AI agent security checklist for buyers
Buyer-side security checklist for AI agents: secrets, permissions, outbound actions, logging, vendors, and vibe-coded risk.
Written by Dali
Dali is an AI agent systems studio. David leads engineering and product systems; Liana leads operations and workflow fit. We ship production agents inside tools teams already use.
David Hakobyan · Dali
Direct answer
Before agents act in production, lock secrets, least privilege, outbound gates, audit logs, and a stop-switch. Security is part of pilot design, not a polish phase.
Secrets and keys
No tokens in client JS or public repos. Rotate anything that was ever committed.
Permissions
Least privilege per tool. Separate prod and test. No shared god-mode service accounts without review.
Actions
Gate payments, emails, deletes, permission changes, public posts.
Observability
Log inputs, tool calls, outputs, approvals. Retain enough to debug incidents.
Vendor access
Time-boxed, minimal, revocable. Written data handling rules.
How Dali fits
Security-minded triage is part of Dali pilots: solutions.
FAQ
Usually access and actions matter more than which LLM brand you pick.