Designing A Least-Privilege Capability Framework for Tool-Using AI Agents in Enterprise Software Systems: Securing Autonomous Operations through Policy-Based Authorization

Authors

  • Durga Narayana Varma Addepalli

Keywords:

Agentic AI, Least-Privilege Access Control, AI Security, Capability-Based Authorization, Enterprise AI Governance, Zero Trust, Policy-Based Authorization, Machine Learning Risk Prediction.

Abstract

The adoption of tool-using AI agents into the enterprise environment rapidly presents highly influential security issues because of the abundance of permissions and unregulated access to resources. The study suggests a Least-Privilege Capability Framework on AI Agents (LPCF-AI) in which the LLM reasoning and deterministic authorization control are decoupled and task-specific access management is achieved. Design Science Research design using machine learning in the form of risk assessment theories of Logistic Regression, Random Forest, and Gradient Boosting is used. Experimental findings indicate that LPCF-AI decreases the permissions by 76% and still is effective in its work, where the Logistic Regression has the accuracy of 0.691 and the ROC-AUC of 0.749. The framework enhances security, transparency, and governance of autonomous AI activities.

Downloads

Download data is not yet available.

References

Guan, S., Lin, F., Li, J., Wang, J. and Wang, F.Y., 2024. Parallel Financial Systems: Towards Governable and Sustainable Intelligent Financial Services. Journal of Cyber-Physical-Social Intelligence, 3(1), pp.9-9.

Zhang, X., Xu, H., Ba, Z., Wang, Z., Hong, Y., Liu, J., Qin, Z. and Ren, K., 2024. Privacyasst: Safeguarding user privacy in tool-using large language model agents. IEEE Transactions on Dependable and Secure Computing, 21(6), pp.5242-5258.

Tang, X., Jin, Q., Zhu, K., Yuan, T., Zhang, Y., Zhou, W., Qu, M., Zhao, Y., Tang, J., Zhang, Z. and Cohan, A., 2024. Prioritizing safeguarding over autonomy: Risks of llm agents for science. In ICLR 2024 Workshop on Large Language Model (LLM) Agents.

Anis, F. and Hammoudeh, M., 2024, December. Weaponizing AI in Cyberattacks A Comparative Study of AI powered Tools for Offensive Security. In Proceedings of the 8th International Conference on Future Networks & Distributed Systems (pp. 283-290).

Jaber, A. and Fritsch, L., 2022, October. Towards ai-powered cybersecurity attack modeling with simulation tools: Review of attack simulators. In International Conference on P2P, Parallel, Grid, Cloud and Internet Computing (pp. 249-257). Cham: Springer International Publishing.

Shahid, J., Muhammad, Z., Iqbal, Z., Khan, M.S., Amer, Y. and Si, W., 2022, March. Sat: Integrated multi-agent blackbox security assessment tool using machine learning. In 2022 2nd International Conference on Artificial Intelligence (ICAI) (pp. 105-111). IEEE.

Santoso, F. and Finn, A., 2023. An in-depth examination of artificial intelligence-enhanced cybersecurity in robotics, autonomous systems, and critical infrastructures. IEEE Transactions on Services Computing, 17(3), pp.1293-1310.

Hamad, M. and Steinhorst, S., 2023, November. Security challenges in autonomous systems design. In International Conference on Computational Technologies and Electronics (pp. 142-154). Cham: Springer Nature Switzerland.

Wang, J., Jiao, Z., Chen, J., Hou, X., Yang, T. and Lan, D., 2023. Blockchain-aided secure access control for UAV computing networks. IEEE Transactions on Network Science and Engineering, 11(6), pp.5267-5279.

Sadeghi, M., Sartor, L. and Rossi, M., 2022. A semantic-based access control approach for systems of systems. ACM SIGAPP Applied Computing Review, 21(4), pp.5-19.

CHERIF, A.N., YOUSSFI, M., EN-NAIMANI, Z., TADLAOUI, A., SOULAMI, M. and BOUATTANE, O., 2024. CQRS and Blockchain with Zero-Knowledge Proofs for Secure Multi-Agent Decision-Making. International Journal of Advanced Computer Science & Applications, 15(11), p.892.

Xiao, S., Ye, Y., Kanwal, N., Newe, T. and Lee, B., 2022. SoK: Context and risk aware access control for zero trust systems. Security and Communication Networks, 2022(1), p.7026779.

