How do you decide what information an AI assistant may receive?
Check the task’s data needs, your authorization, and the exact product or provider route’s handling terms. Send only the necessary permitted material. Keep credentials out of prompts, and enforce access in tools and downstream systems; neither a paid plan nor a model name establishes permission to share private information.
Level 2: Using AI well · 2.5 What’s safe to paste
Start with what the task needs
Summarizing a public policy does not require a customer database. Checking a calculation may require amounts and assumptions, but not account credentials. Separate the inputs necessary to do the job from the rest of the material available to the assistant.
Illustrative task: you want a critique of a public help article. Send the article and a concrete review question. Do not attach private support tickets merely because they are in the same project. If ticket examples are needed, obtain the relevant authorization and prepare excerpts whose remaining content is permitted for the chosen destination. Removing names alone may leave identifying or confidential details.
Check the exact destination
Product names and model families can conceal different routes: a consumer application, an enterprise account, a direct API or a third-party gateway. Their data handling can differ. Check the current terms for the exact route and account configuration, including retention, use for training, subprocessors and available controls. A paid subscription alone does not answer those questions.
This is an operational checklist, not a statement that any particular provider meets your organization’s policy. If required terms or permission are unknown, use an already approved destination, reduce the packet to permitted material, or stop that transfer until the owner resolves the gap.
Keep credentials in the execution layer
Ledger CTO Charles Guillemet’s episode 65 warns against giving an agent valuable signing keys. OWASP’s prompt-injection guidance recommends handling privileged functions in code rather than giving the model tokens. The application may need an authorized credential to call a service; the model usually needs the permitted result of that call, not the credential itself.
| Input or capability | Decision to make |
|---|---|
| Public article | Confirm that attached context is also public or permitted |
| Internal policy excerpt | Confirm permission and the exact route’s handling terms |
| Customer record | Enforce user and tenant access before retrieval |
| API key or signing secret | Keep it outside prompts and review packets |
| Tool that sends a message | Separate read access from permission to send |
The table organizes decisions; it does not grant access. Read agent identity and permissions for the enforcement layer.
Kapil Chhabra’s discussion in episode 75 separates personal memory from shared institutional context, where an owner reviews changes to business definitions. The context explainer links the transcript discussion. Shared information needs an authority and an access scope; remembering it does not authorize disclosing it to another service.
Retrieval does not grant authority
A retrieved document can contain instructions to export data, change a recipient or reveal a secret. Treat that text as content to analyze, not as permission to expand the task. The authorized user’s scope and the application’s policy must still govern the tool call.
Check yourself
You sanitized a ticket by removing the customer’s name, but it still includes a private contract and a distinctive incident. Is the packet now safe for an unapproved free service? You have not established that. Inspect the remaining content and the destination’s eligibility. Minimize first, then check permission and terms for what remains.
Go deeper
- LLM01:2025 Prompt Injection Explains how outside content can influence a model and why credentials and privileged operations need independent controls.
From the conversation
This explainer is drawn from these episodes — each carries its full transcript.