Least privilege and prompt injection
Treat all external content as untrusted data and enforce minimum access and action policy outside the model, because instructions inside a document cannot grant themselves authority.
Start with fluent answers and their limits. Finish with bounded agents, visible memory, tests, accountability and portable workflows. No account required.
Treat all external content as untrusted data and enforce minimum access and action policy outside the model, because instructions inside a document cannot grant themselves authority.
Turn desired behavior into repeatable cases, observable grading rules, and release gates that detect both improvement and regression before wider use.
Context is what the model can use now; retrieval selects external material into that context; visible memory is persistent owner-controlled information; fine-tuning changes model parameters through training.
Deploy only a defined use case with a named accountable owner, tested boundaries, monitored outcomes, incident and appeal paths, and authority to pause or roll back.
Portability comes from open, documented, versioned instructions and data; self-hosting adds operational control but also makes the operator responsible for security, updates, backups, recovery, and model limitations.
Each preset expands its prerequisites. Or choose exactly what matters and generate an instruction pack for your own agent.
Understand limits, write clearer briefs, verify claims and protect ordinary data.
Compose this path →Build a bounded, reviewable agent using provenance, examples, memory and tests.
Compose this path →Design least-privilege workflows, evaluations, accountability and rollback.
Compose this path →Scheduled source checks can detect changed primary documentation. They prepare evidence for editorial review; they never turn external text into authority or publish claims automatically.