assurance · Level 2
Deploy AI agents without losing control
The plain-English companion to Threat-model an agent and its tool boundary: four controls anyone can put in place, no code required.

Start with the essentials
The short answer
In April 2026 a coding agent with excessive permissions deleted a production database and its backups because nobody had limited what it could touch. The fix does not require writing code. Give an agent only the access a task genuinely needs, write down what it must never do without a person present, require sign-off above a set risk level, and keep a plain log of what it actually did.
What you will learn
- You will be able to explain, in plain English, why an agent with broad permissions is dangerous even when it makes an honest mistake rather than acting with intent.
- You will be able to write a least-privilege permission list for an agent you actually use or are considering, narrowed to what its current task needs.
- You will be able to write a short, specific list of actions an agent must never take without a person present.
- You will be able to set a concrete human-approval threshold: what triggers required sign-off, and who actually gives it.
- You will be able to set up a visible log of what an agent actually did, using a document or spreadsheet you already have.
- You will know the difference between preventing a mistake before it happens and being able to see it after it happened, and why an agent you deploy needs both.
Who it is for
Anyone who uses, manages, or is considering deploying an AI agent, coding assistant or automation tool, at work or in a small business, with no technical background needed. If you can use a spreadsheet and a settings menu, you can do every exercise in this workbook.
Before you start
- None beyond curiosity. It helps to have read What is an AI agent? Agentic AI explained first, which explains what an agent actually is and the levels of autonomy it can have.
Keep learning
The complete workbook
This workbook is the plain-English companion to Threat-model an agent and its tool boundary: the same four controls, without the code. You will learn what actually went wrong when a coding agent with excessive permissions deleted a production database and its backups in April 2026, then build your own version of the fix: scoped permissions, a written list of what an agent may never do alone, a clear approval threshold and a visible log. Every exercise uses a tool you already have, a document, a spreadsheet, a settings screen, never a line of code.
- 01What happened when nobody set a limitIn the workbook · 1 exercise
Understanding exactly what went wrong in one real incident is the fastest way to understand what to build instead.
- 02Give it only what the task needs: least-privilege permissionsIn the workbook · 1 exercise
Most agent permissions are set once, for convenience, and never narrowed again. Least privilege means giving an agent exactly the access its current task needs, and taking that access away once the task is done.
- 03Write down what it may never do aloneIn the workbook · 1 exercise
Some actions are too consequential to leave to an agent's judgement, however good that judgement usually is. This chapter builds a short, specific list of exactly which ones, before you need it.
- 04Set a human-approval thresholdIn the workbook · 1 exercise
Not every action needs a person watching, and not every action can be left to run alone. A threshold decides which is which, before the agent ever has to choose.
- 05Keep a visible log of what it actually didIn the workbook · 1 exercise
Permissions and thresholds try to prevent a problem before it happens. A log is what lets you see, after the fact, exactly what an agent did, and it is the control most often skipped.
- 06What you can do nowIn the workbook · Reading
Four controls, none of them code. Here is what changes because you did this, and where to go to prove it.
Also inside: a 7-point checklist, a glossary of 12 terms and 12 questions and answers to test yourself. 5 hands-on exercises, each with a worked answer at the back where the workbook gives one.
No login, no card, no account. Before the download we ask you to follow Mickai (two quick links). Free to download and use for personal learning, study groups and inside your own team. Please do not resell the workbooks or republish them as your own. Link people to trust-agent.ai instead.
Test yourself
Questions and answers
What actually happened in the April 2026 incident?
A coding agent had permissions wider than its task needed inside a real production environment. During a session it deleted a live production database and the backups stored alongside it, with no required approval step and nobody watching closely enough to stop it.
Was the agent being malicious?
No. A coding agent does not want anything. It follows instructions and can take a destructive path by mistake. The failure was in what it was allowed to reach and the missing check before an irreversible action, not bad intent.
What are the four controls this workbook teaches?
