1stProtect Research

1stProtect Research · Flagship report

State of Enterprise Agent Permissions 2026

The first industry report on what AI agents can actually do inside enterprises: credential reach, production tooling, and unapproved destinations — measured in consenting environments, published only when the numbers are real.

Inaugural edition — measurement in progress

Integrity rule

We will not invent benchmarks. Headline percentages appear here only after Audit Mode telemetry is collected, anonymized, and reviewed. Until then, the report publishes the category, the questions, and the method.

Headline findings

These are the rates that define the category. Values stay blank until 10–20 consenting enterprise environments complete the same observation window.

  • Measured rate

    Pending cohort

    Share of coding agents that could read developer credentials

    e.g. SSH keys, cloud CLI profiles, local secret files

    An attributed autonomous actor attempted to read a credential-class path or secret store during ordinary work — not a red-team exercise.

    How we measureAudit Mode file-read events on SSH material, cloud provider credential files, and repo-adjacent secret files, scoped to the agent actor (not the human session).

  • Measured rate

    Pending cohort

    Share of agents that could invoke production tooling

    e.g. kubectl, cloud CLIs, deploy or delete-class commands

    An autonomous actor attempted a production-adjacent command or tool invocation with live kubeconfig, cloud identity, or deploy credentials on the host.

    How we measureNormalized exec and MCP-tool events classified as production-adjacent (cluster, cloud, CI deploy) during the observation window.

  • Measured rate

    Pending cohort

    Share of agents that contacted unapproved destinations

    e.g. unexpected hosts, outbound tools, unlisted MCP endpoints

    An autonomous actor initiated network or tool egress to a destination outside the organization’s approved set for that cohort.

    How we measureConnect and tool-invoke events compared to the environment’s approved destination list supplied at intake.

Industry context · Gartner

Why a permissions baseline is overdue

Gartner figures below are analyst forecasts and surveys. They describe scale, governance, and shadow AI — not the three permission rates this report will measure.

Gartner also names the control work this report measures: agent identity and permissions, information-access governance, and monitoring agents that exceed intended scope. Those recommendations are not a substitute for runtime rates on real developer machines.

How the cohort is built

The instrument is the same fourteen-day AI Agent Exposure Assessment: Audit Mode on a representative developer group. Contributors keep their named report. The public edition receives only anonymized rates.

  • Consenting environments only

    Every contributing site opts in. Operators receive their own assessment findings first. Anonymized aggregates enter the public report only with written consent.

  • Instrument, do not survey

    Percentages come from runtime events in Audit Mode on real developer machines — not questionnaires, lab VMs, or vendor-scripted demos.

  • Anonymize before publish

    No organization names, hostnames, repo paths, or user identities. Findings are environment-level rates and qualitative themes.

  • Minimum cohort before a percentage

    We publish a headline rate only after 10 consented environments complete the same measurement window. Smaller N stays qualitative.

Why this report exists

The industry already has threat reports. It does not have a permissions report for autonomous actors. Security leaders are asked to approve Claude Code, Cursor, Codex, and MCP tooling without a shared, measured picture of what those agents inherit on a real laptop.

A category forms when the same three questions are asked, the same way, across enough environments that the answers can be compared. That is the work of this edition.

Supporting research

Qualitative benchmarks and checklists published while the cohort is assembled.

Call for measured environments

Help set the first industry baseline

If you will put a developer cohort on Audit Mode, you can receive your own exposure findings and — if you opt in — contribute an anonymized environment to the 2026 edition. We publish rates only when we have actually measured them.

Get your exposure report