LESSON 7.6 · Engineering · 110 min
Production boundaries: permissions, safety, human oversight
Production boundaries: permissions, safety, human oversight. Learn least privilege, approvals, sandboxes, and audit and complete: Threat-model a high-risk tool. Part of the “From M
Learning objectives
- Explain what problem “Production boundaries: permissions, safety, human oversight” solves without hiding behind terminology.
- Trace the variables and causal links across least privilege, approvals, sandboxes.
- Complete “Threat-model a high-risk tool” and judge the result with evidence rather than intuition.
Core concepts
least privilege
least privilege is part of the lesson’s causal model. State its inputs, outputs, invariants, and failure mode; then verify it with a hand-check or a minimal experiment before moving to an optimized implementation.
approvals
approvals is part of the lesson’s causal model. State its inputs, outputs, invariants, and failure mode; then verify it with a hand-check or a minimal experiment.
sandboxes
sandboxes is part of the lesson’s causal model. State its inputs, outputs, invariants, and failure mode; then verify it with a hand-check or a minimal experiment.
and audit
and audit is part of the lesson’s causal model. State its inputs, outputs, invariants, and failure mode; then verify it with a hand-check or a minimal experiment.
Build and verify
Threat-model a high-risk tool
- Predict: write the expected output, trend, or failure before running code.
- Build: implement only the minimum components needed to answer the question.
- Verify: compare with a baseline or trusted implementation; save seeds, parameters, and raw outputs.
- Transfer: change one shape, dataset, scale, or workload condition and explain whether the conclusion still holds.