Blank white background with no objects or features visible.

「Gartner Hype Cycle for AI Governance 2026」の全編を無料で公開しています。レポートを入手する →

AIエージェントのアクセス制御:すべてのエージェントに最小権限を

By アシシュ・ドゥベイ

Published: October 6, 202616

⚡ TL;DR

AI agent access control decides whether a call is allowed to happen at all: which agents, users, and teams can reach which models, MCP servers, and individual tools. It is a separate job from guardrails, which inspect what a call contains. On TrueFoundry, access is enforced at the gateway through role-based collaborators at the resource level and roles at the tenant level, so you can scope every agent to least privilege without writing authorization logic into agent code.

Agents make access control harder for one simple reason. A single person can drive dozens of agents, and each agent can call many tools, so the old model of "this user can use this app" no longer describes what is actually happening. A support copilot that only needs to read tickets should never be able to run a refund, even when the person behind it could. Getting that right means scoping the agent, not just the human.

This guide covers what AI agent access control is, how it differs from guardrails, and how TrueFoundry enforces least-privilege across models and MCP tools from one control plane. It pairs closely with AI agent identity, which establishes who is calling in the first place.

AIエージェントのアクセス制御とは?

AIエージェントのアクセス制御とは、特定の呼び出し元が特定のリソースにアクセスできるかどうかを判断する一連のポリシーです。ガードレールが「内容の安全性」を判断するのに対し、アクセス制御は「許可されているか」を判断します。

この違いを理解しておくことは重要です。両者はそれぞれ異なる方法で機能不全に陥る可能性があるため、両方の制御が必要となります。

  • アクセス制御 は、入り口の警備員のようなものです。このエージェント、ユーザー、またはチームが、そのモデルやMCPツールを呼び出す権限をそもそも持っているかどうかを確認します。
  • ガードレール は、金属探知機のようなものです。呼び出しが許可された後、プロンプト、出力、ツールの引数を検査し、インジェクション、個人情報(PII)、機密情報、または安全でない操作がないかを確認します。

あるエージェントがデータベースのMCPサーバーを呼び出す権限を完全に与えられていても、破壊的なクエリを送るよう誘導される可能性があります。アクセス制御はサーバーへのアクセスを許可しますが、クエリが実際に何を行うかは、引数に対するガードレールのみが検知できます。しかし、アクセス範囲を広げすぎると、金属探知機だけに頼ることになってしまいます。最小権限の原則は、そもそも許可される呼び出しの数を最小限に抑えるためのものです。

TrueFoundryにおける2つのアクセス制御レベル

TrueFoundryは2つのレベルでアクセスを制御しており、この区分を理解することが運用の大部分を占めます。

リソースレベルのロール(コラボレーター)

ユーザー、チーム、または仮想アカウントをリソースのコラボレーターとして直接追加し、そのリソースのみにアクセス範囲を限定するロールを選択します。ロールはリソースタイプごとに定義されています。

Resource Roles
Model Account / Provider Account Manager, User
MCP Server MCP Server Manager, MCP Server User, MCP Server Approver
Agent Agent Manager, Agent Access
Workspace Workspace Admin, Member, Viewer
Secret Group Admin, Editor, Viewer, Access

ここに最小権限の原則が適用されます。エージェントには業務に必要なMCPサーバーへのアクセス権のみを付与し、チームには呼び出しが許可されたモデルアカウントのユーザー権限を与え、ツール実行前に承認が必要な場合はMCPサーバー承認者を追加します。これらすべてにおいて、カスタムロールを作成する必要はありません。

テナントレベルのロール

テナントレベルのロールはテナント全体に適用され、「アクセス」メニューの「ロール」から設定します。これらは、リソースの作成、ユーザーの管理、特定タイプのリソースの一覧表示など、テナント全体に関わるアクションを制御します。TrueFoundryには以下の2つが標準で用意されています。 管理者(Admin)は、すべての権限を持つため、少数のユーザーに限定すべきです。そして、 メンバー(Member)はデフォルトでは何もアクセス権を持たず、リソースへのアクセスを明示的に許可する必要があります。既存のロールでは権限が広すぎたり狭すぎたりする場合は、カスタムロールを作成します。

‍

Permissions available when creating a custom tenant-level role in TrueFoundry

 

TrueFoundryドキュメントの製品スクリーンショット:カスタムロールの権限設定。

‍

ロールは個々のユーザーだけでなくチームにも割り当てることができ、ユーザーの有効な権限は、そのユーザー自身のロールと所属するすべてのチームから継承されたロールを合わせたものになります。SCIM経由でIDグループを同期している組織の場合、それらのグループはTrueFoundryのチームとして取り込まれ、直接ロールを付与できるため、IdPで既に管理されている信頼できる唯一の情報源(Source of Truth)に基づいてアクセス権を制御できます。

MCPツールのアクセス制御の仕組み

MCPゲートウェイは、通常混同されがちな3つの懸念事項を分離します。これらを切り離すことこそが、ツールレベルでの最小権限の原則を実用的なものにしています。

‍

Try now.

