惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
量子位
D
DataBreaches.Net
博客园 - 司徒正美
J
Java Code Geeks
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
B
Blog
The Cloudflare Blog
D
Docker
I
InfoQ
爱范儿
爱范儿
MongoDB | Blog
MongoDB | Blog
腾讯CDC
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
Vercel News
Vercel News
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
S
SegmentFault 最新的问题
GbyAI
GbyAI
有赞技术团队
有赞技术团队

Cyera Research

Agents in the Cloud: A Safer Setup When Everyone's a Developer PostGREShell: The database powering much of the internet had an open door for 12 years Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning Sandcastles, Not Sandboxes: How One Architectural Flaw Exposed Seven Products Breaking Local AI Runtimes: 10 vulnerabilities in the Engine Behind Your Open-Source Models The Hidden Attack Surface of Agentic AI: Securing AI Agent Integration Platforms The Helpful Agent Problem: When AI Good Intentions Become Security Incidents Agent-Inflicted Damage: Inside the Real-World Failures of Enterprise AI Systems Proto6: The Schema Was Not Supposed to Run Four New OpenClaw Vulnerabilities: When AI Agents Become the Attacker's Execution Layer The End of Volume-Based Severity: Rebuilding Risk Assessment with AI That File in Teams? Your Entire Organization Might Be Able to Access It The Long-Lived Risk of Malicious OAuth Applications: A Practical Threat Hunting Guide for M365 Escaping the Guest: How Custom LLM Workflows Uncovered Critical VMSVGA Vulnerabilities From Prompt to Exploit: Cyera Research Discloses Command & Prompt Injection Vulnerabilities in Gemini CLI The New Data Breach Playbook: How ShinyHunters Exploit Access The Data Taxonomy Illusion: Why Security Teams Are Solving the Wrong Problem Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama SplitSSHell - When a Comma Becomes Root How a Single Character Broke OpenSSH Certificate Authentication Compromise Once, Breach Everywhere. ‍The Age of Mega-Supply Chain Attacks Top 10 Notable Data Security Risks in AWS Environments Top 10 Data Security Risks on Microsoft 365 Environments One Megabyte to Root: How a Size Check Broke Docker’s Last Line of Defense LangDrained: 3 Paths to Your Data Through LangChain, the World’s Most Popular AI Framework Ni8mare  -  Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) When Language Becomes the Attack Vector: The Lethal Trifecta of AI Agents DESTRUCTURED - Critical Vulnerability in Unstructured.io (CVE-2025–64712) Assessing the Top Data Security Risks in AWS Environments Detection Is Fast. Understanding Is Not. Why File-Access Incidents Stall - and How Impact Clarity Changes the Outcome The OpenClaw Security Saga: How AI Adoption Outpaced Security Boundaries
96% of Enterprise Permissions Go Unused. AI Agents Won't ...
Cyera · 2026-03-27 · via Cyera Research

Cyera Research Joint Research with Oso

We analyzed 2.4 million workers and 3.6 billion permissions. What we found should change how every security team thinks about the age of autonomous AI.

This is the first empirical study of how enterprise permissions are actually exercised in production - not how they’re designed, not how policy says they should work, but what employees actually do with the access they’ve been given. The findings are unambiguous. And the implications, as AI agents enter the picture, are severe.

Infographic showing that 96 percent of enterprise cloud permissions are unused, highlighting the gap between granted access and actual usage as a primary risk for AI agent exploitation.

Finding 01

Almost no one is using their access. Almost everyone still has it.

Only 4 in 100 workers take any action at all in most enterprise applications over a 90-day period. The other 96 hold active credentials and never open the system. Among the 4% who do log in, they exercise just 17% of the permissions available to them. The other 83% sit dormant — live, functional, and waiting.

Technical diagram comparing human user access patterns with AI agent data retrieval, showing how agents can traverse thousands of unused permissions in seconds to access sensitive data.

The exposure isn’t theoretical — it’s structural. 13% of the workforce can reach  regulated data. 31% can modify or delete it. These permissions are  permanently available, whether or not anyone ever uses them.

Finding 02

Over-provisioning is baked into how enterprise systems are built.

This isn’t an accident. Across enterprise SaaS environments, more than 80% of access is managed through static permission profiles - rigid bundles configured once and expanded over time as roles grow and integrations multiply. A quarter of users have no individual permissions at all; their entire access model is a profile that was set up years ago and never trimmed.

Admin access tells the same story. Best-practice governance benchmarks set administrative access at around 2–5% of users. Some environments we analyzed had assigned admin privileges to nearly 30% — six times the expected level, with high-privilege capabilities distributed far beyond any operational need.

Security visualization of the "blast radius" or impact area for a single compromised AI agent with broad standing privileges, showing potential data exposure across SaaS and cloud environments.

