Part IV: Untrusted instructions and excess authority

Untrusted text can influence model output, while document access, action authority, and execution remain separate security decisions.

A document may be relevant to an employee question and still contain instructions from an attacker. Chapter 10 examines that influence on model output. Chapter 11 checks which information the user and each recipient may receive. Chapter 12 follows a resulting action request through service authorization, and Chapter 13 examines the environment in which an allowed action runs. Each decision uses different facts: the source of text, current access rights, permission for a specific operation, or the limits of its execution environment.

A titled technical map follows user requests, documents, email or web pages, tool results, and memory through Chapter 10 data and instructions, Chapter 11 retrieved context, Chapter 12 agent actions, and Chapter 13 agent environments. Distinct boundaries separate the organization, document sources, model provider, action authority, and execution environment. Lower strips list audit fields, units, and risks.
Figure 1: Four decisions separate untrusted influence from authority. Chapter 10 identifies data and instruction sources. Chapter 11 applies current access and disclosure checks to retrieved context. Chapter 12 follows an attempted operation through structural validation, current policy, destination and operation checks, and human approval when policy requires it. Checking format does not establish intent or permission. Retry protection can suppress duplicates only under the receiving service’s idempotency contract and does not grant authority. Chapter 13 limits the environment in which an allowed action runs.

Chapters in this part

  • Indirect prompt injection: Untrusted source text can influence model output. Protection depends on how the application interprets that output, what data it accepts, and which resulting actions and information transfers the receiving services permit.
  • Retrieval access and disclosure: Retrieval controls determine which records may reach the employee, model provider, and other recipients, including after permissions or stored copies change.
  • Agent action authorization: Action authorization keeps model-generated proposals separate from user, service, and policy decisions that permit consequential changes.
  • Limits on agent execution: Browser sessions and coding workspaces give agents access to files, credentials, and services, so execution limits and checks on each result must match the authorized task.