This is a free preview of a subscribers-only post.
If you’ve been following Every, you probably know Claudie, the always-on AI chief of staff for our consulting team. We’ve written about what she does and how we onboarded her, how head of consulting Natalia Quintero manages her, and how her responsibilities have grown.
What we haven’t shared in as much detail is how we decide what she shouldn’t be allowed to do.
When we first built Claudie, we deliberately gave her broad access. It was the fastest way to understand what an agent like her could do. Once we had a clearer picture, we removed access where the risks outweighed the benefits.
The process taught us that agent security isn’t a separate checklist you complete after the agent works. Every new restriction comes with a tradeoff: It may make Claudie safer, but it may also prevent her from doing useful work. Limit access to an inbox and there’s less sensitive information to see, but you also change the job the agent can perform. Block a class of commands and you remove a threat, but perhaps a useful workflow along with it.
Claudie and I wrote up the starter framework we currently use to make those tradeoffs. It’s an early attempt to organize what we’re learning—not a definitive security standard. It lays out four layers of protection that can back one another up. We use them to identify weaknesses in Claudie’s setup, test our assumptions, and decide what to improve next.
The full guide is available to paid and All Access members. It reflects our current thinking, which is still evolving as we encounter new threats and learn where the framework falls short. It also includes a copy-and-paste prompt members can use as a starting point for auditing their own setup.
Nityesh Agarwal is a senior applied AI engineer at Every Consulting, where he builds and maintains Claudie and other automations. You can follow him on X at @nityeshaga.
To read more essays like this, subscribe to Every, and follow us on X at @every and on LinkedIn.
Everyone’s a builder now. Every All Access gets you the full membership plus the Builder Pack—$9,000+ in credits for the tools we build with.
What is included in a subscription?
Daily insights from AI pioneers + early access to powerful AI tools
Front-row access to the future of AI
In-depth reviews of new models on release day
Playbooks and guides for putting AI to work
Prompts and use cases for builders
Bundle of AI software