Live
Illustration: a ring of keys where only one full-length key fits through a narrow slot.
Privacy & Security

How to Lock Down Your Accounts Before You Let an AI Agent Act for You

The pitch for an AI agent is that it stops talking and starts doing: booking the flight, clearing the inbox, filling the cart. The catch is that “doing” means acting inside your logged-in accounts — and the people who build these agents are unusually frank about the risk. OpenAI’s own security team has said that prompt injection, the attack where a malicious web page hides instructions that hijack your agent, “may never be fully solved” for browser agents. OpenAI CISO Dane Stuckey called it “a frontier, unsolved security problem.”

That is not a reason to avoid agents. It is a reason to treat them like a new contractor you just met: useful, but given the narrowest set of keys that lets them do the job, and nothing more. The security principle underneath every step below is least privilege — borrowed from decades of enterprise access control and now codified for agents in the 2026 OWASP Top 10 for Agentic Applications, whose number-three risk (ASI03, “Identity & Privilege Abuse”) is precisely agents inheriting “broad, long-lived credentials.” The labs are already counting agent incidents by the tens of thousands. Here’s how to close that gap before you flip anything on.

The criteria: delegate, don’t share; scope tight; stay revocable

Every step is judged against three tests. Delegation over credential-sharing: an agent should never hold your actual password or passkey, only a token you granted it. Minimum scope: it should be able to read what it needs and write only what you’ve approved. Revocability: you should be able to cut off access in one click without changing your own password. If an action fails all three, don’t let the agent near it yet.

Step 1: Put the agent on its own account, not your main one

The single highest-leverage move is to stop letting the agent operate as you. Create a dedicated, separate account (or a secondary profile/workspace) for agent-driven tasks, and connect only the services that specific job requires. OWASP’s guidance is blunt on why: “shared and borrowed credentials make agent actions unattributable and unrevocable.” If the agent works under its own identity, you can audit exactly what it did and kill that identity without burning down your own.

Step 2: Turn on passkeys and a hardware key — for you, not the agent

Lock your human logins behind a passkey (WebAuthn/FIDO2) or a hardware security key, and keep a second one in a drawer as backup. Here’s the elegant part, per authentication vendor Corbado: an AI agent cannot use your passkey, by design. The WebAuthn standard requires a physical user gesture — a fingerprint, face, or PIN — that a server-side agent simply can’t fake. That’s a feature. It forces the correct pattern: the passkey proves you are human and present; the agent then gets its own separate, temporary credential to act. Never paste a password into an agent that offers “just give me your login.” If a service only works by handing over your password, that service isn’t ready for an agent.

Step 3: Connect through OAuth with the narrowest scopes offered

When you connect an app or data source, you’ll usually see an OAuth consent screen listing permissions. Read it. The modern standard, OAuth 2.1, bakes in protections like mandatory PKCE and exact redirect-URI matching, but it can’t stop you from clicking “allow everything.” Security firm WorkOS recommends “scope discipline”: grant read:calendar rather than write:everything, pick read-only when the task is read-only, and decline connectors that demand far more than the task needs. If the only option is all-or-nothing access to your email or files, treat that as a hard stop for now.

Step 4: Audit and revoke what’s already connected

Before adding anything, clean house. Most people have years of dormant OAuth grants sitting in their accounts:

  • Google: myaccount.google.com → Security → “Your connections to third-party apps & services.” Remove anything you don’t recognize or no longer use.
  • Microsoft: account.microsoft.com → Privacy/Apps and services → review and revoke app access.
  • GitHub, Slack, Dropbox, X, and most SaaS apps have an equivalent “connected apps” or “authorized apps” page under settings.

Revoking a token here does not change your password — it just cuts that one app’s access, which is exactly the revocability you want. Make this a recurring calendar entry, not a one-time purge.

Step 5: Keep browser agents logged out of your high-value sites

For agentic browsers (ChatGPT Atlas, Perplexity’s Comet, and similar), OpenAI’s own recommended hierarchy is instructive. Stuckey advised using logged-out mode whenever the task doesn’t need your accounts — the agent browses “without access to your credentials.” Reserve logged-in agent actions for “well-scoped actions on very trusted sites, where the risks of prompt injection are lower.” Concretely: let an agent add items to a shopping cart; don’t turn it loose to “go read and handle my email.” Keep banking, brokerage, primary email, and health portals off-limits to agents entirely. Atlas’s “watch mode” — which pauses and requires the tab stay active on sensitive sites — is a useful backstop, but security researcher Simon Willison’s caution is fair: don’t lean on a feature you haven’t watched work.

Step 6: Demand short-lived tokens and step-up approval for anything irreversible

Favor integrations that issue short-lived access tokens (minutes, not months) and that require step-up authentication — a fresh approval from you — before high-stakes actions: money movement, deletions, data exports, sending messages on your behalf. WorkOS and Corbado both flag step-up auth as the control that matters most for “write” actions. Where the platform supports it, require explicit confirmation for purchases and set spending caps.

Step 7: Turn on the alarms and use disposable money

Finally, make the blast radius small and visible. Enable login and transaction alerts on every connected account. Where your platform exposes an agent activity log or memory view, check it periodically — OWASP’s ASI06 (“Memory & Context Poisoning”) warns that bad instructions planted in an agent’s persistent memory can activate “long after injection.” For any agent that shops, use a virtual card with a low limit or merchant lock (most major card issuers now offer them) rather than your real card number.

The recurring checklist

Pin this and re-run it monthly: separate account in use; passkey + hardware backup on your logins; connected-apps list audited; scopes read-only where possible; high-value sites logged out from agents; spending caps and virtual card in place; alerts on; activity log reviewed. None of it makes an agent bulletproof — nothing does yet. But it turns a worst-case breach from “they have my whole life” into “they had a scoped token I revoked in one click.”

Sources

// Columnist, Security & Privacy
Oman Hassan

Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.

Latest from prompt/power

  1. How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
  2. OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
  3. When an AI Agent Breaks In, Who Answers for It?Oct 5
  4. The New AI Models Don’t Talk. They Decide.Oct 5
  5. Quebec’s First AI Election: ChatGPT Leaned on an AI-Built Voter GuideOct 5

Leave a Reply

Your email address will not be published. Required fields are marked *