✳ Learning path / 4 lessons
AI application and agent security
Four lessons on treating user, retrieved, and tool text as untrusted, keeping tools and credentials outside the model, and requiring a human gate before high-impact actions. Builds on identity, least privilege, and evidence. Agentic SOC remains the place for investigation architecture.
Work through the lessons in sequence, or choose the question you want to answer today.
01Prompt injection and retrieval trust
Separate developer instructions from user, retrieved, and tool text, and treat a retrieval store as untrusted input rather than as a policy.
Excessive agency: tools, credentials, and blast radius
Constrain what an application can do by limiting tool functions, credentials, and autonomy outside the model, and name the blast radius before a model can call anything.
Human oversight as a designed process
Name who may approve a high-impact agent action, what they must see, and when the application must stop for a person.
A light map to the NIST AI Risk Management Framework
Place a constrained mail-and-payments agent on Govern, Map, Measure, and Manage without treating the AI RMF as a certification.
Turn knowledge into a decision.
Once you have the ideas, try a short scenario. You’ll see why the tempting answer isn’t always the most useful one.
Open the practice range ↗