Agentic competitive research threat card

Every door a web-browsing research agent can be pushed through, the control that closes it, and the kill switches to test before the first run. No control, no launch.

Fill one card per agent. If a row has no control, the agent does not run. Write NONE and stop. Do not write “the prompt tells it not to.”

Test every kill switch before launch. A cap that has never fired is a cap nobody tested.

flowchart LR
    Q["Question"] --> G["Gate: budgets + blocklist"]
    G --> A["Agent: read-only tools"]
    A --> N["Notes store"]
    N --> C{"Quote in fetched text?"}
    C -->|No| X["Drop and log"]
    C -->|Yes| R["Human review"]
    K["Kill switch"] -.-> G
    K -.-> A

Is an agent the right shape?

If you can name the pages, use a scheduled fetch, a diff, and one model step instead. An agent is for open questions where the path is not known.

  • The research question is open and the pages are not known in advance
  • A change monitor was considered and does not fit
  • One named owner for the agent and its output

Toolset (three tools, no more)

ToolAllowedLimit written here
Search public webYesQueries per run: ____
Fetch page (GET only)YesPages per run: ____ Bytes per page: ____
Write note to notes storeYesOne store, append only, schema-validated
Send email or post to chatNoDelivery is a separate approved step
Run code or shellNoNot needed
Access the customer relationship management (CRM) system, billing, or filesNoNo credentials in the agent environment

Budgets enforced by the runner

  • Max steps per run (number)
  • Max pages fetched (number)
  • Max bytes per page (number)
  • Max wall-clock seconds (number)
  • Max model spend per run (amount)
  • Allowed methods: GET only
  • Blocked hosts include localhost, internal addresses, and our own services

Doors and controls

DoorControl (write it)Tested on
Injected instructions in a pageDate
Scope creep (logins, forms, private areas)Date
Fabricated findingsDate
Runaway cost or loopDate
Leaky context in queries or URLsDate
Quiet drift after a prompt or model changeDate
  • No secrets, customer data, or private notes in the agent prompt
  • Every outbound search query and fetched URL is logged with the run id
  • Page text is treated as data, never as instructions

Output gate

  • The agent writes claim records, not a finished brief
  • Each record has a claim, URL, verbatim quote, retrieval date, and source type
  • A script drops any record whose quote is not in the fetched text
  • A named person reviews survivors before anything is used

Kill switches (test each one)

  • Global flag blocks new runs. Tested by flipping it mid-run.
  • A run in flight can be cancelled by run id
  • Page cap lowered to three in a test and the run stopped at three
  • Any stop writes a log line and alerts the owner
  • The whole agent can be stopped in under one minute by someone who did not build it

Change control

  • Prompt, budgets, and allowlists are versioned
  • A short set of known research questions reruns after every change
  • Quote-check drop rate is logged. A sudden rise is an alert.

Related guides