In The Privileges I Gave Away (Article 09) I documented the sixteen OAuth scopes I granted when I connected Perplexity Computer to my GitHub account. Delete repos. Modify GitHub Actions. Add SSH keys. The scope list read like a penetration test wishlist. I wrote it up, published it, and then stared at the question every security practitioner asks after a finding: now what?

This article is the answer. Not a vendor evaluation. A containment procedure I built and tested.

The Scale of the Problem

Non-human identities outnumber human identities by 8.6 to 1 in the average enterprise.[^1] CyberArk research puts some environments at 45 to 1.[^1] DoControl's 2026 analysis found that 70% of SaaS activity originates from non-human identities.[^2] Forty percent of Google Drive events come from NHIs indistinguishable from human behavior in audit logs.[^2] These tokens sit outside the perimeter controls most organizations rely on. SASE, SSE, and EDR cannot differentiate an agent's API calls from a user's.[^3]

I needed a procedure. I built one around four phases: Audit, Scope, Monitor, Respond. Each phase leads with what to do. Tooling enters only where it accelerates or automates a step.

The Four Phases

Audit starts with enumeration. I walked my GitHub grants, catalogued every scope, and used enterprise SaaS-discovery controls to surface shadow AI integrations outside the expected inventory. You cannot scope what you have not inventoried.

Scope reduces each grant to its minimum viable permission set. Where the platform allows it, restrict. Where it does not - GitHub still offers no read-only scope for private repositories - make a conscious risk acceptance or remove the connector.

Monitor establishes behavioral baselines and alerts on anomalies. In an enterprise environment, I validated agent-inventory, SaaS-discovery, and automated-response controls against representative connector activity. The transferable point is the control pattern, not a particular vendor stack.

Respond defines the playbook for when a token is compromised. Revoke, assess blast radius, re-grant with tighter scope, and document the gap that allowed it.

What the Framework Cannot Solve

Containment reduces exposure. It does not eliminate the structural risks underneath. No platform can assert what an agent intended - only what it did. No tool blocks an OAuth API call inline before it executes. GitHub still bundles read and write into a single repo scope. These gaps are architectural, not operational. They remain open until the protocols change.

The honest position: this framework limits blast radius and speeds detection. It does not make agentic AI connectors safe. It makes them manageable.