Skip to content
SamplePreview build: teacher profiles, ratings, reviews and lesson counts are sample data.
All tutors

Guardrails and Permissions for AI Agents

Decide what your agent may read, write and spend, and enforce those limits in code rather than prompts

By Ingrid Solberg Intermediate AI agents 4.7(3) 56 lessons taught Sample

Your first 3 replies from the tutor are free. Then you can continue the lesson for $8 from your credit.

A taste of a lesson

One question and the answer, as this tutor gives it.

Guardrails and Permissions for AI Agents AI tutor following Ingrid Solberg's plan
Student:

Our agent has a run_sql tool so it can answer data questions. I told it to only use SELECT. Is that safe enough?

Tutor:

Not yet. The instruction helps, but a confused or manipulated model could still send a DELETE. Enforce it underneath: connect with a database user that only has read permission, ideally on a replica, and limit it to the tables the task needs. Add a statement timeout and a row limit so a heavy query cannot hurt performance. Log every query with the run it came from. Then the prompt becomes guidance, not your only defence. Quick exercise: list which tables this agent genuinely needs to read for the questions you expect.

Written by the teacher as an example. In your lesson the tutor answers your own questions, and like any AI it can be wrong.

What you will be able to do

  • Explain why prompt instructions are not a security boundary
  • Sort an agent's capabilities into risk tiers and choose controls for each
  • Apply least privilege, allow lists, argument validation and spend limits in code
  • Write a permission plan stating what code, configuration and humans each enforce

Lesson plan

6 lessons. Pick one to start there.

  1. 1 Prompts guide, code enforces Understand why instructions alone cannot keep an agent within limits. Start
  2. 2 Inventory and risk tiers List what an agent can touch and rank each capability by potential harm. Start
  3. 3 Least privilege access Give the agent its own narrowly scoped access instead of broad credentials. Start
  4. 4 Validation, allow lists and limits Check every tool argument in code and cap what the agent can do per run. Start
  5. 5 Approvals, logging and output checks Add human review for high risk actions and keep an audit trail. Start
  6. 6 Writing your permission plan Produce a one page plan mapping every tool to its controls. Start

Try asking

Tap a question to start a lesson with it.

About this tutor

For developers and technical leads preparing to give an agent access to real systems: email, files, databases, payments or customer records. Instructions in a prompt are not a security boundary, so this tutor teaches layered guardrails: least privilege access, separate read and write tools, allow lists, input and output checks, spending and rate limits, and approval for sensitive actions. You will practise writing a permission plan for a real looking agent, mapping each tool to a risk level and deciding what is enforced by code, by configuration and by a human.

Reviews

4.7

3 ratingsSample

  • Clara J.Sample

    The risk tier exercise was simple and effective. I would have liked a sample permission plan to compare mine against, but the structure was clear.

  • Vikram P.Sample

    Calm, no scare tactics, very concrete. Exactly the tone I needed before presenting to our security lead.

  • Femi O.Sample

    'Prompts guide, code enforces' is now our team rule. We moved our agent off an admin API key the same week.

About the teacher

Ingrid Solberg

I teach people to make AI agents safe, observable and testable before they are trusted with real work

9 tutors 4.5(17) 290 lessons taught Sample

My background is in quality assurance and security testing, and I came to agents through the question every tester asks: how do we know this thing works, and what happens when it does not? I teach guardrails, permissions, approval steps, evaluation and trace debugging. My lessons are concrete. We look at a failure, name it, and design the check that...

See Ingrid's profile and tutors