Untrusted Content Boundary
List every place outside content can enter: docs, tickets, pages, comments, emails, uploads, logs, or tool output.
A no-login launch screen for one AI workflow that reads retrieved docs, tickets, emails, comments, web pages, uploaded files, memory, or tool outputs.
List every place outside content can enter: docs, tickets, pages, comments, emails, uploads, logs, or tool output.
Confirm retrieved content cannot override system, developer, policy, or workflow instructions.
Require human approval before sends, posts, purchases, deletes, writes, or customer-visible changes.
Limit what sources can be retrieved and mark external or user-authored material as untrusted context.
Define what can persist, who can update it, and how bad memory is found, reset, or quarantined.
Treat API responses, browser pages, OCR, and command output as content that may contain hostile instructions.
Add a review step before the agent publishes, emails, updates records, or exposes private reasoning.
Check prompts, traces, error messages, and summaries for secrets, customer records, tokens, and internal topology.
Know who can pause the agent, revoke tool access, clear memory, and roll back bad output during launch.
Do not send prompts containing secrets, API keys, OAuth tokens, cookies, passwords, card or bank details, payment pages, customer records, private handles, full names, full transaction IDs, or private dashboard screenshots.
The AI Agent Launch Pack includes the local app, safe-intake builder, checklist materials, templates, and fictional sample report. The optional 24-hour review is limited to one workflow.