English Articles

Read-Only AI Tasks: Separate Accounts and Permissions

日本語で読む

Asking AI to “read the settings without changing anything” is becoming a routine part of development. Before handing over that work, it is worth checking that an accidental update is actually blocked. Alongside the instructions, the account permissions and command-execution environment need to be separated from those used to make changes.

A read-only task triggered an update command

During development, work to set up and check a tool for reading configuration data led to an unintended deployment-related update command. The request was to prepare read access, but execution went as far as an operation that could make changes.

The relevant access-control rules were read again afterward, and their contents had not changed. An error message alone, however, is not enough to conclude that nothing happened. A command may run several operations and stop only after some have succeeded. It was necessary to check both what had run and what had changed afterward.

The whole setup needed a review, including the configuration used to delegate the work. The instruction said “do not change anything,” while the execution environment still allowed changes.

Where is “read-only” actually enforced?

Suppose you ask AI to inspect some settings. The prompt says “read only,” and the available tools are limited to fetching configuration. On the surface, that looks like a read-only setup.

But if the tool runs under an account with a powerful role such as Owner, the account still has permission to make changes. The same problem exists if AI can run another command using those credentials. Removing update tools from the visible list does not remove that route.

There are three layers to check. The instructions define what AI is allowed to do. The exposed tools define which operations it can select. The execution environment and Identity and Access Management (IAM) permissions determine what the account can actually do. All three need to agree.

A tool's name may also hide work that happens behind the scenes. In Firebase CLI v15.30.2, retrieving the tool list through MCP, its interface for AI tools, calls a billing-status check. That check includes code that checks whether the Cloud Billing API is enabled and attempts to enable it if it is not. The path can be traced from the tool-list handler to the billing-status check and then the API-enablement code.

This finding does not establish the cause of the earlier update command. It shows that an operation that appears to retrieve a list can include an attempt to change a setting. Enabling an API and changing a billing plan are also separate operations.

Use a separate account for reading

There is no need to build a custom management system first. Start with a separate account for read-only work, limited to the resources and permissions the investigation needs. Google Cloud also recommends separating service accounts by purpose and granting only the permissions they need.

Creating the account is only part of the job. If administrator credentials remain available in the execution environment, they may still be used. Check for routes to stronger permissions, including through command-execution tools.

When a change is needed, have a person confirm the target and the proposed change before following the procedure for making it. If a read operation fails, find out which permission is missing before adding administrator access.

What to check after connecting

Once the read-only connection is set up, check the following:

  • Is it actually using the intended read-only account?
  • Can it retrieve the required settings, without exposing data it does not need?
  • Do tool startup or tool-list requests include operations that change settings?
  • Have you checked the permission configuration or used a test environment to verify that changes are not permitted?
  • If an error occurs, can you inspect the logs and the state of the affected resources?

Avoid running an update command in production just to see whether it will be rejected.

In this review, the dedicated read-only account has been created. End-to-end testing with the planned connection method is still unfinished. Before calling a setup “read-only,” the preparation needs to include checking which account is being used, what it can do, and what it cannot.

Related Articles

Connect ChatGPT to Your Mac mini · English home

-English Articles