Why it matters

Permission failures are already happening

Public incidents that motivated the approach. TokenVeto has never been run on these systems.

INCIDENT

Meta

AI-assisted account recovery sent password resets to attacker-controlled emails — up to 20,225 accounts.

INCIDENT

Salesloft

Stolen Drift tokens exposed Salesforce data at 700+ organizations.

INCIDENT

Replit

An AI coding agent deleted a production database.

INCIDENT

McDonald's

Access-control weaknesses in an AI hiring assistant exposed applicant data.

INCIDENT

Microsoft

AI assistant integrations surfaced data beyond intended permission boundaries.

INCIDENT

Salesforce

Agent-connected workflows highlighted risks of over-broad tool access.