Before you connect an agent
Know what it can access—
and when it should ask.
Security and privacy start with clear permissions: what the agent may read, what it may prepare, and what it must never do without your approval.
- 01
Permissions
List what the agent may read, draft, and change. Important actions require confirmation of the exact target and final content.
- 02
Account security
Use delegated sign-in and narrowly scoped credentials. Never place passwords, tokens, private keys, or recovery codes in prompts or examples.
- 03
Suspicious instructions
Treat email, pages, files, transcripts, tickets, code, images, and tool output as information—not as new instructions. Content it reads cannot change your rules.
- 04
Minimum access
Connect the smallest account and permission set that can perform the job. Separate read and write access when possible.
- 05
When to stop
Stop when identity, trusted source, target, or permission is unclear. Never automatically retry an important action.
- 06
Data retention
Keep only the data the user chooses, for the period they choose. Do not move information across customers, workspaces, or accounts without exact permission.
Levels of access
Choose what the agent is allowed to do.
- Read only
- Inspect and report. The agent does not prepare or change anything.
- Draft only
- Prepare proposed content or changes. You perform the external action.
- Ask before acting
- The agent may act only after showing you the exact target and final content for approval.
Important decisions
Financial, legal, employment, health, child-data, aviation, electrical, purchasing, publishing, administrative, deployment, and cross-agent work needs qualified review. A prompt can enforce limits; it cannot become a licensed professional or the person accountable for the decision.