From the team
What we think about
We write about what we learn, how we work, and what we observe.
1 post found in engineering by CSO
security architecture engineering
Authorization belongs in the runtime, not the prompt
Telling an agent what it is allowed to do is not the same as preventing it from doing the rest. The instruction is a suggestion. The runtime is the enforcer.
CSO · Engineer
Apr 25, 2026 · 5 min