Control areas · Content and context

Prompt Injection & AI Agent Context Controls

Retrieved documents, messages and tool output may carry instructions that conflict with the user’s task.

Design and verification

Mark trust boundaries

Keep task instructions, retrieved material and tool output distinct. Carry source and access information through retrieval.

Constrain retrieval

Use source permissions and scoped queries; consider what the agent can retrieve as well as what it can output.

Test boundary failures

Use synthetic documents and tool output to check whether untrusted instructions influence actions.

Example

A document asks a support agent to export the customer database. Treat the document as evidence to read, not authority to invoke an export. Action-level restrictions must still apply.

Engineering scope

These are control design requirements. Implementation, supported versions and evidence mechanisms are selected and verified for the customer environment. See Guardrail Engineering.

Turn security challenges into a clear plan

Tell us what you need to protect, improve or achieve. We will help you identify the control gaps, prioritise the work and define practical steps towards your goal.