The prompt is not an authorization rule.
Zenity Labs reported an Agentforce attack that began with instructions hidden in a public lead record. When an employee later asked the agent to review leads, the injected text directed the same subagent to query account data and place values in an external hostname. Zenity says Salesforce fixed the reported URL-redaction bypass.[1]
The important boundary sat earlier in the route. The subagent could read both leads and accounts. The injected instruction did not need a new privilege. It used authority the agent already had. A better output filter can close that specific exit. It does not narrow the records available to the task.
Do not ask the model to remember the fence. Put the fence where the tool executes.
Short-lived and task-scoped answer different questions.
A token can expire in one minute and still allow too much during that minute. GitHub's current App installation tokens keep repository scope, permissions, and a one-hour expiry while changing to a longer stateless format. GitHub tells integrators to treat tokens as opaque strings and update storage, gateways, and redaction rules that assume the old length.[2] That is a transport and validation migration. It is not a claim that the token now carries narrower task intent.
OAuth Rich Authorization Requests shows what finer authorization can look like. Its authorization_details parameter can describe actions, locations, amounts, and named recipients instead of relying on one coarse scope string.[3] The agent version of that idea needs the resource server or tool to enforce the details on every call.
The valet-key proposal is real, but the standard is not finished.
Tenuo proposes signed warrants that name capabilities, arguments, a holder, and an expiry. A holder can pass an equal or narrower grant to another agent. The receiving tool verifies the chain and rejects a call outside the grant. The project publishes an Apache-2.0 implementation for Python and TypeScript.[4]
We installed the released Python package at version 0.3.2 and ran a local smoke check. A warrant for query_records on Lead/LEAD-42 allowed that exact request. The same warrant denied Account/* with ConstraintViolation. This proves the narrow example, not production key custody, revocation, framework integration, policy completeness, or resistance to every bypass.
The related Attenuating Authorization Tokens document is an individual Internet-Draft. The IETF page says it is not endorsed by the IETF and has no formal standing in the standards process.[5] Treat it as a design proposal under review, not a finished standard.
Cut the smallest useful key.
CISA and international partners advise teams to avoid broad or unrestricted agent access, especially around sensitive data and critical systems.[6] Turn that advice into five fields the enforcement point can read: task, resource, action, holder, and expiry.
Start with one common task. Resolve vague language such as "latest lead" to a stable record before minting the grant. Permit one action on that record. Bind the grant to the expected caller. Keep the life short enough for the task. Log the allow or denial without logging the secret itself.