Blank white background with no objects or features visible.

نقدم لكم وصولاً مجانياً إلى تقرير Gartner Hype Cycle الكامل حول حوكمة الذكاء الاصطناعي لعام 2026. احصل على نسختك →

التحكم في وصول وكلاء الذكاء الاصطناعي: أقل الصلاحيات لكل وكيل

By أشيش دوبي

Published: October 6, 202616

⚡ TL;DR

AI agent access control decides whether a call is allowed to happen at all: which agents, users, and teams can reach which models, MCP servers, and individual tools. It is a separate job from guardrails, which inspect what a call contains. On TrueFoundry, access is enforced at the gateway through role-based collaborators at the resource level and roles at the tenant level, so you can scope every agent to least privilege without writing authorization logic into agent code.

Agents make access control harder for one simple reason. A single person can drive dozens of agents, and each agent can call many tools, so the old model of "this user can use this app" no longer describes what is actually happening. A support copilot that only needs to read tickets should never be able to run a refund, even when the person behind it could. Getting that right means scoping the agent, not just the human.

This guide covers what AI agent access control is, how it differs from guardrails, and how TrueFoundry enforces least-privilege across models and MCP tools from one control plane. It pairs closely with AI agent identity, which establishes who is calling in the first place.

ما هو التحكم في وصول وكلاء الذكاء الاصطناعي؟

التحكم في وصول وكلاء الذكاء الاصطناعي هو مجموعة من السياسات التي تقرر ما إذا كان بإمكان جهة اتصال معينة الوصول إلى مورد معين. إنه يجيب على سؤال "هل هذا مسموح به؟"، بينما تجيب حواجز الحماية على سؤال "ما الذي يحتويه هذا؟".

هذا التمييز يستحق الاهتمام، لأن كلا نوعي التحكم يفشلان بطرق مختلفة، لذا فأنت بحاجة إلى كليهما.

  • التحكم في الوصول هو بمثابة حارس البوابة. فهو يتحقق مما إذا كان هذا الوكيل أو المستخدم أو الفريق مسموحاً له أصلاً باستدعاء هذا النموذج أو أداة MCP هذه.
  • حواجز الحماية هي بمثابة جهاز الكشف عن المعادن. بمجرد السماح بالاستدعاء، تقوم هذه الحواجز بفحص المطالبة (Prompt) والمخرجات ووسائط الأداة بحثاً عن أي عمليات حقن، أو بيانات شخصية (PII)، أو أسرار، أو عمليات غير آمنة.

يمكن أن يكون الوكيل مخولاً بالكامل لاستدعاء خادم MCP الخاص بقاعدة بياناتك، ومع ذلك يتم خداعه لإرسال استعلام تدميري. لقد وافق التحكم في الوصول على الخادم، ولا يمكن إلا لحاجز الحماية على الوسائط اكتشاف ما يفعله الاستعلام فعلياً. إذا قمت بتوسيع نطاق الوصول بشكل مفرط، فأنت تعتمد كلياً على جهاز الكشف عن المعادن. مبدأ الصلاحيات الأقل هو ما يحافظ على الحد الأدنى من الاستدعاءات المسموح بها في المقام الأول.

مستويان للتحكم في الوصول في TrueFoundry

تطبق TrueFoundry التحكم في الوصول على مستويين، وفهم هذا التقسيم هو الجزء الأكبر من العمل.

الأدوار على مستوى المورد (المتعاونون)

يمكنك إضافة مستخدم أو فريق أو حساب افتراضي كمتعاون مباشرة على مورد ما، واختيار دور يحدد نطاق وصولهم إلى ذلك المورد فقط. الأدوار خاصة بنوع المورد:

Resource Roles
Model Account / Provider Account Manager, User
MCP Server MCP Server Manager, MCP Server User, MCP Server Approver
Agent Agent Manager, Agent Access
Workspace Workspace Admin, Member, Viewer
Secret Group Admin, Editor, Viewer, Access

هنا يكمن جوهر مبدأ الصلاحيات الأقل. امنح الوكيل "وصول الوكيل" (Agent Access) فقط لخوادم MCP التي يحتاجها لعمله، واجعل الفريق "مستخدماً" (User) على حساب النموذج الذي يُسمح له باستدعائه، وأضف "موافقاً على خادم MCP" (MCP Server Approver) عندما تتطلب الأداة موافقة قبل تشغيلها. لا حاجة لإنشاء أدوار مخصصة لأي من ذلك.

الأدوار على مستوى المستأجر

تطبق الأدوار على مستوى المستأجر عبر المستأجر بأكمله ويتم تكوينها ضمن "الوصول" (Access)، ثم "الأدوار" (Roles). وهي تحكم الإجراءات على مستوى المستأجر مثل إنشاء الموارد، وإدارة المستخدمين، وإدراج كل مورد من نوع معين. توفر TrueFoundry دورين افتراضيين: المسؤول (Admin)، والذي يتمتع بالتحكم الكامل ويجب أن يقتصر على عدد قليل من الأشخاص، و العضو (Member)، والتي لا تملك افتراضياً صلاحية الوصول إلى أي شيء، ويجب منحها صلاحية الوصول إلى الموارد بشكل صريح. وعندما تكون هاتان الصلاحيتان واسعتين جداً أو ضيقتين جداً، يمكنك إنشاء دور مخصص.