Case Study: Cyera Research Deep Dive

Salesforce: where permission sprawl becomes a concrete, measurable risk

Everything  described in this post plays out in sharp relief inside Salesforce — the CRM  platform sitting at the center of most organizations’ customer data ecosystems. Cyera Research conducted a dedicated analysis of Salesforce  environments across multiple organizations and found the numbers are worse than the enterprise average. Not because Salesforce is uniquely broken, but because it is uniquely central: the permissions it holds govern access to customer records, financial data, deals, contacts, and regulated information  at scale.

Cover image for the Cyera and Oso Least Privilege Research 2026 report, titled "AI Agents and the Enterprise Permissions Crisis," featuring research on AI identity and cloud security.

Salesforce itself recommends a modular access model: minimal  profiles that define only baseline access, layered with permission sets for role-specific privileges. Production environments consistently invert this. Profile-heavy configurations make it harder to audit, harder to reduce, and much harder to reason about what any given user can actually do — let alone what an agent would do if it inherited their account.

The ‘nuclear buttons’:  View All Data and Modify All Data

Within Salesforce, two permissions override the entire sharing model. View All Data grants unrestricted read access to every record in the org. Modify All Data goes further - providing read, write, and delete access across the entire environment, effectively elevating the holder to super-admin. Cyera Research found these capabilities distributed far more  broadly than intended, in many cases persisting long after the original justification had passed. While most organizations held admin access to around 5% of users, several environments showed assignments reaching nearly 30%.

Salesforce access management isn’t a technical chore — it’s a strategic pillar of data governance. And as AI agents get connected to Salesforce environments, the governance gaps that have quietly accumulated become something far more urgent than a hygiene problem.

Are Your Salesforce Permissions Protecting You - or Exposing You?

Read the full analysis →

The first in Cyera Research’s Salesforce Access Control Deep Dive series, covering profiles, permission sets, high-privilege capabilities, record-level access, and public data exposure.

Read More →

The Inflection Point

Humans have always saved us from our own permissions. Agents won’t.

Until now, the risks above were largely theoretical. Human behavior has always acted as a natural ceiling:people work slowly, follow routines, and exercise a tiny fraction of their technical access. The 96% of permissions that go unused stay unused because people behave like people.

AI agents remove that ceiling entirely. They operate continuously, at machine speed, calling APIs directly with no natural stopping point. Theydon’t bring judgment or hesitation. When an agent inherits an employee’s permission set, it doesn’t inherit the small slice that employee typically uses. It inherits everything that employee technically could do —including the 96% that was never touched.

Comparison of human worker and AI agent permissions: human uses less than 20% of permissions, limited by time and judgment; AI agent executes hundreds of actions per second with no behavioral ceiling and can be misused via prompt injection.

Over 40,000 agent instances have been found running malicious  community-contributed integrations. An attacker doesn’t need stolen  credentials — just malicious instructions in content the agent processes. That dormant 96% becomes an active attack surface, instantly.

 "When agents are handed broad, static permissions, the unused  ones quietly expand the attack surface. What teams need are identity systems  that keep agent actions tightly scoped and tied back to human intent."

Nancy Wang  - CTO, 1Password

What to do

The window is open. It won’t stay that way.

The good news: when 96% of permissions go unused, there is massive risk reduction available without disrupting anything. Access that no one exercises can be revoked without anyone noticing. Profiles that are over-provisioned can be tightened before an agent ever touches them.

The organizations that get ahead of this treat access governance as infrastructure - not a compliance checkbox. Before any agent deployment: audit what’s actually being used. Provision dedicated agent identities scoped to the specific task, not inherited from human accounts. Start in read-only mode. Log every action from day one. Triage by blast radius - modify, delete, and export permissions first.

 "With agents, risks compound exponentially. Broader surface  area, more secrets, more over-privilege than ever before." -

Armon  Dadgar — Co-Founder & CTO, HashiCorp

Agents are moving from pilot to production now. Every day with an un-audited permission model is a day closer to that model being inherited by something that will use all of it.

Cyera Research & OSO: Full Report

2.4M  workers, 3.6B permissions, 10 actions to close the gap.

Download the complete findings

About Cyera Research

Cyera Research is the data-centric research arm of Cyera, dedicated to advancing vulnerability research and transforming real-world data insights into decisive security action. Led by a multidisciplinary team of researchers, scientists, security engineers, and security vulnerability researchers, they uncover critical vulnerabilities, emerging attack vectors, and AI-driven  risks across modern data environments. By combining hands-on vulnerability discovery with rigorous, evidence-based research, Cyera Research delivers  actionable intelligence and practical guidance that empower organizations to proactively secure, govern, and protect their data and AI assets with confidence.