FIELD NOTE / INSTAGRAM
Let agents move within real boundaries.
The short film, the complete written thought, and the evidence behind it.
The Instagram edition will be linked here after its public post is verified.
Let agents move within real boundaries.
Day 04 · 2026-10-01 · Instagram
Short video caption
If a test agent has a production credential, 'use staging only' is an appeal. Give it staging-only authority, canary every enabled route, and inspect attempted crossings. Illustrative workflow. #EricFieldNotes
Full written post / accessible read
Agents are useful when they can act without asking permission at every step. That requires bounding what their identity can reach. If your test agent holds a production key, 'use staging only' is a request, not a boundary.
The team may have watched one successful staging test and assumed it was safe. But a different tool path or runtime can miss the hook while the same production credential still works.
A pre-tool hook can block the calls it intercepts. It cannot cover a route it never receives. In this illustrative workflow, staging-only credentials create a harder limit, while the trace records attempted crossings.
Give the test identity only staging access. Run a harmless deny canary through every enabled tool route and surface, then inspect the trace. Do this because the credential boundary survives a missed instruction or hook.
#EricFieldNotes
Evidence and boundary
On-screen boundary: ILLUSTRATIVE DATA ACCESS. The sources below support documented mechanisms and specifications; illustrative scenarios are not presented as measured incidents.
- Cursor hooks documentation (S04)
- Codex hooks reference (S44)
- Claude Code hooks reference (S45)