Agents and Workflows
D3 · Context, Tools and Permissions
Giving an agent the context it needs, the tools and connectors to do the work, and no more access than the task requires — with least-privilege thinking and workspace-agent scoping.
The second of the two heaviest domains — 18%, about 9 of 50 items. It tests two paired judgments: giving an agent enough context and tools to succeed, and giving it no more access than the task needs. Under-provision and the agent guesses; over-provision and you have handed a capable, literal worker keys to rooms it never needed to enter. The material rewards least-privilege thinking applied to a workspace agent that acts on your behalf and inherits reach you may not have thought about.
What you need to know
An agent needs four kinds of context: the task brief (from D2), the source documents for this task, relevant company knowledge (policies, standards, product facts), and prior decisions so it doesn’t relitigate settled questions. It needs tools and connectors to reach data and take actions — but each one is capability and blast radius. Least privilege means granting the minimum context and access the task requires and widening only on evidence of need. A workspace agent acts with real reach into shared files, connectors and systems, so its scope must be set deliberately: what it can read, what it can write, and where it must stop. Context and access are the two halves of the same setup: the right context makes the agent competent; the right access makes it safe.
Learning objectives
By the end of this page you should be able to:
- Identify the four kinds of context an agent needs and supply each from the right place.
- Distinguish context the agent needs from noise that degrades its work.
- Match tools and connectors to what the task actually requires.
- Apply least-privilege thinking to an agent’s access, separating read from write and internal from external.
- Scope a workspace agent deliberately, reasoning about the reach it inherits.
- Diagnose whether a failure came from missing context or from missing access.
3.1 The four kinds of context
An agent starts with only what you give it plus what its tools can fetch. Missing context is the most common cause of confidently wrong work — the agent fills the gap with a guess.
| Context type | What it is | Where it comes from | Symptom when missing |
|---|---|---|---|
| Task brief | Goal, done, constraints (D2) | You, in the delegation | Wrong outcome, wrong scope |
| Source documents | The specific inputs for this task | Uploads, attached files | It uses generic or invented facts |
| Company knowledge | Policies, standards, product facts, tone | Company-knowledge / connectors | Off-brand, off-policy output |
| Prior decisions | What’s already been settled | Project notes, prior threads | It reopens closed questions |
what the agent knows ┌───────────────────────────────────────────┐ │ TASK BRIEF (why + what + done) │ you supply │ SOURCE DOCS (the inputs for this task) │ you attach │ COMPANY KNOW. (how we do things here) │ workspace provides │ PRIOR DECISIONS(what's already decided) │ you point to └───────────────────────────────────────────┘ gaps here ─► the agent guesses to fill themAssessment signal
When a stem describes output that is competent-but-generic, off-brand, or reopens a decided question, the fix is almost always supply the missing context (source doc, company knowledge, or prior decision) — not a bigger model or more tools.
3.2 More context is not always better
Context has a cost. Dumping every document you have into the task buries the relevant signal and can actively mislead the agent toward whatever was longest or most recent. The skill is supplying what’s relevant and authoritative, not everything available.
| Too little context | Right context | Too much context |
|---|---|---|
| Agent guesses missing facts | Agent grounds its work | Signal buried; agent over-weights irrelevant docs |
| Off-brand, generic output | On-brand, specific output | Contradictions between stale and current docs |
| Reopens settled questions | Respects prior decisions | Anchors on the wrong source |
The connection to D2’s sources of truth is direct: name what’s authoritative and supply that, rather than everything and hoping the agent sorts it out. When in doubt, supply the specific source document and the relevant slice of company knowledge — not the entire drive.
3.3 Tools and connectors: matching capability to the task
Tools are how an agent reaches beyond the text in front of it — search, file access, connectors to shared systems, the ability to draft or send. Provisioning is a matching exercise: what does this task genuinely require?
| The task needs to… | Provide | Do NOT provide |
|---|---|---|
| Answer from a supplied document | Read access to that document | Web, write, or send tools |
| Synthesise current public information | Web search (read-only) | Any connector that can edit/send |
| Pull facts from a shared system | A read connector to that system | Write access to it |
| Produce a draft for you to send | Draft/artefact creation | Autonomous send |
| Actually send/publish after approval | The send tool behind a checkpoint | Ungated send |
The pattern: read before write, draft before send, one system before many. Every step up that ladder adds capability and blast radius together, so take each step only when the task requires it.
