
Your agent gets the same access you do
Artur Sabirov1 min readYour agent works Lessly the same way you do. Not with a copy of your key — with its own.
I didn't build it that way to be principled. I built it because I'd pasted my own root key into a coding tool too many times, meaning to scope it down later, and there was never anything to scope down to.
Every founding team is in that trap. A coding agent gets one of two things: your key, or nothing. And nothing doesn't ship. So you hand over the one key that opens everything, because a stack stitched from ten services has no smaller key to give. You never chose that reach. Each new service added a little more of it.
The cost shows up in the log. Run an agent on your credentials and everything it does is recorded as you — a change you didn't make that the log insists was yours. It says you did it. It can't say you didn't.
On Lessly the agent gets its own grant instead. Deploy, database, cache, and secrets run from one account, and access to them is a single thing: issued by a named person, scoped to a product, logged, revoked in one motion. The agent connects over MCP and works inside that grant, no wider. When it deploys, the audit line names the agent, not you.
Here's the part you can check the day you're in. Scope a grant to staging, then point the agent at production. It doesn't get there, and the attempt is on the record — under the agent's name, not yours.
That's it. That's the product.
Related posts
Building Lessly in the open
Follow along, and get early access to the private beta.


