मुख्य सामग्री पर जाएँ

SaaS AI agent सुरक्षा: tools और actions की authorization

हर tool call पर server-side authorization, least privilege, सीमित workflows, human approval, audit logs और abuse tests से SaaS AI agents को सुरक्षित रखें।

इस मार्गदर्शिका में

SaaS AI agent के tools को सुरक्षित कैसे रखें?

AI agent कई tools में से चुनाव कर सकता है और कई चरणों में actions जोड़ सकता है। हर tool call को untrusted API request मानें: server user और tenant पहचाने, उसी operation और resource की permission जांचे, arguments validate करे और परिणाम दर्ज करे। Model action का सुझाव दे सकता है; action को वैध बनाने वाला अधिकार उसे नहीं देना चाहिए।

हर tool call को असली caller की identity से authorize करें

Signed-in user या स्वीकृत service workflow का server-issued context आगे ले जाएं। हर invocation पर मौजूदा tenant membership, role, record ownership और operation permission जांचें। Model द्वारा लिखे user ID, tenant name, role claim या approval statement को अनदेखा करें। लंबा workflow रुका हो तो दोबारा जांचें, क्योंकि बीच में access बदल सकता है।

छोटे, typed tools उपलब्ध कराएं

Generic SQL, shell, browser या unrestricted HTTP capability की जगह ऐसा tool रखें जो मौजूदा customer के लिए एक सीमित काम करे। हर argument को strict schema और product rules से validate करें, unknown fields अस्वीकार करें, result size सीमित करें और resource IDs को authorized tenant तक रखें। Tool schema उपयोगी है, लेकिन tool implementation की permission checks का विकल्प नहीं।

Credentials और runtime access पर least privilege लागू करें

Agent service identity को केवल उसके enabled tools, environment और task की जरूरत की permissions दें। Provider keys और customer integration tokens secret store में रखें; model को न दिखाएं। Read और write credentials अलग रखें, expiry और destination limits तय करें, तथा एक tenant के connector credentials को दूसरे tenant में इस्तेमाल होने से रोकें।

AI agent tool authorization matrix
Tool और side effectCaller/tenant permissionCredential scopeApproval या सीमाAudit और rollback
Authorized customer record पढ़ना
Service से बाहर message भेजना
Billing या access बदलना

Agent actions और approvals को सीमित कैसे करें?

Steps, समय, data और खर्च की स्पष्ट सीमा बनाएं

हर workflow के लिए अधिकतम tool calls, execution time, पढ़े या बदले records, token budget और monetary amount तय करें। Loops और बार-बार की failures रोकें। ये सीमाएं orchestrator या tool service द्वारा code और configuration में लागू हों, सिर्फ natural-language instructions में नहीं।

प्रभावशाली operation के लिए सूचित मंजूरी लें

बाहरी communication भेजने, permissions बदलने, data delete करने, refund जारी करने या अन्य high-impact अथवा कठिनाई से पलटे जाने वाले बदलाव से पहले रुकें। Exact action, destination, प्रभावित records और महत्वपूर्ण values दिखाएं। Approval उसी payload से जोड़ें और समय-सीमा रखें; मंजूरी के बाद agent को action चुपचाप बदलने न दें।

इस बिंदु के स्रोत: LLM06:2025 Excessive AgencyOWASP Cheat Sheet: authorization

Retries सुरक्षित और actions reviewable बनाएं

External writes के लिए idempotency keys रखें, स्थिर workflow और tool-call ID दर्ज करें, और partial completion के लिए compensation या cancellation तय करें। User को initiator, agent version, requested action, approval और result का activity history दिखाएं। LLM transcript को authoritative audit record न मानें।

AI agent की authorization सीमा का परीक्षण कैसे करें?

Assistant interface के बाहर direct tool calls जांचें

हर tool endpoint को permission-विहीन user, दूसरे tenant के resource ID, forged tenant context और बदली हुई membership के साथ call करें। Model को पूरी तरह bypass करने पर भी authorization कायम रहना चाहिए। Read और write methods, batch operations, exports और administrative routes शामिल करें।

Chained और injected workflows की जांच करें

Test करें कि untrusted document, email या tool result agent को दूसरा tool चलाने, search फैलाने या private content forward करने के लिए मना तो नहीं लेता। बदले arguments पर approval replay, access revocation के समय parallel calls और timeout के बाद retries जांचें। सुनिश्चित करें कि unauthorized side effect कभी न हो।

Emergency stop रखें और tool behavior पर नजर रखें

Operators के लिए किसी tool या agent workflow को जल्दी disable करने का तरीका हो। Call volume, denied actions, retries, नए destinations और tenant के सामान्य pattern से बाहर actions पर alert दें। Provider या model change को release review में शामिल करें और जांचें कि disablement in-flight jobs पर भी लागू हो।

SaaS AI agent सुरक्षा: अक्सर पूछे जाने वाले सवाल

क्या agent अपने आप user की permissions इस्तेमाल कर सकता है?

केवल तब जब server operation को authenticated user की मौजूदा permissions से स्पष्ट रूप से बांधे और हर tool call जांचे। Prompt में user का नाम लिखने से identity या authorization साबित नहीं होती।

इस बिंदु के स्रोत: OWASP Cheat Sheet: authorizationLLM06:2025 Excessive Agency

क्या agent के हर action के लिए human approval चाहिए?

नहीं। कम जोखिम वाले और पलटे जा सकने वाले काम documented limits में automate हो सकते हैं। असर, irreversibility, बाहरी पहुंच या uncertainty अधिक हो तो approval लें और उसे exact action payload से जोड़ें।

क्या AI agent को broad database या shell access देना चाहिए?

आमतौर पर नहीं। Broad tools model की गलती या prompt injection का नुकसान बढ़ाते हैं। Independent authorization, argument validation और least-privilege credentials वाले सीमित, typed business operations इस्तेमाल करें।

Write के बाद timeout हो तो agent क्या करे?

Result को अनिश्चित मानें। Retry से पहले idempotency key या authoritative status जांचें; external side effect को अंधाधुंध दोहराएं नहीं। Partial completion दिखाएं और सुरक्षित recovery path दें।

इस बिंदु के स्रोत: LLM06:2025 Excessive AgencyOWASP Cheat Sheet: logging