3.4 Least-privilege thinking
Least privilege is the governing principle of the whole domain: grant the minimum access the task needs, and widen only on evidence of need. It is the opposite of the tempting “give it everything so it never gets stuck” default.
blast radius low ◄──────────────────────────► high read one read shared write send / document system data publish / pay │ │ │ │ start here ─┘ │ │ widen only if a run │ │ actually needs it ─────────┴─────────┘ gate anything on the rightWhy it matters specifically for agents: an agent is autonomous and literal. If it can reach something, it may — to satisfy the goal — touch data or take an action you never intended. Narrow access means a misunderstanding stays contained. Broad access means a misunderstanding becomes an incident.
| Least-privilege move | Effect |
|---|---|
| Grant read, not write | A misread can’t corrupt data |
| Scope a connector to one folder, not the drive | Limits what’s exposed |
| Gate send/publish behind approval | Irreversible actions can’t fire unwatched |
| Time-box or spend-cap the run | Bounds runaway cost (developed in D4) |
Assessment signal
“To be safe, give it broad access” is always the wrong reasoning in these stems. Broad access is broad blast radius. The correct answer starts from the minimum and widens on evidence — the phrase to reward is least privilege / only what the task needs.
3.5 An agent inherits reach — think about what it can touch
A workspace agent acts on your behalf and through the connectors and permissions it’s been given. That means it can reach whatever those connectors reach — which may be more than the immediate task suggests. Before delegating, ask what the granted access actually exposes.
| You granted… | The agent can therefore reach… | Question to ask first |
|---|---|---|
| A connector to a shared drive | Every file in that drive, not just the one you meant | Can I scope it to the folder? |
| Access to a channel or inbox | The whole history, including sensitive threads | Does the task need the history? |
| A connector to a system of record | Whatever your permissions there allow | Should the agent have all of my reach? |
| Send-on-your-behalf | The ability to act as you, externally | Does this need a gate? |
The principle: the agent’s reach is the union of the connectors you enable, and it will use any of them if the goal seems to call for it. Scope each connector to the narrowest slice that works.
3.6 Diagnosing missing context versus missing access
When an agent underperforms, distinguish the two failure families — the fixes are opposite.
Agent's output is wrong or incomplete│├─ Did it act on wrong/generic facts, go off-brand,│ or reopen a settled question? ──► MISSING CONTEXT│ fix: supply the source doc /│ company knowledge / prior decision│└─ Did it say it "couldn't access", stop short of a step, or fail to reach a needed system? ──► MISSING ACCESS fix: grant the specific tool/connector (least privilege), not everythingConfusing the two wastes effort: granting more tools won’t fix an off-brand answer (that’s context), and pasting more documents won’t fix “I don’t have access to the CRM” (that’s a connector). Read the symptom, then apply the matching fix.
Decision framework
Use the CARE provisioning checklist before every delegation: Context, Access, Reach, Evidence. Fill each and you provision an agent that is both competent and contained.
| Step | Question | The disciplined answer |
|---|---|---|
| C — Context | What must it know to do this well? | Task brief + the specific source docs + relevant company knowledge + prior decisions — and nothing that buries the signal |
| A — Access | What tools does the task actually require? | The minimum on the read→write→send ladder; draft not send unless gated |
| R — Reach | What does that access let it touch beyond the task? | Scope each connector to the narrowest slice; check inherited reach |
| E — Evidence | When do I widen access? | Only when a real run demonstrably needs more — not “to be safe” |
Apply it tomorrow: for any task, write the four rows. If Access or Reach is broader than the task needs, narrow it before you run — that is least privilege in practice.
