Skip to content

Answers

How do I stop an AI agent sending data where it should not?

Decide every outbound action by where it goes, and keep personal data out of the agent’s hands until a release is allowed. Immiscible refuses destinations a rule does not name, releases personal data from a vault only to allowed recipients, and judges actions on what the agent has read.

Decide every outbound action by its destination, and keep personal data out of the agent until a release is allowed. With Immiscible, a rule lists the domains an agent may reach and the recipients it may give personal data to; anything else is refused (recipient_not_allowed) or asked about, and once the agent has read untrusted content (an email, a web page, a tool’s output) its next outbound action is judged with that in mind.

#How do I set it up?

  1. Name the destinations. An action rule with domains such as github.com and your own; with a list, everywhere else is closed, or set newDomain: approve to ask instead. See action mandates.
  2. Keep personal data in the vault. The agent asks with request_personal_data (MCP) or requestData (SDK) naming the fields, the recipient and the purpose; on allow the values come back once, for that recipient. Restricted fields (passport, national ID, bank account, card, health) always need a person unless the rule names that field and that recipient. See data mandates and the vault.
  3. Gate the routes data can leave by: the Claude Code hook for shell commands and web requests, the MCP proxy for tools, and the gateway for model traffic, which records what entered the agent’s context.

#What is least privilege for an AI agent?

The agent holds only an agent key, which can ask but never approve, widen a rule or lift a freeze. Its authority is a set of written rules, each naming what it may do and where; with no rule for an action, the answer is deny. It starts as an intern and earns more on evidence, with sign-off from people who carry the risk; see autonomy tiers.

#Is this a policy engine for agent authorisation?

In effect, yes, with the parts an agent needs around the policy: a person asked at the right moment, a kill switch, signed receipts and a ledger. The rules are signed objects written for people to read, not a policy language you program; if you already run a general authorisation engine for your application, Immiscible sits beside it for what agents do.

#What does it not do?

  • It is not data loss prevention: it does not scan file contents or network traffic. It decides the actions it is asked about and the routes it stands in front of.
  • It cannot see a channel the agent has without it, such as a credential in its environment. Take those away.
  • Provenance an agent declares is the agent’s word. The gateway and the proxy also observe what entered the session, and when the two disagree a person decides (provenance_mismatch); without the gateway or the proxy, only the declared word is there.