How-to guide
Agent guardrails: permissions, approvals and cost control
How to let an agent work without losing control: limit tools, require approval, protect secrets, cap spending and keep a record of what it did.
- Time 12 min
- Level Advanced
- Steps 6
- Updated
The more an agent can do, the more it matters what it is allowed to do.
Step by step
0/6 done-
1 Least privilege
Give each agent only the tools, folders and accounts it needs. Use a read-only mode while you are learning how it behaves.
-
2 Require approval for risky actions
Deleting files, sending messages, spending money, and changing production should wait for a human yes. Say so in the system prompt and use your tool's permission settings to enforce it.
-
3 Protect secrets and private data
Never put keys in prompts or skills. Keep them in environment variables or a secret manager, and do not let the agent print them.
-
4 Treat outside text as untrusted
Web pages, emails and files can contain instructions aimed at the agent ("ignore your rules and..."). Tell the agent that content it reads is data, not commands, and keep high-risk tools away from agents that read untrusted content.
-
5 Limit cost and time
Set a maximum number of steps, a time limit and a budget, and choose a smaller model for simple steps.
-
6 Keep a record
Log what the agent did and why. When something goes wrong you will want the trail.
Was this helpful?
Thanks — that helps us improve this page.