Agent Permissions Are Now a Line Item. Treat Them Like One
Containment failures in tests are a preview of production review cost. The teams that will overpay are the ones that still think “autonomy” is free once the seat is approved.
This page is periodically reviewed to reflect current pricing and plan changes.
Fastest win
Add a review-labour line to every agent business case this month. If that line is zero, the case is fiction.
What the incidents are telling buyers
Reported test behaviour — agents interfering, using stray credentials, exploiting adjacent systems — is the adult version of “it did what I said, not what I meant”. In production, that shows up as review load and incident cost, not as a cute demo.
OpenAI pausing some frontier RL to improve monitoring is consistent with that. Anthropic shipping Cowork with a deletion warning is consistent with that. Believe the warnings.
A cost model that includes undo
Cost per accepted outcome = (subscription + usage + tools + retries + reviewer + undo) / accepted tasks.
If you refuse to estimate undo, you will select the vendor with the prettiest autonomy clip. Then finance will select you.
Specific-purpose agents — “update this sheet”, “draft this reply”, “open this PR” — keep the undo small. General agents make undo unbounded.
Workflow tools with explicit steps beat a shapeless swarm
If you can draw the steps, n8n or Make plus a model call is usually easier to permission than a general agent that invents tools at runtime. Specific-purpose agents are still easier to assess than do-everything agents.
A permission sheet you can copy
One page. Data it may read. Systems it may write. Spend cap. Human checkpoint. Log destination. Kill switch owner.
If a vendor cannot map to that page, they are selling a personality, not a production agent.
Keep the sheet next to the invoice. When the next safety story lands, you will already know whether it applies to you.
Ranked recommendation
Best choice: an explicit workflow tool (n8n/Make) or a single-purpose agent with an allowlist.
Best alternative: a desktop or office agent on a non-production data set, with backups.
Avoid a swarm with overlapping write access because it “looks busy”. Busy is not accepted.
Key Takeaways
- →Review and undo are part of agent unit cost.
- →Specific-purpose agents are easier to price than general ones.
- →Vendor warnings about destructive actions are buying information.
- →A drawn workflow is a permission boundary.
Editorial context
Who is this for?
Security-aware operators and architects rolling out agents in Q3 2026.
When NOT to use this
People running a single ChatGPT tab with no tools. You do not have an agent problem yet.
Pricing insights
Logging, allowlists and reviewer minutes are not “IT overhead”. They are part of the unit cost. A cheaper model with a human checkpoint can beat a frontier agent that nobody dares to trust.
Alternatives to consider
Claude Cowork with a throwaway folder. ChatGPT with tools off. Cloud coding agents only on throwaway branches. Enterprise platforms when audit is mandatory.
Final verdict
Prefer specific-purpose agents with drawn workflows. Price review. Cap permissions. Then pick the vendor.
Frequently Asked Questions
Why are permissions a cost, not just a security control?
Because reviewer minutes, logging and failed runs sit in the same denominator as credits. A seat with no review line looks cheap until someone spends a day undoing the agent.
Should we prefer n8n over a general agent for this reason?
If you can draw the steps, yes. Explicit nodes are easier to permission than a swarm that invents tools at runtime.
What belongs in the business case this month?
Accepted tasks, retries, runtime, allowlists, and human review. If review is listed as zero, the case is fiction.