Telling an AI agent 'don't touch production' isn't a safety measure

Innowise_ · reddit · 2026-10-06

A developer argues agent safety belongs at the permission layer, not the prompt layer: irreversible actions like payments, data deletion, and customer emails should require human confirmation rather than trusting the agent to remember instructions. The subtler risk is downstream side effects of valid actions — e.g., an agent moving a meeting also updates the CRM deal date, silently changing the sales forecast. The team now maps what an agent can trigger downstream, not just the tools it calls directly.

Original post →

More from coding & agent

coding & agent channel →