Sicherheit zuerst: Agenten einsetzen, ohne die Kontrolle abzugeben

Ein KI-Agent kann E-Mails beantworten, Dateien suchen oder Termine vorbereiten — und genau deshalb verdient er denselben Respekt wie ein neuer Mitarbeiter mit eigenem Zugang. Sicherheit beginnt nicht bei der Technik, sondern bei drei unspektakulären Fragen: Was darf er sehen, was darf er allein tun, und wie komme ich wieder weg, wenn etwas schiefgeht?

Klein anfangen, groß denken

Der sicherste erste Einsatz ist der, der nichts Unumkehrbares auslöst. Lesen, zusammenfassen, entwerfen: alles, was ein Mensch danach prüft, bevor es nach außen geht. Erst wenn dieser Kreis monatelang sauber lief, folgt der nächste Schritt — eine Antwort, die ohne Kontrolle rausgeht. Reihenfolge ist hier kein Zögern, sondern Risikosteuerung.

Was der Agent sehen darf

  • Zugriff begrenzen: nur die Ordner und Postfächer, die die Aufgabe wirklich braucht — nicht das gesamte Laufwerk.
  • Datenweitergabe prüfen: Welche Inhalte verlassen das eigene System, und sind sie dafür geeignet?
  • Rechte trennen: wer den Agenten startet, muss nicht automatisch alle Rechte des Agenten haben.
  • Geheimnisse draußen lassen: Zugangsdaten und Kundendaten gehören nicht in einen Prompt.

Freigaben dort, wo es wehtut

Jede Aktion mit Außenwirkung — senden, bezahlen, löschen, veröffentlichen — braucht eine Schwelle. Die praktikabelste ist eine kurze Bestätigung mit sichtbarem Inhalt: die Person sieht, was passieren soll, und entscheidet in einer Sekunde. Wer alles freigibt, hat keine Kontrolle; wer nichts freigibt, hat keine Geschwindigkeit. Die Mitte liegt bei den Schritten, die schwer rückgängig zu machen sind.

Protokoll statt Gedächtnis

  1. Was wurde beauftragt, und von wem?
  2. Was hat der Agent gelesen, geschrieben oder gesendet?
  3. Welche Entscheidung wurde automatisch getroffen?
  4. Wann wurde sie zuletzt geprüft?

Ein einfach lesbares Protokoll ersetzt später jede Diskussion. Es muss kein Audit-System sein — eine Zeile pro Aktion genügt, solange sie vollständig ist.

Einen Notausgang behalten

Bevor ein Agent produktiv arbeitet, sollte die Rückkehr zum alten Weg geübt sein: Zugang entziehen, Verbindungen trennen, Prozess manuell weiterführen. Diese Probe dauert eine halbe Stunde und kostet sonst Nächte. Kontrolle zeigt sich nicht daran, wie gut etwas läuft, sondern daran, wie schnell man es anhalten kann, ohne dass der Alltag stehenbleibt.

An AI agent can answer emails, find files, or prepare appointments — and precisely for that reason it deserves the same respect as a new hire with their own login. Security does not start with the technology, but with three unspectacular questions: What may it see, what may it do alone, and how do I get out again if something goes wrong?

Start small, think big

The safest first deployment is the one that triggers nothing irreversible. Reading, summarising, drafting: anything a person checks afterwards before it leaves the building. Only once that loop has run cleanly for months does the next step follow — a reply that goes out without review. The order is not hesitation; it is risk management.

What the agent is allowed to see

  • Limit access: only the folders and mailboxes the task actually needs — not the whole drive.
  • Check data flow: which contents leave your own system, and are they suitable for it?
  • Separate rights: whoever starts the agent does not automatically hold the agent's permissions.
  • Keep secrets out: credentials and customer data do not belong in a prompt.

Approvals where it hurts

Every action with an outside effect — sending, paying, deleting, publishing — needs a threshold. The most workable one is a short confirmation showing the content: the person sees what is about to happen and decides in a second. Whoever approves everything has no control; whoever approves nothing has no speed. The middle ground lies with the steps that are hard to reverse.

A log, not a memory

  1. What was requested, and by whom?
  2. What did the agent read, write, or send?
  3. Which decision was made automatically?
  4. When was it last reviewed?

A plain readable log replaces every discussion later. It does not have to be an audit system — one line per action is enough, as long as it is complete.

Keep an emergency exit

Before an agent works in production, the way back should already be practised: revoke access, disconnect integrations, keep the process running manually. That rehearsal takes half an hour and otherwise costs nights. Control is not shown by how well something runs, but by how quickly you can stop it without daily work coming to a standstill.

Bir YZ ajanı e-postalara yanıt verebilir, dosya bulabilir veya toplantı hazırlayabilir — ve tam da bu yüzden, kendi erişimi olan yeni bir çalışanla aynı saygıyı hak eder. Güvenlik teknolojiyle değil, üç sıradan soruyla başlar: Neyi görebilir, neyi tek başına yapabilir, ve bir şey ters giderken yeniden dışarı nasıl çıkarım?

Küçük başlayın, büyük düşünün

En güvenli ilk kullanım, geri alınamaz hiçbir şeyi tetiklemeyendir. Okumak, özetlemek, taslak hazırlamak: hepsi içeride bir insanın kontrolünden geçen işler. Bu dağarcık aylarca temiz çalıştıktan sonra sıradaki adım gelir — kontrolsüz çıkan bir yanıt. Bu sıralama çekingenlik değil, risk yönetimidir.

Ajan ne görebilir

  • Erişimi kısıtlayın: yalnızca görevin gerçekten gerektirdiği klasörler ve gelen kutuları — tüm sürücü değil.
  • Veri akışını denetleyin: hangi içerikler sisteminizden çıkıyor ve bu içerik uygun mu?
  • Yetkileri ayırın: ajanı başlatan kişi, ajanın yetkilerini otomatik olarak edinmez.
  • Sırları dışarıda tutun: erişim anahtarları ve müşteri verisi isteğin (prompt) içine girmez.

Acıtan yerde onay

Dışa etkisi olan her eylem — göndermek, ödemek, silmek, yayımlamak — bir eşik ister. En uygulanabilir eşik, içeriği gösteren kısa bir onaydır: kişi ne olacağını görür ve bir saniyede karar verir. Her şeyi onaylayanın kontrolü yoktur; hiçbir şeyi onaylayanın hızı yoktur. Ortası, geri alınması zor olan adımlardadır.

Hafıza değil, kayıt

  1. Ne talep edildi, kim tarafından?
  2. Ajan ne okudu, ne yazdı, ne gönderdi?
  3. Hangi karar otomatik alındı?
  4. Son ne zaman denetlendi?

Basit okunabilir bir kayıt, sonraki her tartışmayı bitirir. Denetim sistemi olmak zorunda değil — eylem başına tek satır yeter, yeter ki eksiksiz olsun.

Bir çıkış kapısı bırakın

Bir ajan üretime girmeden önce eski yola dönüş provası yapılmış olsun: erişimi kaldırın, bağlantıları kesin, süreci elle sürdürün. Bu prova yarım saat sürür, aksi hâlde geceleri götürür. Kontrol, işin ne kadar iyi çalıştığında değil, günlük iş durmadan ne kadar hızlı durdurabildiğinizde görünür.

← Blog