1stProtect Research · Flagship report
State of Enterprise Agent Permissions 2026
The first industry report on what AI agents can actually do inside enterprises: credential reach, production tooling, and unapproved destinations — measured in consenting environments, published only when the numbers are real.
Inaugural edition — measurement in progress
Integrity rule
We will not invent benchmarks. Headline percentages appear here only after Audit Mode telemetry is collected, anonymized, and reviewed. Until then, the report publishes the category, the questions, and the method.
Headline findings
These are the rates that define the category. Values stay blank until 10–20 consenting enterprise environments complete the same observation window.
Measured rate
—
Pending cohort
Share of coding agents that could read developer credentials
e.g. SSH keys, cloud CLI profiles, local secret files
An attributed autonomous actor attempted to read a credential-class path or secret store during ordinary work — not a red-team exercise.
How we measureAudit Mode file-read events on SSH material, cloud provider credential files, and repo-adjacent secret files, scoped to the agent actor (not the human session).
Measured rate
—
Pending cohort
Share of agents that could invoke production tooling
e.g. kubectl, cloud CLIs, deploy or delete-class commands
An autonomous actor attempted a production-adjacent command or tool invocation with live kubeconfig, cloud identity, or deploy credentials on the host.
How we measureNormalized exec and MCP-tool events classified as production-adjacent (cluster, cloud, CI deploy) during the observation window.
Measured rate
—
Pending cohort
Share of agents that contacted unapproved destinations
e.g. unexpected hosts, outbound tools, unlisted MCP endpoints
An autonomous actor initiated network or tool egress to a destination outside the organization’s approved set for that cohort.
How we measureConnect and tool-invoke events compared to the environment’s approved destination list supplied at intake.
Industry context · Gartner
Why a permissions baseline is overdue
Gartner figures below are analyst forecasts and surveys. They describe scale, governance, and shadow AI — not the three permission rates this report will measure.
Forecast
150,000agents
Average Fortune 500 agent count by 2028, up from fewer than 15 in 2025
Gartner, AI agent sprawl, April 2026Survey
13%
Organizations that believe they have the right AI agent governance in place
Gartner, IT application leaders survey, September 2025Survey
74%
IT application leaders who see AI agents as a new attack vector
Gartner, IT application leaders survey, September 2025Survey
69%
Organizations that suspect or have evidence of prohibited public GenAI use (n=302 cybersecurity leaders, Mar–May 2025)
Gartner, Cybersecurity Innovations in AI Risk Management and Use, 2025Forecast
40%
Enterprise applications with task-specific AI agents by end of 2026, up from less than 5% in 2025
Gartner, enterprise applications forecast, August 2025Forecast
>40%
Agentic AI projects Gartner expects canceled by end of 2027 — costs, unclear value, or inadequate risk controls
Gartner, agentic AI project forecast, June 2025Forecast
>40%
Enterprises expected to face security or compliance incidents from unauthorized shadow AI by 2030
Gartner, shadow AI forecast, November 2025Forecast
15%
Day-to-day work decisions Gartner expects to be made autonomously through agentic AI by 2028
Gartner, agentic AI forecast, June 2025
Gartner also names the control work this report measures: agent identity and permissions, information-access governance, and monitoring agents that exceed intended scope. Those recommendations are not a substitute for runtime rates on real developer machines.
How the cohort is built
The instrument is the same fourteen-day AI Agent Exposure Assessment: Audit Mode on a representative developer group. Contributors keep their named report. The public edition receives only anonymized rates.
Consenting environments only
Every contributing site opts in. Operators receive their own assessment findings first. Anonymized aggregates enter the public report only with written consent.
Instrument, do not survey
Percentages come from runtime events in Audit Mode on real developer machines — not questionnaires, lab VMs, or vendor-scripted demos.
Anonymize before publish
No organization names, hostnames, repo paths, or user identities. Findings are environment-level rates and qualitative themes.
Minimum cohort before a percentage
We publish a headline rate only after 10 consented environments complete the same measurement window. Smaller N stays qualitative.
Why this report exists
The industry already has threat reports. It does not have a permissions report for autonomous actors. Security leaders are asked to approve Claude Code, Cursor, Codex, and MCP tooling without a shared, measured picture of what those agents inherit on a real laptop.
A category forms when the same three questions are asked, the same way, across enough environments that the answers can be compared. That is the work of this edition.
Supporting research
Qualitative benchmarks and checklists published while the cohort is assembled.
Call for measured environments
Help set the first industry baseline
If you will put a developer cohort on Audit Mode, you can receive your own exposure findings and — if you opt in — contribute an anonymized environment to the 2026 edition. We publish rates only when we have actually measured them.
Get your exposure report