Lesson 4 / 25

Defence in Depth

Combine independent layers so one failure does not become an incident.

Independent layers

Layers should fail independently. If a command policy misses a clever command, the sandbox has no secrets to steal. If the sandbox has a hole, network egress rules stop data leaving. If a bad change slips through, branch protection and CI block the merge. If that fails, audit logs let you find and undo it. Design so that no single control is the only thing between the agent and disaster.

The layers, outside in

Read it top to bottom as the path of one risky action: each layer is another chance to stop it.

1. Permission policy      deny / ask / allow per tool and command
2. Hooks                  custom checks before and after actions
3. Sandbox               no secrets, limited files, restricted network
4. Git workflow          agent works on a branch, never on main
5. CI + required review  tests, scanners, human approval before merge
6. Audit + alerts        every action logged; kill switch ready

Test each layer alone

Occasionally disable one layer in a safe environment and see what the others catch. A layer that nobody has ever tested may not work.

Quick check: Why use several independent guardrail layers?

  • More layers always run faster
  • One failure then does not become an incident
  • A single layer is illegal
  • It removes the need for logs
Answer

One failure then does not become an incident — If one control fails, another can still stop or limit the harm.