AI, decoded

How do you decide what information an AI assistant may receive?

Check the task’s data needs, your authorization, and the exact product or provider route’s handling terms. Send only the necessary permitted material. Keep credentials out of prompts, and enforce access in tools and downstream systems; neither a paid plan nor a model name establishes permission to share private information.

· Chain of Thought

Level 2: Using AI well · 2.5 What’s safe to paste

AI SecurityAI Agents

Start with what the task needs

Summarizing a public policy does not require a customer database. Checking a calculation may require amounts and assumptions, but not account credentials. Separate the inputs necessary to do the job from the rest of the material available to the assistant.

Illustrative task: you want a critique of a public help article. Send the article and a concrete review question. Do not attach private support tickets merely because they are in the same project. If ticket examples are needed, obtain the relevant authorization and prepare excerpts whose remaining content is permitted for the chosen destination. Removing names alone may leave identifying or confidential details.

Check the exact destination

Product names and model families can conceal different routes: a consumer application, an enterprise account, a direct API or a third-party gateway. Their data handling can differ. Check the current terms for the exact route and account configuration, including retention, use for training, subprocessors and available controls. A paid subscription alone does not answer those questions.

This is an operational checklist, not a statement that any particular provider meets your organization’s policy. If required terms or permission are unknown, use an already approved destination, reduce the packet to permitted material, or stop that transfer until the owner resolves the gap.

Keep credentials in the execution layer

Ledger CTO Charles Guillemet’s episode 65 warns against giving an agent valuable signing keys. OWASP’s prompt-injection guidance recommends handling privileged functions in code rather than giving the model tokens. The application may need an authorized credential to call a service; the model usually needs the permitted result of that call, not the credential itself.

Input or capabilityDecision to make
Public articleConfirm that attached context is also public or permitted
Internal policy excerptConfirm permission and the exact route’s handling terms
Customer recordEnforce user and tenant access before retrieval
API key or signing secretKeep it outside prompts and review packets
Tool that sends a messageSeparate read access from permission to send

The table organizes decisions; it does not grant access. Read agent identity and permissions for the enforcement layer.

Kapil Chhabra’s discussion in episode 75 separates personal memory from shared institutional context, where an owner reviews changes to business definitions. The context explainer links the transcript discussion. Shared information needs an authority and an access scope; remembering it does not authorize disclosing it to another service.

Retrieval does not grant authority

A retrieved document can contain instructions to export data, change a recipient or reveal a secret. Treat that text as content to analyze, not as permission to expand the task. The authorized user’s scope and the application’s policy must still govern the tool call.

Check yourself

You sanitized a ticket by removing the customer’s name, but it still includes a private contract and a distinctive incident. Is the packet now safe for an unapproved free service? You have not established that. Inspect the remaining content and the destination’s eligibility. Minimize first, then check permission and terms for what remains.

Go deeper

From the conversation

This explainer is drawn from these episodes — each carries its full transcript.

Concepts in this explainer

Generative AITokenization