Control areas · Content and context

Prompt Injection & AI Agent Context Controls

Retrieved documents, messages and tool output may carry instructions that conflict with the user’s task.

Design and verification

Mark trust boundaries

Keep task instructions, retrieved material and tool output distinct. Carry source and access information through retrieval.

Constrain retrieval

Use source permissions and scoped queries; consider what the agent can retrieve as well as what it can output.

Test boundary failures

Use synthetic documents and tool output to check whether untrusted instructions influence actions.

Example

A document asks a support agent to export the customer database. Treat the document as evidence to read, not authority to invoke an export. Action-level restrictions must still apply.

Engineering scope

These are control design requirements. Implementation, supported versions and evidence mechanisms are selected and verified for the customer environment. See Guardrail Engineering.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.