Common mistakes
| Mistake | Why it happens | What to do instead |
|---|---|---|
| Under-provisioning context, then blaming the model | You assumed it “knew” your policies | Supply source docs, company knowledge and prior decisions |
| Dumping every document into the task | “More context is safer” | Supply the relevant, authoritative slice; excess buries signal |
| Granting broad access “to be safe” | Fear of the agent getting stuck | Start least-privilege; widen only on evidence of need |
| Giving write when read would do | Not separating the two | Read before write; a misread can’t corrupt data |
| Enabling send instead of draft | Wanting end-to-end automation | Draft for you; gate the send (D4) |
| Ignoring what a connector inherits | Thinking only of the immediate file | The agent can reach everything the connector reaches — scope it |
| Fixing an off-brand answer with more tools | Confusing context with access | Off-brand is a context gap; supply company knowledge |
| Fixing “can’t access” by pasting more text | Confusing access with context | Grant the specific connector, least-privilege |
Scenario challenge
Scenario. Amara, a customer-success lead on ChatGPT Work, wants an agent to draft renewal-summary emails for twelve accounts up for renewal this quarter. She connects the agent to the shared customer drive and to the team inbox so it “has everything it needs”, and gives it the goal. The drafts come back citing an outdated pricing policy, referencing details from unrelated customers’ files, and one draft quotes an internal margin note that should never leave the company. Amara wonders whether the agent is simply unreliable for this kind of work.
Expert reasoning trace.
- Separate context from access. Two distinct problems are tangled here: the outdated pricing policy is a context failure (it used stale knowledge), while referencing unrelated customers and quoting an internal margin note are reach failures (it touched data it should never have reached).
- Fix the context gap with authoritative sources, not more tools. The outdated policy means the current pricing policy wasn’t supplied as authoritative company knowledge; the agent fell back on whatever it found. Supply the current policy and name it as the source of truth (D2).
- Diagnose the over-provisioning. Connecting the whole shared drive and the whole team inbox handed the agent reach across every customer’s files and every internal thread. It’s a literal, autonomous worker: given a renewal task and access to everything, it pulled from everything.
- Apply least privilege / scoping. The task needs, per account, that account’s file — not the entire drive. Scope the connector to the specific renewal folder or the twelve account records, and remove the inbox connector entirely (drafting emails doesn’t require read access to the inbox history). The internal margin note should never have been reachable.
- Add the read/write and draft/send distinctions. The agent needs read access to account data and the ability to produce drafts. It does not need send — the emails should land as drafts for Amara to review and send, gating the one irreversible step.
- Provision, don’t abandon. The agent isn’t “unreliable for this work”; it was mis-provisioned. Re-run with scoped read access to the right records, the current policy as authoritative context, draft-only output, and the internal note out of reach — and the same agent produces safe, on-policy drafts.
The point. “Give it everything so it has what it needs” caused both the leakage and the noise. The fix is CARE: supply the right context (current policy), scope access to the account records, check reach so internal notes are unreachable, and widen only on evidence — none of which requires a different model.
Assessment traps
| Trap | Why it is tempting | The discriminator |
|---|---|---|
| “Connect it to everything so it has what it needs” | Feels thorough and avoids blockers | Broad access is broad reach; scope to the task (least privilege) |
| “Off-brand output means we need a better model” | Quality problem feels like capability | Off-brand is a missing-context problem; supply company knowledge |
| “Paste all the documents in to be safe” | More context seems safer | Excess context buries signal and anchors on wrong sources |
| “Give write access so it can just finish” | End-to-end automation is appealing | Read before write; write is far larger blast radius |
| “A connector only exposes the file I mean” | You think of the one document | A connector exposes everything it reaches — scope it |
| “‘Can’t access’ means paste more context” | Any gap looks like a context gap | ‘Can’t access’ is a missing-tool problem; grant the specific connector |
Practice questions
Each item states how many responses to select. Attempt before revealing.
Q1 · An agent produces competent but generic, off-brand copy. Which fix is MOST appropriate? (Select one)
A. Grant it more tools and connectors. B. Supply the relevant company knowledge — brand voice, style guide and product facts — as authoritative context. C. Switch to a larger model. D. Give it write access to the website.
Answer: B. Off-brand output is a missing-context symptom: the agent lacks the company knowledge that defines the brand. More tools (A) and write access (D) add access, not context. A larger model (C) still won’t know your brand without being told.
Q2 · Which four kinds of context does an agent typically need? (Select one)
A. Task brief, source documents, company knowledge, prior decisions. B. Temperature, top-p, max tokens, seed. C. Model, region, plan tier, language. D. Font, colour, layout, length.
Answer: A. The four context types are the task brief, the source documents for the task, relevant company knowledge, and prior decisions already settled. B lists sampling settings, C lists account/config facts, and D lists formatting — none is the context an agent reasons from.
Q3 · A task only needs the agent to answer questions from one attached report. What access should it get? (Select one)
A. Web search plus write access to the shared drive. B. Read access to that report and nothing more. C. A connector to every company system, to be safe. D. Send-email capability so it can share the answer.