‍

Permissions available when creating a custom tenant-level role in TrueFoundry

 

لقطة شاشة للمنتج، وثائق TrueFoundry: أذونات الأدوار المخصصة.

‍

يمكن تعيين الأدوار للفرق وكذلك للمستخدمين الأفراد، وتكون الأذونات الفعلية للمستخدم هي مجموع أذونات دوره الخاص وجميع الأدوار الموروثة من فرقه. بالنسبة للمؤسسات التي تقوم بمزامنة مجموعات الهوية عبر بروتوكول SCIM، يتم استيراد هذه المجموعات كفرق في TrueFoundry ويمكن منحها أدواراً مباشرة، بحيث يتبع الوصول نفس مصدر الحقيقة الذي يديره مزود الهوية (IdP) الخاص بك بالفعل.

كيف يعمل التحكم في الوصول لأدوات MCP

تفصل بوابة MCP بين ثلاثة جوانب غالباً ما تتداخل مع بعضها البعض في الفرق، وهذا الفصل هو ما يجعل تطبيق مبدأ "أقل الصلاحيات" على مستوى الأداة أمراً عملياً.

‍

Try now.

One gateway for all your models, MCP servers, and agents.
No credit card needed.

Start free
Table of Contents

One Gateway for Every LLM, Agent and MCP Server

Book a 30-min with our AI expert

Book a Demo

The fastest way to build, govern and scale your AI

Book Demo
Summarize with
ChatGPT logo by OpenAI
Perplexity AI logo
Blurry red snowflake on white background, symmetrical frosty design with soft edges and abstract shape.

Discover More

No items found.
AI architecture questions
October 10, 2026
|
5 min read

5 أسئلة حول بنية الذكاء الاصطناعي ستطرحها فرق المشتريات (وكيفية الإجابة عليها)

No items found.
TrueFoundry AI gateway is an enterprise complement to AI evaluation tools
October 10, 2026
|
5 min read

أفضل أدوات ومنصات تقييم الذكاء الاصطناعي في عام 2026: مقارنة مخصصة للفرق الهندسية

No items found.
October 10, 2026
|
5 min read

نقدم بوابة الوكلاء: طبقة تحكم موحدة للوكلاء في بيئة الإنتاج

الهندسة والمنتج
نماذج اللغة الكبيرة والذكاء الاصطناعي التوليدي
October 10, 2026
|
5 min read

البناء مقابل الشراء

الهندسة والمنتج
October 6, 2026
|
5 min read

هوية وكيل الذكاء الاصطناعي: منح كل وكيل هوية غير بشرية

No items found.
August 25, 2026
|
5 min read

AI Agent Guardrails: Inspecting Every Tool Call and Model Hop

No items found.
What is MCP Authorization
October 10, 2026
|
5 min read

ما هو ترخيص MCP؟ دليل مفصل

No items found.
MCP Server Security Best Practices for Safe AI Deployments
July 4, 2026
|
5 min read

أفضل ممارسات أمان خادم MCP

الهندسة والمنتج
What is an AI Agent Registry?
October 10, 2026
|
5 min read

ما هو سجل وكلاء الذكاء الاصطناعي؟

No items found.

Recent Blogs

Black left pointing arrow symbol on white background, directional indicator.
Black left pointing arrow symbol on white background, directional indicator.

Frequently asked questions

What is AI agent access control?

AI agent access control is the set of policies that decide whether an agent, user, or team is allowed to reach a given model, MCP server, or individual tool. It governs whether a call is permitted, which is a separate job from guardrails that inspect what a call contains. On TrueFoundry it is enforced at the gateway through resource-level collaborators and tenant-level roles.

What is the difference between access control and guardrails?

Access control decides whether a call is allowed to happen. Guardrails inspect the content of a call that is already allowed, catching injections, PII, secrets, and unsafe operations. You need both: access control keeps the set of permitted calls small, and guardrails police what flows through the ones that are permitted.

How do I enforce least-privilege for an AI agent?

Give each agent its own identity, then grant it access only to the specific model accounts and MCP tools its function requires, using resource-level collaborator roles. Scope the agent to its job rather than to the permissions of the person driving it, use approver roles for sensitive tools, and prefer team-based grants so access stays manageable.

Can I control access to individual MCP tools, not just whole servers?

Yes. Access rules on the MCP Gateway can narrow to specific tools within a server, so an agent can be granted a read-only tool while the write tool on the same server stays off limits. Because the gateway fronts every call, the rule covers every caller of that tool automatically.

هل يمكنني نشر TrueFoundry في شبكتي الافتراضية الخاصة (VPC) أو في موقعي؟

نعم. تعمل TrueFoundry في شبكتك الافتراضية الخاصة (VPC)، أو في موقعك، أو في بيئة معزولة، أو في بيئة هجينة، أو عبر سحابات متعددة، ولا تغادر أي بيانات نطاقك. هذا هو السبب الرئيسي الذي يجعل الشركات الخاضعة للتنظيم تفضلها على بوابات SaaS فقط.

Does TrueFoundry support MCP and AI agents?

Yes. It includes an MCP Gateway, Agent Gateway, and an MCP and Agents Registry with tool-level access control, governing agents from LangGraph, CrewAI, AutoGen, and custom frameworks from one place.

Take a quick product tour
Start Product Tour
Product Tour