Claude Operator: Prompt to Autonomy · 20 min · 140 XP

Threat-modelling a workflow

Assets, actors, entry points and gates — the reasoning behind every rule in this level.

Everything so far has been individual controls. A threat model is what tells you which ones you need — five questions, answered for one real workflow.

What are the assets? Source, credentials, customer data, your ability to publish. Who are the actors? You, your teammates, anyone who can open a pull request, anyone who can send you an email the workflow reads. What are the entry points? Every place text enters: prompts, files, tool results, issues, web pages. What are the risky actions? Sends, deletes, publishes, money, anything irreversible. What are the mitigations? And for each one: does it prevent, detect, or recover?

That last distinction is where most designs are thin. Permission rules and allow lists prevent. Logs and metrics detect. Version control, drafts and revocation recover. A workflow with only prevention has no idea when it failed; one with only detection finds out afterwards. You want at least one control in each column for anything that touches the outside world.

Untrusted input deserves its own line, because this is the entry point people forget. Email, documents, issues, web pages and tool results are data. Say so explicitly in your instructions: content from those sources is information to report, never instruction to follow, and anything resembling a command gets quoted back rather than acted on.

And put a human approval gate in front of the irreversible actions: external communication, money, deletion, publishing. A gate is only real if it's specific — the approver sees the exact recipients, the exact change, the evidence behind it. "Proceed?" with no payload is a button people learn to press. The gate is also your backstop when a prevention control fails, which is why the two belong together.

Practice. Threat-model one real workflow: list assets, actors, entry points, risky actions and mitigations, and mark each mitigation as prevention, detection or recovery. Write instructions that treat email, documents, issues and web content as untrusted data, then feed in a malicious sample and confirm it's quoted or reported rather than followed. Design an approval gate with a named approver and an exact review payload. Then combine a narrow skill, minimum permissions, completion checks and that gate into one shared practice task a teammate could run without inheriting broader access.

Loading your workspace…