certslothcertsloth
PAA/Topic 06

Google Cloud / Professional · Upcoming

Identity, guardrails and governance

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Authorize actions outside the model.

Must remember

  • Give agents dedicated identities and least-privileged access. Principal access boundary policies constrain eligible resource access where supported; IAM permissions and explicit policy still govern actual actions.
  • OAuth-based tool access and identity propagation can preserve user authorization. Avoid a single administrator token that makes every user’s request equally powerful.
  • Agent Gateway/Registry provide supported control and visibility points; Model Armor and Sensitive Data Protection help screen harmful or sensitive content. Apply controls at input, retrieval, tool calls/results and output.
  • Prompt injection can arrive through documents, websites or tool responses. Treat those as untrusted data and validate proposed actions against the original user scope and external policy.
  • Use human approval for consequential actions, with an exact target and proposed change. Keep network boundaries, secret storage, audit, retention and incident response aligned with organizational policy.
  • Test guardrail bypasses, unauthorized data access, malicious tool arguments and cross-tenant leakage. Governance needs enforceable controls and accountable owners, not merely a system prompt.

Choose under exam pressure

Requirement Choice and reason
An agent proposes deleting a production dataset External authorization, explicit bounded approval and an appropriate recovery process.
A retrieved document requests secret exfiltration Treat it as malicious data and block the unauthorized tool action.

Traps

  • A safety filter cannot grant permission to a resource.
  • A principal access boundary is not a substitute for granting the required narrow role.

Active recall

1. Where must authorization be enforced?

At the service/tool boundary outside the model’s generated text.

2. Why propagate user identity?

To prevent the agent from exposing data or actions the requesting user cannot access.

3. What is prompt injection?

Untrusted content attempting to redirect the model’s behavior or tool use.

4. Why inspect tool results?

They can contain malicious instructions, malformed data or sensitive information.

5. What proves a guardrail works?

Representative adversarial tests and observed enforcement, with monitoring for failures.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.