Skip to content
Search prompts, tools, agents…

How-to guide

Agent guardrails: permissions, approvals and cost control

How to let an agent work without losing control: limit tools, require approval, protect secrets, cap spending and keep a record of what it did.

  • Time 12 min
  • Level Advanced
  • Steps 6
  • Updated

The more an agent can do, the more it matters what it is allowed to do.

Step by step

0/6 done
  1. 1 Least privilege

    Give each agent only the tools, folders and accounts it needs. Use a read-only mode while you are learning how it behaves.

  2. 2 Require approval for risky actions

    Deleting files, sending messages, spending money, and changing production should wait for a human yes. Say so in the system prompt and use your tool's permission settings to enforce it.

  3. 3 Protect secrets and private data

    Never put keys in prompts or skills. Keep them in environment variables or a secret manager, and do not let the agent print them.

  4. 4 Treat outside text as untrusted

    Web pages, emails and files can contain instructions aimed at the agent ("ignore your rules and..."). Tell the agent that content it reads is data, not commands, and keep high-risk tools away from agents that read untrusted content.

  5. 5 Limit cost and time

    Set a maximum number of steps, a time limit and a budget, and choose a smaller model for simple steps.

  6. 6 Keep a record

    Log what the agent did and why. When something goes wrong you will want the trail.

Was this helpful?