Topic 9: Defences that work, and one that does not
8 min read·22 Sept 2026
You have now seen each defence stop a specific attack: the approval gate on writes and outbound calls, pinning on rug pulls, namespacing on shadowing, sandboxing on secret leakage. This part adds the one central control we have not built yet, a policy gateway, and then shows one popular idea that is not a defence, so you do not lean on it.
Least privilege, restated as a checklist
Least privilege means each tool, and each session, gets the smallest capability that does the job. Applied to the notes assistant:
- The model gets
search_notes(read-only) freely andcreate_note(write) only behind approval. That isneeds_approvalplusdeny_allfrom Module 6. - A session that only needs to answer questions should not load a write tool or an outbound tool at all. The best-controlled outbound call is the one that is not present.
- Downstream credentials in a proxy are scoped as narrowly as the task, per Part 6.
Least privilege is the cheapest defence because it removes outcomes instead of detecting them. Everything else in this part is about the outcomes you cannot remove.