Memory hook: Policy outside prompts; release behind gates.
Must remember
- Use per-agent/workload identity, scoped RBAC and network boundaries. OAuth/on-behalf-of flows preserve supported user context; API keys require secure storage and rotation when unavoidable.
- Key Vault stores supported secrets, keys and certificates with access controls and lifecycle management. Do not copy a broad secret into every agent environment.
- Apply guardrails at user input, retrieval, tool request, tool response and final output. Domain-specific constraints such as transaction limits require deterministic validation, not only content filtering.
- Red-team the system early, including indirect prompt injection, data exfiltration, cross-tenant access and unauthorized actions. Foundry red-team tooling can support tests; inspect coverage and validate mitigations.
- Development-Test-Acceptance-Production, canary and blue/green strategies control release exposure. Version infrastructure, agents, prompts, tools and data contracts; test rollback with compatible state.
- CI/CD needs unit, integration, regression and evaluation gates plus scoped release identities. Human approval must describe the exact proposed consequential action, not a blanket permission for future unknown operations.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| An external document asks the agent to reveal keys | Treat it as untrusted content and enforce tool/data policy independently. |
| Release changes both tools and prompts | Promote a tested versioned bundle with compatibility and rollback checks. |
Traps
- A system prompt is not an access-control list.
- Input screening alone misses malicious content returned by tools or retrieval.
Active recall
1. What does on-behalf-of preserve?
Supported delegated user authorization when a service calls another service.
2. Why use multiple guardrail points?
Risk can enter through inputs, sources, tool calls, results and generated output.
3. What should a canary measure?
Quality, safety, completion, latency, failures and cost against predefined thresholds.
4. Why test rollback with state?
A new schema or memory format may not be readable by the prior release.
5. Where should transaction authorization live?
In the trusted application/service boundary outside model-generated instructions.