The outcome
Deliver useful open-ended assistance without enabling prompt injection, tenant crossover, uncontrolled loops, or autonomous consequential actions.
Step by step
A workflow you can repeat.
- 01
Define the user task, model, data classes, allowed tools, user roles, tenant boundaries, output schema, stop conditions, request and token budgets, approvals, and audit fields.
- 02
Create typed read-only tools first, validate and canonicalize inputs, fetch current authorization inside each executor, use scoped service accounts, and never expose secrets in descriptions or results.
- 03
Register the smallest toolset, quote retrieved and MCP content as untrusted data, constrain model and steps, validate structured output, and require explicit approval before any side effect.
- 04
Test prompt injection, unknown tools, forged arguments, cross-tenant IDs, data exfiltration, duplicate calls, loops, malformed output, timeouts, provider failure, denial, and cancellation.
- 05
Inspect Studio traces and evals, redact sensitive fields, canary behind rate and cost limits, monitor tool and model changes, and keep an immediate tool-disable and rollback path.
Working standard
What good use looks like.
- Authorize inside every tool.
- Start with read-only capabilities.
- Require approval for side effects.
Official references