Least Privilege

Article tag · 3 matching pages

Linux Permission Layers for AI Sandboxes

Linux can constrain an AI process through multiple independent permission layers, including UID/GID ownership, mode bits, ACLs, device access, sockets, capabilities and namespaces.

Creating Separate Accounts and Permissions for Automated Systems

A dedicated automation account lets Linux enforce what a script, worker or AI agent may read, write and control. Start with no access and add only the files, groups, devices and tokens the task proves it needs.

Why AI Agents Should Not Have Your Main Administrator Password

An AI agent should not share the administrator credential a human uses for the whole computer. Give automation a separate identity, narrow permissions and explicit elevation only where a task truly requires it.