Control areas · Content and context
Prompt Injection & AI Agent Context Controls
Retrieved documents, messages and tool output may carry instructions that conflict with the user’s task.
Design and verification
Mark trust boundaries
Keep task instructions, retrieved material and tool output distinct. Carry source and access information through retrieval.
Constrain retrieval
Use source permissions and scoped queries; consider what the agent can retrieve as well as what it can output.
Test boundary failures
Use synthetic documents and tool output to check whether untrusted instructions influence actions.
Example
A document asks a support agent to export the customer database. Treat the document as evidence to read, not authority to invoke an export. Action-level restrictions must still apply.
Engineering scope
These are control design requirements. Implementation, supported versions and evidence mechanisms are selected and verified for the customer environment. See Guardrail Engineering.
Turn security challenges into a clear plan
Tell us what you need to protect, improve or achieve. We will help you identify the control gaps, prioritise the work and define practical steps towards your goal.