Skip to slide
Chapter 11 · Security, Auth, and Multi-Tenancy
107 / 191

CHAPTER 11 · Security, Auth, and Multi-Tenancy · 9 / 9

The mindset

Security for agents combines classic web-app discipline (authenticate, authorize, isolate, validate, encrypt, rate-limit) with a new humility: the model will sometimes try to do the wrong thing, whether from confusion or manipulation. So you bound it: narrow tools, least privilege, human confirmation for consequential actions, and access checks that authorize against the user, not the model's stated intent. Design as if a clever adversary controls part of the content the model reads, because eventually one will.

← → arrow keys work too