Dashboard
0%
1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →

Q44HardScenario

During user acceptance testing, you discover the agent can be manipulated into deleting customer records. What do you do?

30-second answerSay your answer out loud first, then reveal.

Immediate actions

  1. Contain: remove or disable the delete tool in all environments; rotate credentials if they were exposed.
  2. Communicate: a clear, factual note to the stakeholders: what was found, the impact (UAT only, no production data affected, if true), and the next steps.
  3. Analyse: how was it manipulated? Direct user instructions, injected text in records, or a missing authorisation check? Which permissions did the agent's service account have?

Fixes (defence in depth)

LayerFix
CapabilityDoes the agent need deletion at all? Usually no. Remove it.
PermissionsService account without delete rights; per-user OAuth scopes
Action designSoft delete/archive only, with recovery; confirmation step with a clear summary
AuthorisationServer-side checks of user rights and business rules, not prompt instructions
Injection defenceTreat record content as untrusted; separate data from instructions
MonitoringAlerts on destructive or unusual actions; rate limits
TestingRed-team suite in CI covering destructive actions

Follow-up: a post-mortem, an update to the FDE checklist for all deployments (a "no destructive tools by default" policy), and sharing the learning with the product team.

This is what real progress feels like.