Блог

1 мин чтенияtutorial

Security checklist AI-агента для покупателей

Buyer-side security checklist для AI-агентов: secrets, permissions, outbound actions, logging, vendors и vibe-coded risk.

Dali

Dali - студия AI agent systems. Давид ведёт engineering и продукт, Лиана - operations и fit процессов. Делаем production-агентов в tools, которыми команда уже пользуется.

David Hakobyan · Dali

Прямой ответ

До того как agents действуют в production, зафиксируйте secrets, least privilege, outbound gates, audit logs и stop-switch. Security - часть pilot design, не polish phase.

Secrets и keys

Нет tokens в client JS или public repos. Rotate всё, что когда-либо было committed.

Permissions

Least privilege на каждый tool. Разделите prod и test. Нет shared god-mode service accounts без review.

Actions

Gate на payments, emails, deletes, permission changes, public posts.

Observability

Логируйте inputs, tool calls, outputs, approvals. Храните достаточно, чтобы debug incidents.

Vendor access

Time-boxed, minimal, revocable. Written data handling rules.

Как помогает Dali

Security-minded triage - часть pilots Dali: solutions.

FAQ

  • Обычно access и actions важнее, чем какой LLM brand вы выбираете.