Control areas · Content and context
Prompt Injection & AI Agent Context Controls
Retrieved documents, messages and tool output may carry instructions that conflict with the user’s task.
Design and verification
Mark trust boundaries
Keep task instructions, retrieved material and tool output distinct. Carry source and access information through retrieval.
Constrain retrieval
Use source permissions and scoped queries; consider what the agent can retrieve as well as what it can output.
Test boundary failures
Use synthetic documents and tool output to check whether untrusted instructions influence actions.
Example
A document asks a support agent to export the customer database. Treat the document as evidence to read, not authority to invoke an export. Action-level restrictions must still apply.
Engineering scope
These are control design requirements. Implementation, supported versions and evidence mechanisms are selected and verified for the customer environment. See Guardrail Engineering.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.