Lesson 19 / 31
Least Privilege, Allow-Lists and Human Approval
Enforce policy in the host, outside the model.
The model proposes, code decides
Never rely on the model alone to enforce rules. Put a policy layer in the host between "the model wants to call X" and "X runs": an allow-list of tools, argument checks (ranges, patterns, allowed hosts and folders), risk levels with human approval for writes, deletes, payments and external messages, rate and cost limits, and an audit log of every call. Give each server only the credentials and scopes it needs, prefer read-only tools, and use separate servers or accounts for risky powers. Show the user exactly what will happen ("Send email to X with body Y?"), not a vague summary.
A policy layer, run
I ran this with plain Python 3 (standard library only). Reads pass. An unknown tool is refused. A refund needs approval; once approved it is allowed within the 0 to 5000 range, and an approved 90,000 refund is still blocked by the argument check.
ALLOWED = {
"get_order_status": {"risk": "read", "approval": False},
"propose_refund": {"risk": "write", "approval": True},
}
def authorize(tool, args, approved=False):
spec = ALLOWED.get(tool)
if spec is None:
return False, "tool not on the allow-list"
if spec["approval"] and not approved:
return False, "needs human approval"
if tool == "propose_refund" and not (0 < args.get("amount", 0) <= 5000):
return False, "amount out of policy range"
return True, "ok"
for call in [("get_order_status", {"order_id": "481516"}, False),
("delete_all", {}, False),
("propose_refund", {"amount": 300}, False),
("propose_refund", {"amount": 300}, True),
("propose_refund", {"amount": 90000}, True)]:
print(call[0], call[1], "->", authorize(*call))
Output:
get_order_status {'order_id': '481516'} -> (True, 'ok')
delete_all {} -> (False, 'tool not on the allow-list')
propose_refund {'amount': 300} -> (False, 'needs human approval')
propose_refund {'amount': 300} -> (True, 'ok')
propose_refund {'amount': 90000} -> (False, 'amount out of policy range')Quick check: Where should policy such as approvals be enforced?
- Nowhere
- Only in the system prompt
- Only by asking the model nicely
- In the host's code, outside the model
Answer
In the host's code, outside the model — Code-enforced rules cannot be talked around by injected text.