A real estate AI agent should have the smallest set of permissions needed for one defined job—and no standing authority to send, publish, submit, change records, or move money. The practical test is not whether a permissions screen looks restrictive. It is whether the agent stays inside those boundaries when it reaches the same resource by a less obvious route.
Anthropic released Claude Code 2.1.289 on October 3 with several permission-related fixes. The release notes say the update corrected cases in which deny or ask rules could be missed inside compound shell commands, after certain variable assignments, or when a file was reached through a symbolic link in an editor. It also fixed a case in which a user-installed plugin could rewrite descriptions for sign-in tools on an organization-managed server.
Claude Code is a developer tool, and these technical fixes do not show that every consumer AI assistant has the same behavior. They do show why permission design deserves more than a one-time setup. A rule can appear correct at the front door while an indirect path, connected plugin, or unusual command changes what happens.
Define the job before granting access
“Help with my real estate business” is too broad to permission safely. “Turn an approved fictional property fact sheet into a draft open-house follow-up for review” is much clearer. The second version identifies the source, the action, the destination, and the required human checkpoint.
For that test, the agent may need read access to one approved folder and write access to one draft folder. It does not need the whole computer, live inbox, CRM, MLS account, transaction platform, contact list, calendar, or social accounts. It certainly does not need a brokerage administrator’s credentials just because that account is convenient.
Think in capabilities instead of app names. “Access to Google Workspace” says almost nothing. Can the agent read one document, search every Drive file, draft an email, send an email, change a calendar, or invite an outside guest? Those are different permissions and should be decided separately.
Use four permission levels
A simple permission map can separate what the agent may see from what it may do:
- Read: Allow only the approved source material required for the task. Begin with fictional or de-identified records.
- Draft: Let the agent create output in a review location that cannot publish or send on its own.
- Change: Keep CRM updates, file moves, calendar edits, and other record changes off during early tests. Add an approval step if a later use truly requires them.
- Act externally: Reserve email sending, ad publishing, document submission, account changes, purchases, and payments for a person.
This structure also makes problems easier to diagnose. If the task only needs reading and drafting, a request for send access is a design warning—not a routine setup step.
Do not treat a deny list as the whole boundary
A deny rule is useful, but it asks the system to recognize every route to a prohibited action. Anthropic’s release is a timely example: the fixes concern nested commands, variable prefixes, linked file paths, and plugins. Most real estate professionals should not have to interpret those details. The useful business lesson is that one control can miss a path you did not anticipate.
Layer the boundary instead. Give the test account no ability to send. Keep protected folders outside the approved workspace. Use a separate review destination. Avoid connecting an administrator account. Require the operating system, application, or organization policy to enforce limits where possible, rather than relying only on instructions inside a prompt.
On a managed brokerage device, ask the person responsible for technology or security to confirm how organization rules interact with local plugins, linked folders, desktop tools, and sandbox or auto-approval settings. If the answer is unclear, keep the integration disconnected.
Test the side doors
Permission testing should include attempts that are supposed to fail. Ask the agent to read a file just outside its approved folder. Try a shortcut or linked location that points to a restricted folder. Confirm that a draft cannot send, a calendar suggestion cannot create an event, and a CRM summary cannot update a contact. Remove a permission mid-session and verify that the agent loses it.
Then test connected components. Can a plugin introduce another tool? Can an integration change the description of what an action does? Does a remembered approval carry into a new session? Record what happened, including the product version and account used. A successful test is evidence for that configuration—not a permanent guarantee after every update.
AI agent permission checklist
- Name one bounded task, its owner, and its final stop point.
- List the exact files, folders, tools, and accounts the task requires.
- Remove broad workspace, administrator, and unrelated account access.
- Begin with fictional or de-identified information.
- Separate read, draft, change, and external-action permissions.
- Keep outputs in a review location with no send or publish authority.
- Test direct access, linked paths, connected plugins, and new sessions.
- Confirm that denied actions fail and produce a visible record.
- Retest after product, plugin, policy, or account changes.
- Keep a person responsible for every client-facing or consequential action.
The practical decision today
If an AI agent cannot complete a preparation task without broad access to live business systems, narrow the task. Start with one source folder, one review folder, fictional records, and no external action. Expand only after the team can explain the business need, test the boundary, and identify the person responsible for the result.
Permissions are not paperwork around the workflow; they are part of the workflow. If you want guided help choosing a small first task and placing the human checkpoints, join the free AI Agents for Agents Skool community. The detailed worksheets, prompts, and implementation lessons live there.
Primary source: Anthropic, Claude Code 2.1.289 release notes, published October 3, 2026. Claude Code is a developer tool; the specific fixes described here should not be generalized to every AI product.
This article is educational and does not provide individualized legal, privacy, security, fair-housing, tax, or compliance advice. Follow your brokerage’s policies and the requirements that apply to your work.
Start with one bounded job.
Give the task what it needs—not the keys to everything.
Join the free community for practical lessons on choosing a first AI workflow, setting permissions, and keeping consequential actions under human control.
Join AI Agents for Agents free on Skool