The slide says the agent respects your permissions. Ask how. The answer, more often than a security committee would like, is a paragraph in the system prompt: do not disclose salary data, do not reveal the supplier’s price. A paragraph is an instruction. The person on the other side of the agent is typing instructions too, and he has all afternoon.

A prompt is a request, not a right

A system prompt and a user’s question travel through the same channel and are read by the same machine. The policy is a sentence; the attack is a sentence; the more persuasive one prevails. A better model will not fix this, because a model that follows instructions well is exactly what was ordered. A right is different in kind. Either the field is visible to this person, or it is not, and the institution decided which before the question was asked.

Who may see what is an institutional fact. It was settled by a directory, a clearance, a contract, a regulator’s letter. An agent that carries a paraphrase of that fact in its prompt has been handed a summary of the law and asked to enforce it from memory.

Guardrails filter the answer after the data was read

The second answer is a guardrail: a filter that inspects the agent’s output and removes what should not leave. The data was retrieved, placed in the context, reasoned over, and only then examined at the door. The salary was in the room. The guardrail decides whether it is mentioned, and it decides on a pattern, which is to say on a probability.

A right operates before the read. What enters the context is the security question; what leaves it is a courtesy. An organisation that cannot say what its agent read cannot defend the agent, and an organisation that cannot be read cannot be defended.[1] Ownership of an informational asset is measured by a single test: whether a question can be put to it and an answer returned that its owner would defend before a regulator, a court, or a minister who has already read the newspaper.[2] “The guardrail usually catches it” is not that answer.

Two settings is not a policy

The third answer is a perimeter. Put the agent inside the network, give it the service account, and rely on the walls. Perimeter security offers two settings, everything or nothing, which is why nothing is ever shared.[3]

Consider who needs the same fact at different depths. The prime and its subcontractor. The bank and its regulator. Governance at the level of the field and the relation lets one model serve a cleared officer and an uncleared subcontractor, showing each exactly what he is entitled to see and stopping there. A perimeter must duplicate the data downward, degrade it in the copying, and sever the link between the two versions.[3:1]

Then aggregation. Two unclassified facts combine into a classified one: the position of a fleet and its readiness are each shareable and together are not. The classification attaches to the relation, and a system that governs at the perimeter has nowhere to write it.[3:2] The founder’s phrase for the alternative is exact: security and governance enforced down to the cell.

A log is not a permission

The industry’s current answer is the audit trail: a chronological, tamper-resistant record of every input, model call, tool execution and output an agent produced. Keep the log; it is necessary. It is also a record of what was read, and a record cannot decide whether something could be. By the time the entry exists, the answer is on the screen.

The manifesto’s sentence on lawful capability has three clauses: every query logged, every access scoped to a purpose, every action attributable to a named officer.[4] The log is the first clause. The second is a right that existed before the query. The third is a person, not a service account. A vendor who ships the first and calls it governance has shipped one third of the sentence.

What Galahad refuses

A system prompt as an access policy. Guardrails as a substitute for rights. A perimeter with two settings, everything or nothing. The first can be argued with, the second arrives after the read, and the third cannot say less than everything.

The company page holds the position in one line: who can see what is enforced by the database itself rather than by application code that could be bypassed, and one deployment serves one organisation.[5] The agent inherits the institution’s decision. It does not carry a copy of it.

The questions to put to a vendor

Ask them before the agent is connected to anything.

  1. Where is the rule for who may see this field written: in the prompt, in the application, or in the institution’s own access system?
  2. If I revoke a user’s right in my directory, does the agent’s next answer change without anyone editing a prompt?
  3. Can two people with different clearances put the same question to one model and each receive a correct answer?
  4. What happens when two facts a user may see separately combine into one he may not?
  5. Show me the log of the last query, and show me the rule that let it run.
  6. Who is named on each access: the person, or the service account the agent runs under?

A vendor who answers with rights that exist outside the model has built something a regulated organisation can defend. A vendor who answers with a paragraph has built a request.

Monarch enforces security and governance down to the cell, inside your infrastructure, under your accounts and your keys. See it on your data.


  1. Machines of Consequence, thesis 16. Read it ↩︎

  2. Machines of Consequence, thesis 17. Read it ↩︎

  3. Machines of Consequence, thesis 28. Read it ↩︎ ↩︎ ↩︎

  4. Machines of Consequence, thesis 26. Read it ↩︎

  5. Galahad, the company. Read it ↩︎