Back to Insights
PentestAgentic AIMCP

Your permission model was not built for AI helpers

Cesar Adames · · 8 min read

A user is patient, slow, and forgetful, while an AI helper is none of those things.

Wiring an AI into your tools through an MCP server, an API, or a CRM connector changes the game. You are handing off critical work to a system that never sleeps and never forgets what it has seen. Most importantly, it does not respect the invisible boundaries your current rules were built around.

Most business systems were built on a quiet assumption that the human at the keyboard would only try a few things at a time. A sales rep might check some quotes, update a contact, or look up a client record. Agents are different: they try everything, they act within seconds, and they act in parallel across multiple systems. They work with perfect, instant recall of every prior action they have ever taken.

This is the core problem with rolling out new AI tools. We are not looking at brand new flaws in your software; we are looking at old flaws operating at machine speed. If your CRM lets a rep see too much data by mistake, an AI will find it instantly.

The three mistakes we keep finding

Over the last six months, we have looked deeply at how AI is used at five mid-market firms in SaaS, healthcare, and data analytics. The exact same three mistakes show up every time we check their work.

One: Giving the AI too many tools at once. When a firm sets up a new AI tool, they often give it access to everything by default. Each new AI gets the same broad MCP server and connects to every data source. Nobody stops to ask what this specific AI needs to do its job.

The result is a complete mess for your security. An AI meant to draft sales emails can suddenly read salary records it has no business touching because nobody set clear limits based on the user’s role. When your reps use an AI to speed up client renewals, they need to see contract dates, not the whole company payroll. You have to limit what the AI can see based on the job it is doing.

Two: Letting the AI return raw data. An AI answers your questions in plain English, which means whatever your background tools return becomes part of its thought process. That raw data then becomes part of the final output the user sees.

We have seen AI tools include hidden SSN data in their answers because the tool that dug up the information returned the full database record. The AI saw the extra data and saw no reason to filter it out. A rep asking for a client brief before a big call needs just the context to close the deal, not private data that breaks your rules. You must filter the data before the AI turns it into a sentence.

Three: Failing to keep a clear record of actions. When a manager asks what the AI did at 14:32 last Tuesday, the firm cannot answer. They might have a basic log of the prompt the user typed, but no clear, step-by-step record of what tools the AI used or what data came back.

Without that strict record, finding out what went wrong is just guesswork. An AI might quote the wrong price on a big deal, and your sales manager needs to see exactly where that bad number came from. You cannot fix what you cannot trace; a missing log means a missing answer.

An AI’s access level is not what your IAM policy says on paper. It is the total sum of every tool the AI can reach. It is every piece of data those tools return. It is every clever prompt that can talk the AI into using them.

What we do to fix it

A real review of an AI system looks at the hard facts to make sure your tools work safely.

  1. List every tool the AI can reach. We do not just look at the tools you want the AI to use; we look at the tools a tricky prompt could talk it into using. MCP servers often share much more data than most IT teams realize. We find those loose ends and lock them down before they cause trouble.

  2. Check the exact shape of every response. Your AI should only handle the exact type of data it needs. We build strict data checks at the boundary between your database and the AI so it cannot accidentally show a field a user is not allowed to see. If a rep asks about the sales pipeline, the system only returns pipeline data and drops everything else.

  3. Make every step easy to trace. We log every tool used, every data request, and every piece of returned data, tying this log back to a specific user and session. If you cannot trace the exact path of an AI, you cannot trust it with your business. We give you a clear record so you can see exactly what happened at any given moment.

  4. Test the AI like a hacker would. We treat the AI the way a bad actor might by feeding it tricky prompts and trying to make it break your rules. We see if we can swap roles or trick it into leaking private data. We run these hard tests to find your weak spots and fix them before they become real problems.

The only AI setup that lasts is a setup you can completely trust. You need to be able to track every move the AI makes and know it cannot step out of bounds. When you can trust your tools, your team can focus on their work without worrying about data leaks.

Next step

If this sounds like your team, we can look at it together. A free pipeline review takes thirty minutes and ends with a written list of what to fix first. Book a review.

Take the next step

Give your reps their selling hours back.

Thirty minutes on a call. You leave with a list of what comes off your reps' plates first, and a fixed quote if you want one. No deck.