Join our Newsletter — 33% off our NHI Course

Identity-aware Claude agents: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Claude-powered Gmail agents chain inbox reading, drafting, and sending across multiple systems, so Descope’s tutorial focuses on on-behalf-of OAuth, progressive scoping, MCP server controls, and per-message approval for sensitive actions. The security lesson is that agent capability must be constrained by runtime authorization and human intent, not broad upfront access.

Editorial analysis by NHI Mgmt Group, based on content published by Descope: “Build an Identity-Aware Claude Gmail Agent With Descope”.

Key questions

Q: How should teams prevent an AI agent from turning a read-only task into outbound action?

A: Split the workflow into separate read, draft, and send permissions, then require a fresh consent or approval step when the action crosses into external effect.

Q: Why does on-behalf-of OAuth matter for AI agent security?

A: It prevents the agent from directly holding the downstream service token, which reduces the blast radius if the agent logic is compromised.

Q: What are the signs that an agent access model is too broad?

A: A broad model usually shows up when one user request unlocks multiple downstream actions, when permissions are granted before they are needed, or when outbound actions do not require a second intent check.

Practitioner guidance

  • Define action-tiered scopes Separate read, draft, and send permissions into distinct runtime boundaries so the agent cannot inherit outbound capability from a low-risk query.
  • Keep downstream tokens server-side Use on-behalf-of token retrieval so the agent never sees Gmail OAuth credentials or any other sensitive downstream access token.
  • Add approval gates for irreversible actions Require per-action human approval before an agent sends mail, updates records, or triggers other external side effects.

Bottom line: Claude-powered Gmail agents bundle multiple operations into a single request, which makes broad standing permissions a poor fit for the risk profile of the workflow.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Scoped authorisation is the real control plane for identity-aware agents: the login event is no longer the meaningful security boundary once an AI agent can chain multiple actions inside one user request. The security question becomes which action is being authorised, for which tool, at what moment, and with what approval state. That is a runtime authorisation problem, not a static access problem. Practitioners should treat agent identity as a sequence of bounded decisions rather than a single authenticated session.

A few things that frame the scale:

  • 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
  • 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: What should organisations do when an agent can send messages on a user's behalf?

A: Treat sending as a separate risk class from reading and require explicit approval at the moment of send, not just at account sign-in. That approach reduces the chance that a misread prompt or bad draft becomes an external communication. It also gives review teams a clear accountability point for the final action.

👉 Read our full editorial: Identity-aware Claude agents still depend on scoped authorization


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.