1. Inventory available actions. For every tool, record the data it reads, the effect it produces and its authorized users. Searches need mandatory project filters; writes need specific resource targets. Remove generic execution tools when the task only requires lookup.
2. Separate proposals from effects. An agent may prepare a message or change without receiving permission to send or apply it. The application checks contextual authorization and enforces recipient, volume and expiry limits. A sentence inside a document must never grant access.
3. Minimize tool responses. Return only fields required by the task and process them before inference. Avoid returning full customer records to answer a status question. Apply the same discipline to attachments, retrieved context and error messages.
4. Test useful refusals. Include a document requesting another project's data, a tool returning extra fields and an attempt to repeat a write. The system should prevent unauthorized effects, explain the limit and let the task continue through an authorized path.