Skip to content
Dare Omotosho
ArticlesCloudNewcomer

The second column nobody draws

Most teams running an agent in production have already done the hard part. Somebody worked out which systems the thing may reach, wrote that down, and put a name against it. Plenty of teams never get that far.

It answers one question: what can this agent do. There is a second question in the same wall, and it rarely has an owner. Who is allowed to talk to it.

Words, and everything around them

Think about a phone ringing in an office.

Two things arrive on that line. There are the words, which is the part anybody would write down. Then there is everything wrapped around them: which extension it came in on, what the voice sounds like, whether you passed that person by the kitchen an hour earlier. Your colleague sorts the finance director from a stranger in about two seconds, and the words are almost never what did it.

An agent has the line and none of the rest of it. Every source reaches it as the same kind of text, at the same volume, carrying nothing about where it has been. That is not gullibility. It is a missing sense.

A label is not a wall

Modern systems do mark where text came from. This part is the system prompt, this came back from a tool, this is the user. The marking is real and it is not nothing.

But a marking is a hint, weighed against everything else the model is weighing. A permission check cannot be talked out of a decision. A hint can.

That matters because of what a permission model is a model of: this actor, these resources, these verbs. Underneath sits an assumption nobody writes down, which is that what the actor wants is fixed and only its reach is in question. With a person, that holds. Nobody reads a support ticket and comes away with new goals. With a model, the goals travel down the same pipe as the data. So the control is not broken. It is a sound lock, fitted to one of the two doors in that wall.

Twenty minutes, one page

Pull up however the agent is configured. On a blank page, put down each source its text arrives from, one to a line. System prompt. Ticket queue. Shared inbox. Indexed documents. Any address it may fetch. The file names.

Then rule a second column, and in it put who can leave words there.

Most rows will name a colleague or a team. One row will say anyone who can email support, and that row is the finding. No specialist was needed to reach it. The page needed to exist.

What you do next is a separate conversation, and it is usually one of two moves. Take a source off the read list, or put a gap between reading and acting. Neither of those is more permissions work.

Where the field is looking

Black Hat USA 2026 lists a talk called Kinetic Prompt Injection on its schedule. That is their programme, not a result of mine, and it is a talk I have not sat through, so there is nothing I can honestly report about its contents. A title on a schedule still tells you something: it says where a field has chosen to put its attention this year, and here that is the input path.

Read the same diagram defensively and those sources are plumbing you draw once. Read it the other way and they are the way in.

The row that says anyone

Ruling the columns was never the difficult part. The cost sits in the row that comes back reading anyone, and in leaving that word alone.

What that page looks like, with both columns ruled and the rows left blank, is here: https://dareomotosho.com/resources/field-kit

Discussion

  • No comments yet, be the first to add one.

Comments appear once approved. Upvotes are live.