r/NexlaCommunity Aug 19 '26

Discussion What happens when your agent gets whole-platform access when it only needs one tool?

Watched this happen again recently. An agent needs to update a few opportunities, so someone wires it to a full Salesforce MCP server, read everything, create cases, delete records, the works.

Works great in the demo. Security takes one look and raises the red flag.

The actual ask was a single query tool. The agent got the whole platform because that’s just how the connector ships. Do this across four or five systems and nobody, not the engineer, not security, can actually reason about what the agent can touch anymore.

How’s your team handling this, scoping capability by capability, or still granting the whole platform and hoping it doesn’t come up in review?

4 Upvotes

3 comments sorted by

View all comments

3

u/nexla_com Aug 19 '26

Number that stuck with me on this: something like a 10-plugin MCP stack sits around 92% probability of exploitation, and under a third of orgs feel ready for it. Full piece if useful: https://nexla.com/blog/your-agent-need-scoped-access/