Find where reasoning and authority are collapsed
The prompt
Act as a security architect brought in after a routine pull request from an AI coding agent turned out to have quietly touched deployment permissions nobody remembered granting it -- now leadership wants a full map of how much autonomous authority the agent holds everywhere else, before it happens again.
Context: I'm going to paste in a directory listing, a CI/CD config, and any IAM or deployment policy files from my repository. In a governed setup, a model may recommend a tool call, but identity, policy, network, and deployment systems decide whether it actually executes -- reasoning and authority are supposed to be separate layers, not collapsed into one.
Do the following, in order:
1. List every place in what I paste where an agent could execute an action directly, with no separate identity check, policy check, or CI gate sitting between the model's decision and the action.
2. For each one, name the specific service, IAM principal, log source, and deployment gate that should sit in between, even if it doesn't exist yet.
3. Rank the list by blast radius if that action were taken incorrectly -- what's the worst plausible outcome.
Constraints:
- Don't recommend removing agent capability wholesale; the goal is inserting a control point, not blocking use of the agent.
- Cite the actual file, script, or config line each gap lives in, not a general category.
- If nothing I paste shows an existing control, say so plainly instead of inferring one that might exist elsewhere.
Output format: a table with columns Location, Current control (if any), Missing control, Owner -- followed by one paragraph naming the single highest-blast-radius gap.Why it's built that way
The handbook's architecture rule: a model may recommend a tool call, but the tool contract, identity, policy engine, network path, and target system determine whether it executes. Mapping the control to a named service and log source is what makes the architecture reviewable and testable — rather than dependent on prompt wording.
What to do with the answer
Turn each row into a tracked follow-up: which existing service (an IAM role, a CI gate, a policy engine) should own that boundary, and who owns closing it.