Least privilege
Give each agent only the tools and data required for the current job.
A practical field guide for identifying trust boundaries, reviewing agent behavior, and placing human control where it matters. Use it while mapping a system—not after the build is complete.
Explore the risk libraryFoundation
Model output is a proposal. Permissions, policy, and people decide what happens next.
Give each agent only the tools and data required for the current job.
Keep user intent, external content, model output, and policy visibly distinct.
Check permissions and arguments at execution time—not only when the UI renders.
Make consequential actions understandable and reviewable before they happen.
System map
A secure workflow is rarely secured in one place. Trace the action from the person who initiates it through the data and services it touches, then back to the record the app leaves behind.
Who is acting—and how strongly has that identity been verified?
What information enters, leaves, persists, or crosses a workspace boundary?
Which server-side rules still hold when the interface is bypassed?
What external service, scope, credential, or recipient is involved?
What can the model infer, propose, retrieve, and execute?
Reference library
Select a topic to turn a broad concern into design questions and controls.
Instruction integrity
Untrusted content attempts to redirect an agent or override the task it was given.
Ask during design review
Can retrieved content change the agent’s authority, tools, or destination?
Recommended controls
Approval anatomy
Describe the operation in plain language.
Name the account, workspace, service, or recipient.
List the exact records, fields, files, or context.
State whether reversal is possible and how.
Explain the material risk without alarmist language.
Observability
Keep enough context to understand the action and investigate failure. Avoid storing hidden model reasoning or sensitive prompt content that the record does not need.
Shared responsibility
Working method
Security is not a final gate. Each stage should leave the next person with a clearer boundary, a testable control, or a decision that can be revisited.
Name the job, actors, assets, boundaries, and worst credible outcome.
Choose the minimum data and capability needed to complete the job.
Test authorization, injection, leakage, unsafe tool use, and recovery.
Record meaningful actions without retaining secrets or hidden reasoning.
Review the design when tools, providers, permissions, or data sources change.
Before handoff
Use these prompts during critique or attach the answers to the system map.