What each AI system can reach, and what it should not
Agents act through identities, tools and MCP servers. Cogna8 keeps those permissions on the same record as the AI system's risk and controls, so security and governance look at one picture.
Tool and MCP permissions
What each agent can reach, and what needs a person first.
Access matrix
AllowedApproval| Agent | Payments API | Claims DB (write) | Email (external) | Policy MCP | Web search | File store |
|---|---|---|---|---|---|---|
| Claims triage agent | Approval | Allowed | No access | Allowed | No access | Allowed |
| Broker email drafter | No access | No access | Approval | Allowed | Allowed | Allowed |
| Customer reply assistant | No access | No access | Approval | Allowed | No access | No access |
| Underwriting risk summariser | No access | No access | No access | Allowed | No access | Allowed |
| Fraud signal model | No access | Allowed | No access | No access | No access | Allowed |
Findings
5 open- HighUnused write grant, Fraud signal model can write to Claims DB but has not in 30 days
- MediumPrompt injection test, Broker email drafter followed an instruction in a supplier attachment
- MediumKey rotation due, two service identities older than 90 days
- LowNew MCP server, Policy MCP added by Legal, reviewed
Security attached to the AI system, not beside it
Identities and access
Service identities and keys used by each agent, with owners and rotation dates.
Tool and MCP permissions
Which agents can reach which tools and MCP servers, and which actions need a person first.
Threats
Risks catalogued against the OWASP Top 10 for LLM applications and the MITRE ATLAS knowledge base, linked to the systems they affect.
Findings
Unused grants, prompt injection test results and overdue key rotations, each with an owner and a fix.
Least privilege, enforced at the gate
Permissions are not only listed. When an agent tries to use a tool it should not, or one that needs approval, the action gate applies the same rule at runtime.
- Permissions reviewed with the AI system owner
- Approval required for external and financial actions
- CPS 234 information security controls linked where they apply
Let's connect
Tell us where your AI programme is today. We start with a short, scoped pilot on your own AI estate, and every enquiry is handled in confidence.