James, M., Newe, T., O'Shea, D. and O'Mahony, G.D., 2024, June. Authentication and authorization in zero trust IoT: A survey. In 2024 35th Irish Signals and Systems Conference (ISSC) (pp. 1-7). IEEE.

Burhan, M., Alam, H., Arsalan, A., Rehman, R.A., Anwar, M., Faheem, M. and Ashraf, M.W., 2023. A comprehensive survey on the cooperation of fog computing paradigm-based IoT applications: layered architecture, real-time security issues, and solutions. IEEE Access, 11, pp.73303-73329.

Zambare, P. and Liu, Y., 2023, October. Understanding security challenges and defending access control models for Cloud-based Internet of Things network. In IFIP International Internet of Things Conference (pp. 179-197). Cham: Springer Nature Switzerland.

Islam, M.Z. and Dhanekula, A., 2023. Measuring the Security Impact of Zero Trust Access Controls: A Mixed-Methods Study of Identity-Based Policies (Cisco ISE+ AD) and Incident Reduction. American Journal of Data Science and Analytics, 4(06), pp.01-42.

Chaisiri, A. and Boonmee, K., 2024. Authentication and Authorization Mechanisms in Secure Systems: Their Impact on Information Assurance and Access Control. Transactions on Embedded Systems, Real-Time Computing, and Applications, 14(6), pp.1-14.

Jin, Z., Xing, L., Fang, Y., Jia, Y., Yuan, B. and Liu, Q., 2022, November. P-verifier: Understanding and mitigating security risks in cloud-based IoT access policies. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (pp. 1647-1661).

Choudhary, A.R., 2023. Enhancing cybersecurity using a new dynamic approach to authentication and authorization. Issues in Information Systems, 24(2), p.22.

Dabra, M., Sharma, S., Kumar, S. and Min, H., 2024. An improved finegrained ciphertext policy based temporary keyword search on encrypted data for secure cloud storage. Scientific Reports, 14(1), p.5264.

Jangala, V.K., 2024. Authentication and authorization mechanisms in Java-based systems. International Journal of Contemporary Research in Multidisciplinary, 3(1), pp.277-284.

Vadlapatla, S., 2024. Schema-Grounded Agentic AI for Regulatory-Compliant Data Access: Bridging Natural Language and Enterprise Data Governance in Financial Services. International Journal of Research Publications in Engineering, Technology and Management (IJRPETM), 7(4), pp.10861-10868.

Meesala, L.K., 2023. A layered security framework for enterprise operations in the Generative AI and Agentic AI era in regulated cloud environments. International Journal of Future Innovative Science and Technology (IJFIST), 6(6), p.11760.

Feretzakis, G. and Verykios, V.S., 2024. Trustworthy AI: Securing sensitive data in large language models. Ai, 5(4), pp.2773-2800.

Kang, H., Liu, G., Wang, Q., Meng, L. and Liu, J., 2023. Theory and application of zero trust security: A brief survey. Entropy, 25(12), p.1595.

Jeffrey, N., Tan, Q. and Villar, J.R., 2023. A review of anomaly detection strategies to detect threats to cyber-physical systems. Electronics, 12(15), p.3283.

Sai, S., Yashvardhan, U., Chamola, V. and Sikdar, B., 2024. Generative AI for cyber security: Analyzing the potential of ChatGPT, DALL-E, and other models for enhancing the security space. IEEE access, 12, pp.53497-53516.

Ragothaman, K., Wang, Y., Rimal, B. and Lawrence, M., 2023. Access control for IoT: A survey of existing research, dynamic policies and future directions. Sensors, 23(4), p.1805.

Tariq, U., Ahmed, I., Bashir, A.K. and Shaukat, K., 2023. A critical cybersecurity analysis and future research directions for the internet of things: a comprehensive review. sensors, 23(8), p.4117.

Awan, S.M., Azad, M.A., Arshad, J., Waheed, U. and Sharif, T., 2023. A blockchain-inspired attribute-based zero-trust access control model for IoT. Information, 14(2), p.129.

Downloads

Published

30.04.2025

How to Cite

Durga Narayana Varma Addepalli. (2025). Designing A Least-Privilege Capability Framework for Tool-Using AI Agents in Enterprise Software Systems: Securing Autonomous Operations through Policy-Based Authorization. International Journal of Intelligent Systems and Applications in Engineering, 13(1s), 497 –. Retrieved from https://www.ijisae.org/index.php/IJISAE/article/view/8546

Issue

Section

Research Article