JournalDAY 69 / X

FIELD NOTE / X

You cannot censor a capability away.

The complete written thought and the evidence behind it. The video edition will follow its public release.

Journal September 25, 2026 · X target December 5, 2026

You cannot censor a capability away.

Video caption

You cannot censor a capability away. A second tool or handoff can perform the same effect. No prompt or grammar can revoke a service key. #EricFieldNotes

Full written post / accessibility read

If an agent has a credential that can publish a customer export, suppressing the phrase 'send externally' in its text output does not revoke that credential. Token control acts during generation. The business effect happens when a service accepts a request.

In a synthetic host, direct export is denied by one hook, but a generic file-share function reaches the same partner. A model can be perfectly compliant with the blocked wording and still select the alternate tool. The defect is the uncovered capability map.

Group actions by what they can change, not what the function is called. Give the agent a credential scoped to tenant, recipient and operation. Run a harmless forbidden request through every route and read the target state to prove that nothing happened.

Keep output constraints where they help, but enforce action policy at the last unavoidable service boundary. Do this because the agent's words are only a proposal; the service's capabilities determine what can actually happen.

#EricFieldNotes

Four-beat scene transcript

1. You cannot censor a capability away.

If an agent has a credential that can publish a customer export, suppressing the phrase 'send externally' in its text output does not revoke that credential. Token control acts during generation. The business effect happens when a service accepts a request.

Visual: Masking a word does not remove the action behind a tool.

2. One intent can take multiple routes.

In a synthetic host, direct export is denied by one hook, but a generic file-share function reaches the same partner. A model can be perfectly compliant with the blocked wording and still select the alternate tool. The defect is the uncovered capability map.

Visual: A second tool or handoff can perform the same effect.

3. Map equivalent effects, then deny at service.

Group actions by what they can change, not what the function is called. Give the agent a credential scoped to tenant, recipient and operation. Run a harmless forbidden request through every route and read the target state to prove that nothing happened.

Visual: Tool names are not security boundaries.

4. Use masks for language, permissions for actions.

Keep output constraints where they help, but enforce action policy at the last unavoidable service boundary. Do this because the agent's words are only a proposal; the service's capabilities determine what can actually happen.

Visual: No prompt or grammar can revoke a service key.

Research and claim limits

The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.

More notes from the work ↗