Enforce least-privilege tools and pre-action containment: Which missing control most directly limits
Enforce least-privilege permissions and pre-action containment for consequential agent actions.
The question
A school administration agent can update enrollment records and send messages. During testing it sends a message to the wrong student group. Permissions are broad enough to permit this, and logging exists, but no pre-action containment or approval boundary is enforced. Which missing control most directly limits recurrence and impact?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Refine the agent’s prompt examples.Prompt examples may influence outputs, but they do not create an enforceable authorization boundary or contain tool actions.
- Raise confidence thresholds for generated messages.Confidence scores may filter some outputs, but they do not restrict recipients or prevent unauthorized tool use.
- Have administrators review each message only after transmission.Post-transmission review can detect an error but cannot prevent delivery to the wrong group or contain the action beforehand.
- Enforce least-privilege tools and pre-action containment. ✓Narrow permissions and a pre-action boundary limit what the agent can do when it behaves unexpectedly, directly reducing recurrence and impact.
The trap
For agents, focus on permissions, tool restrictions, approvals, observable actions, and containment. How to remember it
Enforce least-privilege permissions and pre-action containment for consequential agent actions.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- Pause the secondary use pending purpose-specific: Which missing control most directly addresses this emergent →
- Treat retrieved instructions as untrusted data: What missing control most directly addresses this →
- Scope prompt-log access: Which missing control most directly addresses this exposure? →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.