Back to Blog
Announcing State of Enterprise Agent Permissions 2026

Announcing State of Enterprise Agent Permissions 2026

A flagship report on what enterprise AI agents can actually do — credential reach, production tooling, and unapproved destinations — published only from measured, consented environments.

The 1stProtect Team Sep 13, 2026 5 min read

Announcing State of Enterprise Agent Permissions 2026

The industry already has threat reports. It does not have a permissions report for autonomous actors.

Security leaders are being asked to approve Claude Code, Cursor, Codex, and MCP tooling without a shared, measured picture of what those agents inherit on a real laptop. We are building that picture.

Read the flagship report — methodology live, headline rates withheld until they are measured.

What we will publish

When a cohort of 10–20 consenting environments completes the same Audit Mode window, the public edition will answer three questions:

  1. What share of coding agents could read developer credentials?
  2. What share could invoke production tooling?
  3. What share contacted unapproved destinations?

Those are the rates that define the category. We will not fill them in from a lab, a survey, or a guess.

How environments are instrumented

The instrument is the AI Agent Exposure Assessment: fourteen days of Audit Mode on a representative developer group. Contributors receive their own named findings first. Anonymized aggregates enter the public report only with written consent — no organization names, hostnames, or identifying paths.

Why we are publishing the empty boxes

A category report that invents percentages trains the market to distrust the category. The inaugural edition therefore ships the questions and the method now, and the numbers when the cohort exists.

If you will put a developer cohort on Audit Mode, you can help set the first industry baseline.


Flagship report: /research/state-of-enterprise-agent-permissions-2026

Contribute: /offers/ai-agent-exposure-assessment