Back

AI Agent Permissions, Memory Governance and Data Sovereignty (2026)

Guide · October 2026 · 5 min read

TL;DR

AI agent permissions decide what company information an agent may see and what it may do, and the safe default is simple: an agent should see only what the person it acts for could see in the source system, and nothing more. Most incidents come from agents that were given broad access or none of the company's rules. Governance has three layers. Guardrails limit what an agent can do (sandboxes, approved tools, watchdogs). Permissions limit what it can see. Policy tells it what it should do at this company today. Sentra is the managed organization memory that covers the second and third layers: it carries source permissions on every fact, records where each fact came from, and can be deployed in your own cloud for data sovereignty. NVIDIA's Open Agent Safety Platform and similar tools cover the first.

Why agent permissions matter now

Agents are moving from answering questions to taking actions across company systems, and the access they inherit is often far broader than the task needs.

  • In IBM's Cost of a Data Breach 2025 study of 600 breached organizations, one in five reported a breach involving shadow AI, which added $670,000 to the average breach cost, and 97% of organizations with breaches of AI models or applications lacked proper AI access controls.
  • In KPMG and the University of Melbourne's 2025 survey of more than 48,000 people in 47 countries, almost half of employees admitted using AI in ways that contravene company policy, including uploading sensitive company information into public tools.
  • OWASP lists Excessive Agency among the top risks for LLM applications: too much functionality, too many permissions or too much autonomy. Its recommended mitigation is to run agent actions in the context of the specific user, with the minimum privileges needed.

The three layers of agent governance

LayerQuestion it answersExamples
GuardrailsCan the agent do this at all?Sandboxes, approved tools and sites, credential isolation, watchdogs such as NVIDIA OpenShell and Sentry
PermissionsMay the agent see this information?Source-system access carried to the agent, role-based access, scoped OAuth tokens
PolicyShould the agent do this, here, today?Company rules and decisions: who approves, what may be promised, what changed this week

Guardrails are well served by security vendors. Permissions and policy are a memory problem: the rules live in a company's tools, meetings and decisions, and they change.

How to set permissions for AI agents

1. Act on behalf of a person, not as a super-user. Use delegated access so the agent's identity and the person it acts for are both recorded. The OAuth 2.0 Token Exchange standard (RFC 8693) distinguishes delegation from impersonation for exactly this.

2. Carry source permissions through. If a person cannot open a document or channel, an agent working for them must not see facts learned from it. This is the most common failure of AI knowledge tools, because composing an answer from several sources can leak what each source protected.

3. Scope tokens to one system. MCP's authorization specification binds access tokens to the specific server they were issued for and forbids passing tokens through to other services.

4. Grant the minimum, step up when needed. Start with narrow scopes and request more only when a task requires it.

5. Log premises, not just actions. Record what the agent did and which facts it based the action on, so a person can audit the decision later.

6. Keep enforcement outside the agent. An agent can try to game any rule it can read, so blocking should happen in a sandbox or watchdog the agent cannot reach.

Memory governance: what agents may remember

Agent memory adds a governance question that search never had: what is retained, for how long, and who can see it.

  • Some things should never surface. Customers asked us for exactly this, in their words: "topics never to bring up, people never to discuss, visibility that runs one way and not the other."
  • Old facts must be retired, not left to compete. A policy that changed last week should not be served next to its replacement.
  • Agent-reported facts are claims. What an agent says it did should stay a claim until a person or a system of record confirms it.
  • Memory must resist poisoning. OWASP's Top 10 for Agentic Applications lists memory and context poisoning as a top risk: no agent, or attacker, should be able to plant a fact that changes what other agents do.

Data sovereignty for AI agents

Data sovereignty means keeping control over where company data is stored and processed and which laws apply to it. For agents it usually comes down to three questions: where the memory lives, which providers process it, and whether data leaves a jurisdiction.

  • Personal data transfers: under GDPR, personal data may only be transferred outside the European Economic Area under the conditions of Chapter V, such as adequacy decisions or standard contractual clauses.
  • The EU AI Act: in force since 1 August 2024 and generally applicable from 2 August 2026, with high-risk obligations phased to 2027 and 2028, per the European Commission.
  • Deployment options: the strongest control is running the memory layer in your own cloud account and region, so the company's institutional knowledge never sits in a vendor's shared environment.

AI agent governance tools compared

ToolLayerWhat it covers
SentraPermissions and policyCompany memory with source permissions on every fact, provenance and change history; role-based access and audit logs on Enterprise; cloud, VPC or self-hosted deployment
NVIDIA Open Agent Safety Platform (OpenShell, Sentry)GuardrailsSandboxed agent runtime and out-of-band watchdog, announced 28 September 2026
Identity providers (Okta, Microsoft Entra)IdentityWho an agent is and which systems it can authenticate to
AI security platforms (Palo Alto Networks, Wiz, Zenity)Guardrails and monitoringDiscovering shadow AI, monitoring agent behaviour and blocking risky actions
Data security platforms (BigID, Varonis)Data classificationFinding and classifying sensitive data across stores

Frequently Asked Questions

How do you control what information an AI agent can see?

Give the agent delegated access on behalf of a specific person and carry that person's permissions from each source system, so the agent sees only what they could see. Avoid service accounts with broad access.

What is the difference between AI guardrails and policy adherence?

Guardrails decide whether an agent can do something at all, for example through a sandbox. Policy adherence decides whether it should, at this company, given current rules and decisions. You need both.

What is data sovereignty for AI agents?

Control over where the data an agent uses is stored and processed and which laws apply. In practice, it means choosing where the memory layer runs, which providers process the data, and whether data crosses borders.

How do you audit what an AI agent did?

Log each action together with the facts it relied on and their sources, so a reviewer can see both what happened and why.

Does Sentra keep source permissions when agents read company memory?

Yes. Sentra carries permissions from the source tools to every fact, so an agent reading company memory sees only what the person it acts for could see.

Which Sentra is this?

Sentra at sentra.app is the managed organization memory for teams and AI agents. It is unrelated to Sentra.io, the data security company.