Week 7 operating page

Agent + HITL

Khóa tool authentication, permission boundaries, pending-only writes, HITL, audit và red-team.

Weekly review
AVAILABLE TO READ · LOCKED FOR PASS

Đọc và bookmark được phép; mọi mutation vẫn bị khóa server-side cho đến khi week trước PASS.

Missions
0/7
Weekly quiz
0%

PASS ≥ 80%

Evidence
0

learner artifacts

Boss Fight
OPEN
Open incident

Missions

MISSION 01 · Agent Architecture

Agent, Tool Calling & Security Architecture

Agent→tool selection→schema→args validation→Backend API architecture and AI is not superuser

NOT STARTEDOpen
MISSION 02 · Agent Tools

Read Tools: Schema, Limits, Auth & Audit

Read tool such as get_low_stock_products, argument schema/limits, authorization, row limit and audit

NOT STARTEDOpen
MISSION 03 · Agent Write Security

Write Tools: Pending-only State & HITL

create_purchase_request tool, source=AI, DRAFT/PENDING, no approve tool, Manager approval and workflow continuation

NOT STARTEDOpen
MISSION 04 · Agent Security

Agent Service Authentication, RBAC & Permission Boundary

Agent service auth, user actor context, Backend RBAC, tool permission, expired token and 401/403 tests

NOT STARTEDOpen
MISSION 05 · Agent Operations

Agent Audit, Limits, Timeout & Resilience

Agent audit actor/tool/sanitized args/result/timestamp/correlation/latency, rate/row/quantity limits, timeout/malformed output and retry safety

NOT STARTEDOpen
MISSION 06 · Agent Red-team

Agent Red-team: Injection, Privilege & Secret Defenses

Ignore-rules, self-approve, secret extraction, SQL, huge quantity, malicious retrieved text, wrong role, expired token, timeout and malformed output red-team

NOT STARTEDOpen
MISSION 07 · Agent QA

Agent E2E, Security Closure & Configuration Freeze Prep

Two controlled tools, E2E Agent workflow, DRAFT/PENDING/Manager approval, AI audit, red-team report and final config inventory prep

NOT STARTEDOpen