Radical Geek field guide
Radical Geek's Guide to Secure Agentic Engineering
A practical control guide for private code, tools, credentials, data, CI, cloud accounts and production-affecting agent workflows.
Why this guide
Secure agentic engineering gives teams an approved route for productive work with private repositories, internal tools, credentials, CI systems, cloud accounts, customer data and production workflows.
The guide translates governance into enforceable technical controls: workload identity, least privilege, data routing, tool boundaries, approvals, privacy-safe evidence, failure containment and recovery.
It is designed for real delivery systems where agents can read, write, run commands and call external services, and where the organisation must be able to see what happened and contain the impact when something goes wrong.
Give agents the smallest useful authority. Make every material action visible, bounded and reversible.
What you will leave with
A guide built to be used.
- 01
Classify data, consequence and delegability before selecting models, tools and workspaces.
- 02
Give each agent the smallest useful repository, command, network and credential boundary.
- 03
Protect prompts, logs, memory, retrieved context and generated artefacts as sensitive operating stores.
- 04
Place approvals, evidence and rollback around destructive, privileged and production-impacting actions.
- 05
Design stopping, fallback, recovery and incident evidence into the sanctioned route.
Inside the guide
The working ground it covers.
- Threat modelling and data-class routing
- Consequence, delegability and sanctioned routes
- Least-privilege workspaces and tool guardrails
- Secrets, network and filesystem controls
- Prompt injection, RAG and context poisoning
- Approvals, observability and audit evidence
- Cloud escalation, stopping and recovery
Book a Call