Design least-privilege access for systems acting on behalf of people.
Type Skill · introduced in version 0.1
Normative. These state what would be observed in a person who holds the statement.
Non-normative. Illustrative of evidence an awarding body might accept; not a required form.
Assumes
Statements a candidate is taken to hold already. Never at a higher level than this one.
Configure an AI system’s access so that it holds only the permissions its task requires.
Assumed by
Derived inverse. Statements that take this one as given.
Design an agent’s tool access and authorisation boundaries.
Design access control so retrieval respects the requester’s entitlements.
Related
Cross-domain relationships, stated in both directions and typed in the content model.
Review an incident involving AI output and identify the assurance gap that allowed it.
Referenced by
Entries on the register of conformance claims whose coverage map cites this statement.
No entry on the register cites this statement. This block is populated from the coverage maps of register entries as they are listed.
| Introduced | Version 0.1 |
|---|---|
| Last modified | Not modified since introduction |
| Status | active · stable |
| Version displayed | v1.29 |
| Permanent URL | aicertificationstandards.org/framework/statements/D8.L3.07 |
AI Certification Standards (2026) AICF D8.L3.07, D8 Security, version 1.29. Available at aicertificationstandards.org/framework/v1.29/statements/D8.L3.07 (accessed date).
Statements change through the published process, not by correspondence
An amendment to this statement, its indicators or its relationships is proposed through the contribution process. Every submission is answered on the record, and the reasoning for acceptance or rejection is published in the release record for the version that follows.
Propose an amendment to D8.L3.07Writing rules and the controlled verb list that govern how this statement is worded are published in the methodology.
This page displays version 1.29 · last reviewed 30.08.2026