Containment reduces blast radius when agents malfunction or are compromised. Principle of least privilege applied to AI.
Mechanisms
- Sandboxed execution
- Limited tool access
- Network isolation
- Resource quotas
Trade-offs
- Reduced capability
- Increased complexity
- User friction for legitimate actions