Set the agent’s boundaries

Reading ·

An agent’s instructions don’t tell you which actions its software will allow. Dell’s Ihab Tarazi argues that permissions and execution controls need their own enforcement. His article describes runtime, network and hardware controls intended to contain an agent when its instructions go wrong.

OpenShell governs what an agent can access and execute. Sentry adds identity checks, monitoring and isolation through separate infrastructure. The article describes Dell’s NVIDIA architecture; it doesn’t establish how every deployment performs.

So our takeaway is to write the boundary down before giving the agent a tool. You might set a refund limit, check the receiving account and name a reviewer for exceptions. The software should check those conditions at the point where money would move. That check belongs in the tool, where the agent can’t talk its way around it.

Then test attempts to step outside that boundary, including requests that sound reasonable. An agent shouldn’t gain permission because it explains its request well. Keep a record of the attempted action and the rule that allowed or blocked it. You need to be able to inspect the decision after the conversation ends.

Ihab Tarazi, Dell. Original article and this commentary published .

Read Ihab Tarazi’s original Dell article.