CHAPTER 11 · Security, Auth, and Multi-Tenancy · 9 / 9
The mindset
Security for agents combines classic web-app discipline (authenticate, authorize, isolate, validate, encrypt, rate-limit) with a new humility: the model will sometimes try to do the wrong thing, whether from confusion or manipulation. So you bound it: narrow tools, least privilege, human confirmation for consequential actions, and access checks that authorize against the user, not the model's stated intent. Design as if a clever adversary controls part of the content the model reads, because eventually one will.