Skip to content

Secure an agent

Define authority and execution boundaries before giving tools real access.

Questions to answer

Who authorized this action? Can code bypass the tool boundary? Where are credentials visible?

Start here

Start with the ecosystem map and AST research. Separate model behavior, tool policy, and actual OS/network enforcement.

Prerequisites: a small task you can describe, its permitted effects, and basic Python for executable examples. Reading the guides needs no API key.

Evidence and coverage

Approval mechanics are measured. Boundary-response work tests fixture policy behavior; it cannot certify host isolation or model injection resistance.

Follow the concept and build path for runnable lessons and the ecosystem map for wider coverage. Return to all journeys.