What the agent is allowed to see on the AI Agents track. The agent sees whatever you put in the prompt and whatever tools return. That can include other customers' data if a tool is loosely scoped. Scope every read to the current user.
This lesson assumes you already worked through Prompt injection through tools.
The idea in practice
Pass a user id into tools on the server. Do not trust a user id the model typed. Filter fields before they enter the prompt.
A concrete check
goal = {
'track': 'AI Agents',
'lesson': 'What the agent is allowed to see',
}
checks = [
'input available at decision time',
'score matches the real decision',
'failure case written down',
]
print(goal['lesson'])
for item in checks:
print('-', item)
Run the sketch locally if you have Python. The printout is a reminder of the checks, not a trained model. Replace the strings with the real inputs from your own example before you treat it as a design.
What usually goes wrong
A search tool that returns any customer's row will leak data the moment the model is asked to. When this happens, stop adding parameters or tools. Fix the check, the data, or the permission, then run the same example again.
What to write down
- The input you are allowed to use at decision time.
- The output and the score or pass rule.
- One failure you will test on purpose.
- What you will not claim the system can do.
Practice
Mark three fields that must never enter the prompt for a billing agent.
Self-check
- Say What the agent is allowed to see in one sentence that mentions an input and an output.
- Name the failure mode in this lesson and the check that would catch it.
Done when: you can explain this lesson without the page open, and you have a written failure case.