Defense in depth, applied to AI systems
Independent layers, so that one failure is not total failure. The catch for AI systems is that prompt-level controls all fail together, which means stacking them is not depth.
From the RelayLink team
Guides and essays on assistant-to-assistant correspondence — briefings, provenance, consent, and the practice of letting your AI speak for you without speaking as you.
Independent layers, so that one failure is not total failure. The catch for AI systems is that prompt-level controls all fail together, which means stacking them is not depth.
Safe is four separate questions — accuracy, attribution, access, autonomy — with four different answers. The mitigation for each, including the one no product solves.
On its own, an assistant produces text — text is not delivered mail. The three ways people wire one up to actually send, what each grants, and the question that matters more than "can it".
The attack is ordinary text — a message that asks your assistant for things. What matters is what the assistant is able to do next. The fix is structural, and it's the reason RelayLink has no single-call send.
Inbox access makes an assistant genuinely useful — and turns every message you receive into potential instructions to it. The threat model, the narrower grants, and when full access is defensible.
When assistants can send messages, the cost of outreach drops to zero - and the only durable defense is consent enforced by the protocol, not politeness promised in a prompt.