit records that distinguish discovery from change. | |
| IA-5 — Authenticator Management | Shared sessions and token handling determine whether read and write paths stay separated. | |
| Recommendation — Limit each agent session to the minimum privileges needed for its current task. Log tool use and state changes with enough detail to separate observation from administration. Use distinct credentials or tokens for discovery and mutation and rotate them promptly. | ||
| NIST Zero Trust (SP 800-207) | SC-3 — Security Boundaries | The core failure is collapse of the boundary between observe-only and change-capable access. |
| Recommendation — Enforce separate trust boundaries for discovery tools and administrative tools. | ||
Practitioner Guidance
What to prioritise: Separate discovery from mutation at the authorization layer first, not just in UI labels or runbooks. If a tool can change identity state, treat it as a different capability with its own policy, approval path, and audit trail.
What to verify: Confirm that read-only sessions cannot call write-capable endpoints indirectly through shared tokens, delegated scopes, or fallback code paths. A good test is whether the agent can complete full discovery without ever holding the authority needed to act on what it finds.
Decision rule: If the same session can inspect and mutate identity infrastructure, assume the control boundary has failed and redesign before expanding the agent’s scope. If discovery and write operations must coexist, force a separate step-up decision for every change, not a standing permission to do both.
Practitioner takeaway: The safest model is not “trusted agent with careful prompts”, it is “observable discovery plus separately governed change”. Once those are fused, accountability, containment, and rollback all get worse at the same time.