The read-only AI agent: the write it could make versus the write it can’t
Before: an AI agent with access to live systems could delete a user or push a policy. After: the agent reads only a separate snapshot — there is no write path back to the tenant, by construction.
Ketan Kamble
BEFORE · WHAT IF IT WRITES?
AFTER · NO WIRE BACK
STEP 1 · THE FEAR, HONESTLY
AI AGENT → LIVE TENANT
Intune · Graph · Entra — “what if it deletes a user?”
the write nobody wants
STEP 2 · THE GUARANTEE
READ-ONLY BY CONSTRUCTION
collectors → snapshot → agent · a write can’t travel back
STEP 3 · ASK IT ANYTHING
PLAIN-ENGLISH QUESTION
“Which disabled users still hold a Teams Phone licence?”
▶ the read-only agent (no tenant access)
reads only the snapshot · every source read-only
ANSWER · CITED READ-ONLY SOURCES
from the reclaim list · shadow-AI · AVD — all read-only
answers anything ·
changes nothing — no wire back
Pause