- Untrusted input and retrieval
- Customer text, attachments, web content, tickets, and knowledge passages can contain direct or indirect instructions. Separate data from system instructions, restrict sources and tools, validate outputs, and test prompt injection as an ongoing threat.
- Privacy by purpose
- Collect, retrieve, display, log, retain, and disclose only data needed for the stated service purpose. Enforce identity and permission outside the model, communicate processing, and give privacy owners evidence to verify the arrangement.
- Grounding and uncertainty
- Answers should cite current approved passages or deterministic records, distinguish source facts from generated phrasing, expose missing and conflicting evidence, and stop when the requested conclusion is unsupported.
- Least agency
- Grant narrowly scoped tools and credentials, mediate every action through typed code, recheck authorization at execution, cap consequence and frequency, require approval where needed, and record the actual committed state.
- Accessible service continuity
- Keyboard operation, focus order, names and states, status announcements, readable error recovery, timing, language, alternative channels, and human transfer should remain usable when AI or a connected system is unavailable.
- Incident and correction ownership
- Wrong answers, inappropriate actions, disclosure, biased treatment, failed transfers, repeated refusal, and accessibility defects need severity rules, customer remedy, containment, evidence preservation, root-cause repair, and authorized restart criteria.