# How do I stop an AI agent sending data where it should not?

> Decide every outbound action by where it goes, and keep personal data out of the agent's hands until a release is allowed. Immiscible refuses destinations a rule does not name, releases personal data from a vault only to allowed recipients, and judges actions on what the agent has read.

Source: https://immiscible.fly.dev/docs/answers/agent-data-exfiltration

Decide every outbound action by its destination, and keep personal data out of the agent until a release is allowed. With Immiscible, a rule lists the domains an agent may reach and the recipients it may give personal data to; anything else is refused (`recipient_not_allowed`) or asked about, and once the agent has read untrusted content (an email, a web page, a tool's output) its next outbound action is judged with that in mind.

## How do I set it up?

1. **Name the destinations.** An action rule with `domains` such as `github.com` and your own; with a list, everywhere else is closed, or set `newDomain: approve` to ask instead. See [action mandates](https://immiscible.fly.dev/docs/concepts/mandates.md#action-mandates).
2. **Keep personal data in the vault.** The agent asks with `request_personal_data` (MCP) or `requestData` (SDK) naming the fields, the recipient and the purpose; on allow the values come back once, for that recipient. Restricted fields (passport, national ID, bank account, card, health) always need a person unless the rule names that field and that recipient. See [data mandates and the vault](https://immiscible.fly.dev/docs/concepts/mandates.md#data-mandates-and-the-vault).
3. **Gate the routes data can leave by**: the [Claude Code hook](https://immiscible.fly.dev/docs/answers/claude-code-block-commands.md) for shell commands and web requests, the [MCP proxy](https://immiscible.fly.dev/docs/answers/mcp-tool-permissions.md) for tools, and the [gateway](https://immiscible.fly.dev/docs/guides/gateway.md) for model traffic, which records what entered the agent's context.

## What is least privilege for an AI agent?

The agent holds only an agent key, which can ask but never approve, widen a rule or lift a freeze. Its authority is a set of written rules, each naming what it may do and where; with no rule for an action, the answer is `deny`. It starts as an intern and earns more on evidence, with sign-off from people who carry the risk; see [autonomy tiers](https://immiscible.fly.dev/docs/concepts/autonomy-tiers.md).

## Is this a policy engine for agent authorisation?

In effect, yes, with the parts an agent needs around the policy: a person asked at the right moment, a kill switch, signed receipts and a ledger. The rules are signed objects written for people to read, not a policy language you program; if you already run a general authorisation engine for your application, Immiscible sits beside it for what agents do.

## What does it not do?

- It is not data loss prevention: it does not scan file contents or network traffic. It decides the actions it is asked about and the routes it stands in front of.
- It cannot see a channel the agent has without it, such as a credential in its environment. Take those away.
- Provenance an agent declares is the agent's word. The gateway and the proxy also observe what entered the session, and when the two disagree a person decides (`provenance_mismatch`); without the gateway or the proxy, only the declared word is there.
