Examples and incident analysis
See how the controls would work in realistic situations, and read the external research behind two failure analyses. No customer deployment story is represented here.
Browse workflowsThree evidence types have different jobs.
- Example workflow
- A fictional task with a proposed control path and intended result. It explains a decision, not a measured deployment outcome.
- Incident analysis
- An attributed public researcher report, followed by DriftGate's control-design interpretation. The event was not a DriftGate customer incident.
- Customer case study
- A real customer's work and verified results would need customer authorization and evidence. None is presented on this website.
Follow the decision all the way to the result.
The environment example separates a portable approved setup from personal credentials. The refund example binds approval to the actual amount, order and destination. The prompt-injection example treats retrieved material as data, not authority. The learning example keeps a proven fix separate from a private conversation.
Each workflow labels its local simulation and points to connected capabilities. Its intended result remains a design goal until tested in a qualified system.
Four ways to inspect the model
Fictional example workflows · local simulations
A working environment should travel. Credentials should not.
A developer joins a payments project while also working on a public marketing website. The projects need different tools, instructions, accounts and restrictions.
Resolve the complaint. Control the refund.
A fictional food-delivery platform uses an assistant to resolve a missing order. A customer requests more than the eligible refund or asks for a different payment destination.
Read the document. Don’t obey the document.
A supplier document contains instructions to retrieve confidential internal records and send them to an external destination.
Share the proven fix. Not the private conversation.
One agent repeatedly retries uncertain actions. A fix would help the team, but the original context includes private customer information.
Public reports help frame the boundary.
The linked Invariant report describes a controlled demonstration involving untrusted issue content and access to a private repository. The linked Lasso report examines a shopping assistant moving away from its intended purpose. Read the original sources for their facts; the site uses them to explain why source content, task scope and action authority must stay distinct.
Incident analysis from public research
Read the original report and our separate control-design interpretation. These are not customer results.