Overbroad service account
The agent used a service account that allowed updates across all customer records instead of enforcing the requesting user's permissions.
A tool-using AI agent can call APIs, update records, send messages, create tickets, trigger workflows, or complete multi-step tasks on behalf of a user.
Buyer question
Can this AI agent safely take action without exceeding permissions, bypassing approvals, or creating changes the business cannot explain?
Scenario
A company wants to deploy an AI agent that does more than answer questions. It can use tools. It may update CRM records, create service tickets, send emails, search databases, modify workflow status, summarize messages, query APIs, or automate internal tasks. This is powerful because it can reduce manual handoffs and speed up operations. It is also risky because tool access turns the AI from a conversational system into an operational actor.
Why it matters
Once an AI can act, the question changes from “Did it answer correctly?” to “What can it do, under whose authority, with what approval, and how do we prove it?” Agentic AI can create real business changes before anyone realizes something went wrong.
Risk surface
Assessment scope
Mythos projects
Athena
maps tool access, identity, permissions, service accounts, action paths, approval controls, logs, and evidence.
Achilles
tests agent behavior, tool selection, approval boundary behavior, adversarial instructions, memory misuse, and action safety.
Minotaur
may support internal-only adversarial scenarios involving malicious emails, poisoned documents, tool abuse, and chained-action tests.
Illustrative findings
Illustrative examples of what a Mythos assessment may surface. They are representative patterns, not findings from a specific customer.
The agent used a service account that allowed updates across all customer records instead of enforcing the requesting user's permissions.
The agent was instructed to ask for approval, but the backend tool executed actions without requiring a valid approval token.
The agent attempted to draft and send an external message based on instructions inside an untrusted email.
The agent combined search, summarize, and message tools to expose restricted data outside the intended workflow.
Logs showed that an action occurred but did not preserve the exact prompt, tool input, approval state, or output.
Deliverables
Decision
Whether the agent should remain read-only, operate in draft-only mode, enter limited pilot, gain selected write actions, or be blocked from production action-taking.
Recommendation
An AI agent with tools should be released in stages. Mythos should help the customer prove that the agent acts under the right identity, cannot bypass approvals, cannot chain tools into unsafe outcomes, and produces enough evidence for security, engineering, and leadership to trust the next release decision.

Mythos AI Security
Evidence-first AI deployment assurance.
Authorized. Scoped. Human-controlled.
Start the Assessment
Tell Mythos what you are building, connecting, or preparing to release. We will help identify the right assessment path.