What permissions should an AI agent have?

The narrowest set of permissions that lets it do the specific job you hired it for. Agents should never inherit a human's permission set, and they should never share credentials with another agent or service. Permissions are granted at the tool level, scoped to the record types and actions the agent's job actually requires, and reviewed on the same cadence as the rest of your privileged-access program.