Least-privilege permissions, a written list of what an agent may never do unsupervised, a human-approval threshold above a set risk level, and a visible log of what it actually did.
What does least privilege actually mean for an agent?
Giving an agent only the access its current task genuinely needs, and removing that access again once the task is done, rather than granting broad access once for convenience.
Why is "just in case" access risky?
It sits unused most of the time, so nobody notices it, until the agent makes a mistake and that unused access turns a small error into a large, sometimes irreversible one, exactly what happened when a bug-fixing agent still had permission to touch a production database.
How is a never-without-a-person list different from a permission list?
A permission list says what an agent can technically reach. A never-without-a-person list says which of those reachable actions it must never actually carry out alone, even with the access, because the consequence is too hard to undo.
Why does the never list need to be written down?
A rule that only exists in someone's memory cannot be followed by the agent's owner, checked by anyone else, or handed to whoever manages the agent next. Writing it down turns an intention into an enforceable control.
What is a human-approval threshold?
A specific, written line at which an agent must stop and wait for a named person to approve before continuing, used for actions riskier than routine but not on the never list.
How is a threshold different from the never list?
The never list blocks an action completely, always. A threshold lets a lower-risk version of an action proceed on its own, and only requires sign-off once it crosses a defined line, such as an amount or an irreversible change.
Why must a threshold name an actual person, not just "someone"?
An approval rule with no named, available person becomes either an unplanned delay or a rule people quietly bypass. Naming a real, reachable role is what makes the threshold work in practice.
What does a log actually protect against, if permissions and thresholds already exist?
It does not prevent a mistake. It lets you find out what happened afterwards, reconstruct the decision, and catch a threshold that was crossed without approval, instead of discovering damage with no record of how it happened.
Do I need special software to keep this kind of log?
No. A shared spreadsheet or running document recording what was asked, what actually happened, when, and who approved it is a real, usable log. What matters is that someone checks it, not which tool holds it.
When you have finished
Get your certificate of completion
Type your name and download a certificate for this workbook as a PDF, ready to print or to add to LinkedIn. It is made on your own device, so your name is never sent to us. It is a self-declared certificate, not an accredited qualification.
Learn the language
Key terms
- Least privilege
- The principle of giving a user, program or agent only the access its current task needs, and no more.
- Permission
- A specific thing an agent is allowed to access or do, such as reading a file, sending an email or editing a record.
- Blast radius
- How much damage an agent could do if it acted wrongly, based on everything it can currently reach.
- Irreversible action
- Something that cannot easily be undone once it happens, such as deleting data, sending a message or making a payment.
- Never list
- A written list of specific actions an agent must never take without a person present, regardless of what its other permissions allow.
- Approval threshold
- A defined line above which an agent must stop and wait for a named person's sign-off before continuing.
6 of the workbook's 12 terms. The complete glossary is in the workbook.
Follow the evidence
Sources and checks
Facts last checked: .
These workbooks use AI assistance. See how the workbooks are made.
- LLM06:2025 Excessive AgencyOWASP GenAI Security Project
- Authorization Cheat SheetOWASP
- AI Risk Management FrameworkNational Institute of Standards and Technology (NIST)
Created by Mickarle Wagstaff-Irons - Micky Irons with the Mickai team. Published by Mickai LTD. Last updated 29 September 2026.
NextKeep going
Where to go next
Recommended for you
Threat-model an agent and its tool boundary
Map an agent tool boundary and test a local gateway for identity, ownership, exact-action approval, expiry, replay and stale writes using fictional notes.
Recommended for you
AI governance: risk registers, evidence and human accountability
Govern an AI system without being an engineer: map hazards, score and evidence them, name owners and stop rights, make oversight real, and check the register with tested code.
Recommended for you
Prompt injection: threat analysis and defensive testing
Learn why prompt injection happens, analyse the harm it can do, and measure which defences work with a harmless offline Python lab that uses fake canary secrets.