for agents/llms.txtv0.8.0

Home / SGit Newsroom / Newsletter / Issue 4

SGit Newsroom · Issue 4 · 2026-10-11

Authority outside the model: Satya Nadella on models as insider risks, the platforms that now enforce, and the controls we run on our own agents

By , written with the Journalist

Abstract: The CEO of one of the largest AI vendors published seven principles for treating models as insider risks, and Microsoft shipped containers and a control specification for agents. Both say what this network has been arguing: an agent's limits must sit outside the agent. Eight articles on what that means in practice. An answer to the seven principles, one by one, with what runs and what is only designed; the same argument translated into the language of behaviour policies; where the platform draws its line and why the business logic sits above it; ten hard questions for RiskMandate; and the controls we run on our own agents every day, from a second reader that fails closed to a desktop of their own.

When an agent breaks a rule, the first question is who was keeping the rule. If the answer is the agent, it was not a rule, it was a hope. This week that argument went mainstream: Satya Nadella published seven principles for treating models as insider risks, and Microsoft shipped the containers to enforce some of them. This issue is eight articles on what it takes for an agent's limits to sit outside the agent. It is the second of three on what was published between 9 and 11 October, after pay after you read and before no server, by design.

Authority outside the model in six pictures, one from each of the first six articles

Seven principles, answered

Authority outside the model answers Satya Nadella's seven principles one by one: what stands behind each on this network today, what runs, what is a published design, and what is only argued, with a table that keeps the three apart. It names five things the list leaves out, starting with the mandate, because watching an agent tells you what it did, not whether it was allowed. Its core is the test this network has used for a while:

a control bounds a grant only if it is enforced by something the grant does not include.

Nadella's seven principles, and what stands behind each one on this network today.

The same argument, in our words translates his post idea by idea into the vocabulary of behaviour policies, reach, mandate, gap, barriers and accepted risk, and finds that his ending and ours are the same sentence read from opposite ends:

the more you can constrain an agent, the more you can trust it, and the more autonomy you can afford to give it.

Where the platform draws the line

Where the platform draws the line reads Microsoft's new execution containers and agent control specification field by field. The platform puts the policy outside the workload and enforces it in the operating system, and it can only name what it can see: files, addresses, processes. That is the shared responsibility model again, and the business logic sits above the line:

an agent must not be the one that decides its own limits.

The shared responsibility model, drawn for agents: each layer can only name what it can see.

Run the same agent three ways, it finds, and rows of a behaviour policy that were hope can now become boundaries kept by the platform. Ten hard questions for RiskMandate is where that policy comes from: the questions a co-founder brought back from a conference, about bypasses, liability, insurance and what a customer is actually paying for, answered in a two-hour interview.

RiskMandate defines the risk that comes with the mandate a business gives an agent.

The controls we run on our own agents

The principles are easy to state. These four articles are what keeping them looks like on a real system, every day.

A second reader the agent cannot skip starts with two emails that went out in my voice despite a written rule, and ends with a hook that makes a second model approve every draft, run by the harness rather than the agent, failing closed:

A rule kept by the agent it governs is hope.

Re-anchoring deals with the forgetting. A long session is summarised again and again, each time replacing most of what the agent had in view, and nothing says what was kept. So the rules live in a file, printed back after every summary, with a short report every few answers to show it is still working:

The rules are restored, not remembered.

Every summary in the session that runs this site, read from its own transcript: each turned about 785,000 tokens into 9,000 to 19,000, and all eighteen were automatic.

How I work with Claude is the practical guide behind all of it: one session per topic, named agents with a role file, curated memory, vaults, and policy before connectors.

Memory is what the session reads.

And a Mac of the agent's own is the next dedicated resource after a mailbox, a code-host account and a Claude account: a desktop, read against what Apple's licence allows, built clean for every run from vaults and erased at the end.

The vaults are the state.

The eight articles

The principles

Models as insider risks, answered and translated.

The platform and the policy

What the operating system can now enforce, and the behaviour policy above it.

On our own agents

A second reader, rules that survive summaries, the daily routine, and a desktop of their own.

This is issue 4 of the SGit Newsroom newsletter, also published on LinkedIn in Deterministic GenAI. Every article it links to is on sgit.ai, with its sources and its data. To get the next issue by email, subscribe at sgit.ai/subscribe.

← All issues