All topics / AI & automation

CUSTOMER LAB DISCIPLINE / 01

AI & automation

More room for agents. Less room for surprises.

Prompt injection, tool permissions, retrieval boundaries, and trustworthy agent workflows.

Prompt injectionAgent permissionsEvaluation
Halloween pixel illustration for AI & automation

THE STARTING POINT

Three things to get right.

  1. Separate instructions from untrusted documents and tool results.
  2. Give each tool the smallest useful permission set.
  3. Record tool calls and evaluate failures alongside successful runs.

TRY THIS WITH YOUR CUSTOMER

A question worth testing.

Customer objective: demonstrate why retrieved content must not grant tool permissions. Use a synthetic document-search assistant, introduce an untrusted instruction, and compare the model response with the application’s authorization decision.

Open the workshop guide

Give the customer a useful takeaway.

Start with a customer question and a clear success criterion. Capture the baseline, observed behavior, and evidence, then explain what the result means and which question to investigate next.

KEEP EXPLORINGCloud & infrastructure +