Follow the workflow beyond the chat window
An AI assistant that summarizes a document has a different exposure than an agent that can also email the summary, modify a record, or deploy code. To review the system, draw the workflow: user request, retrieved content, model processing, tool call, and resulting action. Identify the data and authority that cross each connection.
A useful question for every tool is: what could this action affect if the model misunderstood the task? OWASP describes excessive agency in terms of unnecessary functionality, permissions, and autonomy. Narrow tools and permissions to the job the application is meant to perform. [1]
Enforce the boundary where actions happen
For consequential actions, validate authorization outside the model’s free-form reasoning. Check the actor, destination, resource, and parameters at execution time. If an approval is required, it should apply to the exact action being executed. OWASP’s agent security guidance recommends independent scope, privilege, and approval validation for high-impact actions. [3]
Prefer a tool that reads a permitted record over one that runs an arbitrary database query when the task only needs that record. Keep a drafting capability separate from sending where the workflow allows it. These are concrete ways to reduce the authority available when a model produces an unexpected result. [1]
Test outcomes, then preserve the evidence
Use a test environment and synthetic data to exercise realistic misuse scenarios. Can one user retrieve another user’s content? Can a document change the destination of an export? Does a rejected action stay rejected after a retry? Record the attempted action and the enforced result, not only whether the model used reassuring language.
Keep enough protected telemetry to understand tool use and authorization outcomes. Repeat relevant checks after material changes to prompts, tools, retrieval, memory, or providers, as OWASP recommends. A useful security finding identifies the boundary that failed and the system control needed to restore it. [3]
