Lesson 4 / 25
Defence in Depth
Combine independent layers so one failure does not become an incident.
Independent layers
Layers should fail independently. If a command policy misses a clever command, the sandbox has no secrets to steal. If the sandbox has a hole, network egress rules stop data leaving. If a bad change slips through, branch protection and CI block the merge. If that fails, audit logs let you find and undo it. Design so that no single control is the only thing between the agent and disaster.
The layers, outside in
Read it top to bottom as the path of one risky action: each layer is another chance to stop it.
1. Permission policy deny / ask / allow per tool and command
2. Hooks custom checks before and after actions
3. Sandbox no secrets, limited files, restricted network
4. Git workflow agent works on a branch, never on main
5. CI + required review tests, scanners, human approval before merge
6. Audit + alerts every action logged; kill switch readyTest each layer alone
Occasionally disable one layer in a safe environment and see what the others catch. A layer that nobody has ever tested may not work.
Quick check: Why use several independent guardrail layers?
- More layers always run faster
- One failure then does not become an incident
- A single layer is illegal
- It removes the need for logs
Answer
One failure then does not become an incident — If one control fails, another can still stop or limit the harm.