AI Coding-Agent Guardrails

Design layered guardrails for AI coding agents: permissions, sandboxes, secret and network controls, Git and CI gates, hooks, logging and incident response.

Start course →

Syllabus

The Threat Model

  1. Why Guardrails
  2. What Can Go Wrong
  3. Trust Boundaries
  4. Defence in Depth

Permissions and Command Policy

  1. Allow, Ask, Deny
  2. Why Prefix Allowlists Fail
  3. A Parsed Allowlist
  4. Allowed Commands Can Still Run Code

Filesystem and Sandbox

  1. Path Guards and Symlinks
  2. Containers and Dev Environments
  3. Protected Paths

Secrets and Network

  1. Keeping Secrets Out of Reach
  2. Redacting Secrets
  3. Network Egress Allowlists

Git and CI Guardrails

  1. Branches, Never Main
  2. Diff Size and Scope Gates
  3. CI and Review as the Final Authority

Hooks, Policy as Code and Budgets

  1. Pre-Action Hooks
  2. Policy as Code and Managed Settings
  3. Budgets and Rate Limits

Detection and Response

  1. Audit Logging
  2. Red-Teaming Your Guardrails
  3. Incident Response and the Kill Switch

Putting It Together

  1. Case Study: Rolling Out Agents to a Team
  2. Revision: Cheat Sheet and Self-Check