Answers
How do I stop an AI agent sending data where it should not?
Decide every outbound action by where it goes, and keep personal data out of the agent’s hands until a release is allowed. Immiscible refuses destinations a rule does not name, releases personal data from a vault only to allowed recipients, and judges actions on what the agent has read.
Decide every outbound action by its destination, and keep personal data out of the agent until a release is allowed. With Immiscible, a rule lists the domains an agent may reach and the recipients it may give personal data to; anything else is refused (recipient_not_allowed) or asked about, and once the agent has read untrusted content (an email, a web page, a tool’s output) its next outbound action is judged with that in mind.
#How do I set it up?
- Name the destinations. An action rule with
domainssuch asgithub.comand your own; with a list, everywhere else is closed, or setnewDomain: approveto ask instead. See action mandates. - Keep personal data in the vault. The agent asks with
request_personal_data(MCP) orrequestData(SDK) naming the fields, the recipient and the purpose; on allow the values come back once, for that recipient. Restricted fields (passport, national ID, bank account, card, health) always need a person unless the rule names that field and that recipient. See data mandates and the vault. - Gate the routes data can leave by: the Claude Code hook for shell commands and web requests, the MCP proxy for tools, and the gateway for model traffic, which records what entered the agent’s context.
#What is least privilege for an AI agent?
The agent holds only an agent key, which can ask but never approve, widen a rule or lift a freeze. Its authority is a set of written rules, each naming what it may do and where; with no rule for an action, the answer is deny. It starts as an intern and earns more on evidence, with sign-off from people who carry the risk; see autonomy tiers.
#Is this a policy engine for agent authorisation?
In effect, yes, with the parts an agent needs around the policy: a person asked at the right moment, a kill switch, signed receipts and a ledger. The rules are signed objects written for people to read, not a policy language you program; if you already run a general authorisation engine for your application, Immiscible sits beside it for what agents do.
#What does it not do?
- It is not data loss prevention: it does not scan file contents or network traffic. It decides the actions it is asked about and the routes it stands in front of.
- It cannot see a channel the agent has without it, such as a credential in its environment. Take those away.
- Provenance an agent declares is the agent’s word. The gateway and the proxy also observe what entered the session, and when the two disagree a person decides (
provenance_mismatch); without the gateway or the proxy, only the declared word is there.