Security & data handling

Use the minimum access needed to produce trustworthy evidence.

Every evaluation starts by reducing exposure: narrow the workflow, prefer non-production environments, limit the access window, and agree how artifacts are handled before testing begins.

Wide crystalline structure representing bounded data access

Default posture

Deliberate boundaries before execution.

01

Staging first

Use a demo, sandbox, or staging environment whenever it can reproduce the relevant workflow and system behavior.

02

Least necessary access

Request only the interface, role, and time window required for the agreed evaluation scope.

03

Synthetic or sanitized data

Prefer fictional, masked, or purpose-built records unless representative data is essential and separately agreed.

04

Separated artifacts

Keep engagement evidence bounded to the evaluation and avoid mixing it with unrelated customer or operating data.

Engagement controls

Security questions are resolved during scoping—not after access arrives.

01

Environment

Confirm which system is in scope, whether it is isolated from production, and what actions the evaluation account may perform.

02

Data

Identify prohibited data, acceptable fixtures, necessary redactions, and what may appear in captured evidence.

03

Access

Define approved users, credential method, permissions, access period, and the process for revocation.

04

Artifacts

Agree what is captured, where it is delivered, who may receive it, and when working materials should be removed.

What to prepare

A lightweight security review for a bounded sprint.

The exact questions depend on the agent, tools, and workflow. These are the minimum topics a design partner should expect to resolve.

01

System map

The agent surface, tools it can call, authoritative systems, and the environment available for testing.

02

Access owner

A named person who can provision, constrain, rotate, and revoke access during the engagement.

03

Data rules

Which data classifications may be used, what must be sanitized, and what must never be shared.

Security review

Discuss the boundary before sharing access.

Include your environment, data restrictions, and review requirements in the application so feasibility can be assessed early.