# Defence in Depth — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/en/coding-agent-guardrails/tm-defence-in-depth

> Combine independent layers so one failure does not become an incident.

## Independent layers

Layers should fail independently. If a **command policy** misses a clever command, the **sandbox** has no secrets to steal. If the sandbox has a hole, **network egress rules** stop data leaving. If a bad change slips through, **branch protection and CI** block the merge. If that fails, **audit logs** let you find and undo it. Design so that no single control is the only thing between the agent and disaster.

## The layers, outside in

Read it top to bottom as the path of one risky action: each layer is another chance to stop it.

```text
1. Permission policy      deny / ask / allow per tool and command
2. Hooks                  custom checks before and after actions
3. Sandbox               no secrets, limited files, restricted network
4. Git workflow          agent works on a branch, never on main
5. CI + required review  tests, scanners, human approval before merge
6. Audit + alerts        every action logged; kill switch ready
```

## Test each layer alone

Occasionally disable one layer in a safe environment and see what the others catch. A layer that nobody has ever tested may not work.

**Quiz:** Why use several independent guardrail layers?

- [ ] More layers always run faster
- [x] One failure then does not become an incident
- [ ] A single layer is illegal
- [ ] It removes the need for logs

*Answer:* One failure then does not become an incident. If one control fails, another can still stop or limit the harm.
