Read the document. Don’t obey the document.
A supplier document contains instructions to retrieve confidential internal records and send them to an external destination.
All use casesMake the boundary explicit.
Treat document text as untrusted. Restrict retrieval to assigned sources, refuse model-requested permission expansion and evaluate outbound destinations against data classification and approved purpose.
The assistant can summarize the supplier information while the unrelated private-data read and export are denied on controlled paths.
Keep source content below instruction authority.
Evidence to inspect
The retrieved document's provenance, the agent's original task, requested tool action and any attempted access to a protected resource.
Control to apply
Treat document instructions as untrusted data and deny an out-of-scope action at the qualified operation boundary.
Inspect the decision.
Summarize the supplier document from its permitted source.
Ready to evaluate
No external action
Select a variation and inspect the local example. This demonstration does not call a model or connect to a business system.
Do not rely only on recognizing a malicious phrase. Resource and destination restrictions must remain effective when the wording changes.
The controls behind the workflow.
Explore the capabilities that compose around this task, rather than treating each step as a separate product.
Related ways to use DriftGate.
Help with the appointment. Respect the patient-record boundary.
An appointment assistant is asked to reveal another patient’s information or perform an out-of-scope clinical change.
Explain the policy. Don’t invent the policy.
An assistant confidently describes a refund exception that conflicts with the actual policy.