AI SECURITY • 335 / 397
Understand how untrusted text, tools and autonomy create new attack paths.

Allowlist

An allowlist explicitly permits only approved tools, hosts, actions or inputs.

Think of it like

Think of Allowlist as an input-trust or privilege problem: words can influence software decisions, so boundaries must be explicit.

Real life

Email, documents and web pages can become hostile inputs to AI systems through attacks involving Allowlist.

SRE lens

Allow an agent to query specific read-only monitoring APIs.

Remember thisAn allowlist explicitly permits only approved tools, hosts, actions or inputs.
AIForSREJump to a concept
Search is optional. The main journey is simply ↓ Next.