This paper proposes dynamic least-privilege control for enterprise AI agents. Its three-source architecture combines role-based permission ceilings, a task-context classifier, and policy-derived prohibitions on risky permission combinations. The authors release a synthetic dataset of 600 enterprise task prompts labeled across a 15-permission tool taxonomy, together with an environment specification and generation pipeline. In a 60-record, 688-decision human-reviewed sample, Cohen’s kappa was 0.917 before review and 0.967 after review. Iterating between prompt generation and policy refinement reduced ceiling violations from 46 to 3, a reported 93% reduction.
No heat snapshots are available in the last 24 hours.