An agent should never be able to do more than the person who ran it

Service accounts are why security teams say no. Here is the permission model that gets them to yes.

run #2318
09:14:02readnetsuite.vendor#4471
09:14:03deniedworkday.salary
09:14:03flagneeds a person

This is a placeholder post. It exists so the blog shows its real layout; Rayyan replaces it, or deletes it, before launch.

The service account problem

Placeholder text for this section. The finished post will make one point here, in plain language, with the numbers or the example that backs it up.

Running as the person

Placeholder text for this section. The finished post will make one point here, in plain language, with the numbers or the example that backs it up.

More on the blog

From the research

Bring us a process your team still does by hand.

We’ll give you automated workflow agents.