Path 03 · 6 lessons · 61 min
Make risk visible
Data boundaries, agent permissions, software supply chains, and evidence that makes governance practical.
- 01
Define where your data can go
Trace data through the development tool, model, logs, and deployed service. Verify the boundary before using confidential information.
- 02
Limit an agent’s authority
Define allowed actions, resources, and conditions. Verify permissions outside the model and separate implementation from release.
- 03
Treat retrieved content as untrusted input
Recognize instructions hidden in repository files and tool results. Keep retrieved information separate from authority to act.
- 04
Verify what enters the release
Inspect dependencies, build inputs, and artifact provenance. Connect the reviewed source to the software that reaches production.
- 05
Connect obligations to evidence
Separate legal applicability, technical controls, and proof of operation. Build a record that a responsible reviewer can inspect.
- 06
Threat-model an AI development workflow
Map assets, trust boundaries, and possible failures. Select controls and tests for a specific development scenario.