{"found":true,"collection":"patterns","library_url":"https://www.grokbotdb.com/library/pat.scoped-service-accounts","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"pat.scoped-service-accounts","name":"Scoped service accounts, not the owner's admin login","category":"safety","problem":"Grok Bot cannot give a Bot less access than its neighbours, because the boundary is the account.","technique":"Create dedicated service accounts in every source system that supports them, scoped to the minimum the workflow needs: a CRM account with read access to one view, a repository token limited to one project, a mail account for one shared inbox.","why_it_works":"The source system can draw the boundary the product cannot, so the blast radius becomes the union of what those scoped identities can do rather than the union of what you can do.","when_to_use":"Every business integration.","manual_ref":"5.3","evidence":"reported","attributed_to":"Kumar Gauraw","source_url":"https://www.gauraw.com/grok-bot-complete-guide-ai-agent-team/","related":["pat.start-read-only","pat.bots-are-not-a-security-boundary","pat.scoped-permissions-over-written-boundaries"],"confidence":"high","first_seen":"2026-09-03","last_verified":"2026-09-03"}}