One gateway for all your models, MCP servers, and agents.
No credit card needed.

Start free
Table of Contents

One Gateway for Every LLM, Agent and MCP Server

Book a 30-min with our AI expert

Book a Demo

The fastest way to build, govern and scale your AI

Book Demo
Summarize with
ChatGPT logo by OpenAI
Perplexity AI logo
Blurry red snowflake on white background, symmetrical frosty design with soft edges and abstract shape.

Discover More

No items found.
October 10, 2026
|
5 min read

2026年版 LLMOpsツール ベスト10

比較
October 10, 2026
|
5 min read

本番環境でエージェントAIを運用するための5つの教訓 — ファイヤーサイドチャットより

No items found.
October 10, 2026
|
5 min read

Kubernetesにおけるスケール・トゥ・ゼロ:Elastiの深掘り

エンジニアリングとプロダクト
October 10, 2026
|
5 min read

LLMワークフローにおける可観測性:ブラックボックスをガラスボックスに変える

No items found.
October 6, 2026
|
5 min read

AIエージェントのアイデンティティ:すべてのエージェントに非人間としてのアイデンティティを付与する

No items found.
October 6, 2026
|
5 min read

AIエージェントのガードレール:すべてのツール呼び出しとモデルホップを検査する

No items found.
What is MCP Authorization
October 10, 2026
|
5 min read

MCP認証とは?詳細ガイド

No items found.
MCP Server Security Best Practices for Safe AI Deployments
July 4, 2026
|
5 min read

MCPサーバーのセキュリティベストプラクティス

エンジニアリングとプロダクト
What is an AI Agent Registry?
October 10, 2026
|
5 min read

AIエージェントレジストリとは何ですか?

No items found.

Recent Blogs

Black left pointing arrow symbol on white background, directional indicator.
Black left pointing arrow symbol on white background, directional indicator.

Frequently asked questions

What is AI agent access control?

AI agent access control is the set of policies that decide whether an agent, user, or team is allowed to reach a given model, MCP server, or individual tool. It governs whether a call is permitted, which is a separate job from guardrails that inspect what a call contains. On TrueFoundry it is enforced at the gateway through resource-level collaborators and tenant-level roles.

What is the difference between access control and guardrails?

Access control decides whether a call is allowed to happen. Guardrails inspect the content of a call that is already allowed, catching injections, PII, secrets, and unsafe operations. You need both: access control keeps the set of permitted calls small, and guardrails police what flows through the ones that are permitted.

How do I enforce least-privilege for an AI agent?

Give each agent its own identity, then grant it access only to the specific model accounts and MCP tools its function requires, using resource-level collaborator roles. Scope the agent to its job rather than to the permissions of the person driving it, use approver roles for sensitive tools, and prefer team-based grants so access stays manageable.

Can I control access to individual MCP tools, not just whole servers?

Yes. Access rules on the MCP Gateway can narrow to specific tools within a server, so an agent can be granted a read-only tool while the write tool on the same server stays off limits. Because the gateway fronts every call, the rule covers every caller of that tool automatically.

TrueFoundryを自社のVPCまたはオンプレミス環境にデプロイできますか?

はい。TrueFoundryは、お客様のVPC、オンプレミス、エアギャップ環境、ハイブリッド環境、または複数のクラウド環境で動作し、お客様のドメインからデータが外部に出ることはありません。これが、規制対象企業がSaaSのみのゲートウェイよりもTrueFoundryを選択する主な理由です。

Does TrueFoundry support MCP and AI agents?

Yes. It includes an MCP Gateway, Agent Gateway, and an MCP and Agents Registry with tool-level access control, governing agents from LangGraph, CrewAI, AutoGen, and custom frameworks from one place.

Take a quick product tour
Start Product Tour
Product Tour