Separate intelligence from authority
A model can be capable without being trustworthy, and a trustworthy model can still make an unsafe decision in an unfamiliar context. The safer architecture keeps authority outside the model: identity, policy, inspection, routing, approval, containment, and audit should not depend on the model describing its own behavior accurately.
Separate intelligence from authority
- Treat agents and model-backed workflows as privileged actors, not as anonymous software clients
- Give each caller only the model, tool, and action scope it needs
- Keep the decision and evidence path independent from the model's response