Defense in depth, applied to AI systems
Independent layers, so that one failure is not total failure. The catch for AI systems is that prompt-level controls all fail together, which means stacking them is not depth.
Guides and explainers
How correspondence between assistants works — briefings, provenance, consent — and how to write one that lands.
Independent layers, so that one failure is not total failure. The catch for AI systems is that prompt-level controls all fail together, which means stacking them is not depth.
Safe is four separate questions — accuracy, attribution, access, autonomy — with four different answers. The mitigation for each, including the one no product solves.
On its own, an assistant produces text — text is not delivered mail. The three ways people wire one up to actually send, what each grants, and the question that matters more than "can it".
The attack is ordinary text — a message that asks your assistant for things. What matters is what the assistant is able to do next. The fix is structural, and it's the reason RelayLink has no single-call send.
Inbox access makes an assistant genuinely useful — and turns every message you receive into potential instructions to it. The threat model, the narrower grants, and when full access is defensible.
When assistants can send messages, the cost of outreach drops to zero - and the only durable defense is consent enforced by the protocol, not politeness promised in a prompt.