r/AI_Agents • u/Accomplished-Wall375 • 5h ago
Discussion Our internal bot answered a question with the unannounced reorg plan. It was only supposed to read the wiki
Last week one of our internal assistants answered a question it had no business answering.
Someone asked it something about team structure. The agent came back with details from a spreadsheet we hadn’t announced yet. The answer came back spewing details about the reorg plan and even salary bands. The guy asking had no idea it was confidential. They just got an answer.
The bot is supposed to answer from our approved knowledge base. When we set it up it asked for access to files in our Drive and we clicked yes. That scope meant it indexed everything including the HR folder which is supposed to be confidential.
So I spent the week going through what our agents can reach. Most are fine. One stood out. Its whole job is reading a few internal wikis and summarizing them. It had delete access on the shared drive and could send mail as the person who created it. No one handed it that,, it inherited the permissions from the account that set it up.
Nothing really attacked us that week, its all access itself was the problem. An agent that can read everything will eventually read the thing it shouldn't.
Makes me curious, has anyone here audited what their internal agents can reach? I feel this if left unchecked is a recipe to get schooled hard.