Scoped access means an AI agent is granted only the specific, named permissions it needs for a task, such as "read loyalty balance" or "initiate a refund," rather than broad or standing access to an account. Narrow, well-described scopes let a customer make an informed decision about what they are authorizing and limit the damage if an agent's credentials are ever misused.
Frequently asked questions
What happens if an agent's credentials are stolen?
Because access is scoped narrowly, an attacker can only perform the specific actions the agent was granted, not everything the customer's account can do.
Who decides what scopes an agent can request?
The business defines which scopes exist and are available to a given agent type; the customer decides which of those to actually approve.
.avif)