AgentLog describes OpenShell as a runtime focused on security and privacy for autonomous agents. The integration lesson is to distinguish two controls: authority to perform actions and information available for reasoning.
List the agent's tools and their individual permissions. Reading a record should not grant access to an entire database; drafting a message should not authorize sending it. Separate reading, writing and execution with limits enforced by the system.
Process data before calling the model. A restricted execution environment does not prevent a prompt from containing a complete customer record. Documents, pages and tool responses can also contain hostile instructions: receive them as data without expanding permissions.
Evaluate with adversarial documents and fictional personal data. Check what reaches inference and which effects tools can produce. Rota processes the data path; execution isolation and authorization for each action remain the application's responsibility.