Blast-radius engineering: scoped credentials, allowlists, dry-runs and irreversibility gates.
01
01
Understand the problem
sandboxingleast-privilegesecurityagents
02
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Stuck? AI Nudge Available
Get a conceptual hint to guide your logic without spoiling the final implementation.
03
03
Study the solution
The solution is waiting
Give it an honest attempt first — then compare your thinking with the full walkthrough.
04
04
Read the code
Tool registry with permission tiers
const registry: ToolPolicy[] = [
{ tool: readFile, tier: "read", scope: { paths: ["/workspace/**"] } },
{ tool: runTests, tier: "read", sandbox: { net: "none", cpuMs: 60_000 } },
{ tool: writeFile, tier: "write", scope: { paths: ["/workspace/**"] } },
{ tool: gitPush, tier: "irreversible" }, // human approval
{ tool: sendEmail, tier: "irreversible" },
];
async function authorize(call: ToolCall, session: Session) {
const p = registry.find((r) => r.tool.name === call.name);
if (!p) throw deny("unknown tool");
if (!inScope(call.input, p.scope)) throw deny("out of scope");
if (p.tier === "irreversible") await requireHumanApproval(call, session);
}05
05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.