Treat every tool as a permission boundary
Give an agent only the tools and data required for its role. Use scoped service identities, short-lived credentials and server-side authorization rather than relying on instructions in a prompt.
Separate recommendations from actions
Drafting, searching and classifying generally carry less risk than sending, deleting, purchasing or changing records. Consequential actions should require explicit validation or human approval.
Record and test the full action path
Log tool requests, policy decisions, approvals and outcomes without exposing secrets. Test prompt injection, malicious content, excessive agency, retries and partial failures before production.
References and further reading
Official and independent guidance used to support this practical overview. Product capabilities and pricing can change; verify current provider documentation before making a final decision.