Tool & permission boundaries for agents

P59.agent-boundaries.01 · Audience: guest, it-ml, language-pro · Prerequisites: AuthZ models: RBAC, ABAC, ReBAC, Prompt injection & untrusted content

Real LLM grading for this pageLLM grading (this page):

The single most important idea in agent security: the model proposes, your code decides. A tool call emitted by a model is a proposal. If a confused or manipulated model asks to delete a file or send an email, the only thing that stops it is a gate outside the model — P56's policy thinking applied to tool calls.

Two rules carry most of the value: a least-privilege allowlist (a tool this agent doesn't have is refused outright) and human-in-the-loop for irreversible actions. This platform runs exactly these rules for its own agent-assisted authoring — scoped access, and confirmation before anything irreversible or outward-facing.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — gate an agent's tool calls

Loading exercise…

My notes on this module

Loading your notes...

Tool & permission boundaries for agents — TransformerLab