CHAPTER 18 · Reference Architecture and a Design Checklist · 9 / 15
Security
- Does every protected route authenticate via one middleware and authorize via centralized helpers? (Ch 11)
- Are list/batch inputs filtered to accessible resources before acting? (Ch 11)
- Is the agent's blast radius bounded by least-privilege tools, with human-in-the-loop for consequential actions? (Ch 11)
- Have you designed against prompt injection (untrusted content can't gain authority; actions authorized against the user)? (Ch 11)
- Are user secrets encrypted (AES-GCM, per-record IV, key from env, fail closed) and never exposed to clients? (Ch 12)
- Is credential resolution user-beats-operator with fallback, exposing status not secrets? (Ch 12)