Answer: B. Least privilege: the task needs read access to the one document, so grant exactly that. Web and write (A), broad connectors (C) and send (D) all add blast radius the task never requires.
Q4 · What is least-privilege thinking for an agent? (Select one)
A. Grant every possible tool up front so it never stalls. B. Grant the minimum access the task requires and widen only on evidence of need. C. Grant access based on the seniority of the person delegating. D. Grant write access by default and read only if asked.
Answer: B. Least privilege starts from the minimum and expands only when a real run demonstrates a need. Granting everything (A) maximises blast radius. Seniority (C) isn’t the basis for an agent’s task access. Write-by-default (D) inverts the safe order of read-before-write.
Q5 · You connect an agent to a whole shared drive to give it one file. What is the risk? (Select one)
A. None; it will only open the file you meant. B. The agent can reach every file in the drive and may pull from files you didn’t intend. C. It will run more slowly. D. It will use a different model.
Answer: B. A connector exposes everything it reaches, and an autonomous agent may use any of it toward the goal — so it can surface data far beyond the one file. It will not politely restrict itself to your intended file (A). Speed (C) and model (D) are unaffected by scope.
Q6 · An agent reports it 'cannot access the CRM' and stops. What is the correct fix? (Select one)
A. Paste more background documents into the task. B. Grant a scoped read connector to the CRM records the task needs. C. Use a bigger model. D. Lower the temperature.
Answer: B. ‘Cannot access’ is a missing-access problem; grant the specific connector, scoped least-privilege to the records required. Pasting documents (A) addresses context, not access. Model size (C) and temperature (D) don’t grant access.
Q7 · Why can supplying too much context hurt an agent's output? (Select one)
A. It never hurts; more context is always better. B. Excess and stale documents bury the relevant signal and can anchor the agent on the wrong source. C. It changes the model’s price. D. It disables the agent’s tools.
Answer: B. Dumping everything in buries the authoritative signal and can make the agent over-weight irrelevant or outdated material. More context is not always better (A). It doesn’t change pricing (C) or disable tools (D).
Q8 · A task requires the agent to send an email after you approve it. How should access be arranged? (Select one)
A. Give it autonomous send so it can finish end to end. B. Give it draft creation now, with the send tool available only behind an approval checkpoint. C. Give it write access to the whole mail system. D. Give it no tools; it can describe the email in text.
Answer: B. Draft-before-send with the irreversible send gated behind approval is the least-privilege, safe arrangement. Autonomous send (A) removes the gate on an irreversible action. Whole-system write (C) is far broader than needed. No tools (D) under-provisions a task that must produce and eventually send a draft.
Q9 · An agent reopens a question the team settled last month. Which context was missing? (Select one)
A. Prior decisions — what has already been settled. B. A larger context window. C. Web search access. D. Write access to the project.
Answer: A. Relitigating a settled question is the signature of missing ‘prior decisions’ context; supply the record of what’s decided. A bigger window (B) doesn’t help if the decision was never provided. Web (C) and write (D) are access, not the missing context.
Q10 · Which TWO moves best reduce an agent's blast radius without necessarily reducing its ability to do the task? (Select two)
A. Grant read access instead of write when the task only reads. B. Scope a connector to the specific folder rather than the whole drive. C. Give it every connector available. D. Enable autonomous send for convenience. E. Remove the definition of done.
Answer: A and B. Read-instead-of-write (A) and scoping a connector to the needed folder (B) both shrink blast radius while leaving the task fully doable. Every connector (C) and autonomous send (D) enlarge blast radius. Removing the definition of done (E) harms the task and does nothing for safety.
Q11 · An agent drafting customer emails quotes an internal margin note that should never leave the company. What is the ROOT cause? (Select one)
A. The model hallucinated the note. B. The agent had reach into internal data it should never have been able to access; scope its access so the note is unreachable. C. The temperature was too high. D. The definition of done was too strict.
Answer: B. The agent could quote the note because it had reach to it — an over-provisioning/scoping failure; the fix is to make internal data unreachable. It didn’t hallucinate a real internal note it was given access to (A). Temperature (C) and a strict definition of done (D) are unrelated to the leak.
Q12 · Applying the read→write→send ladder, which is the correct default posture? (Select one)
A. Start at send and remove access if problems appear. B. Start at read, add write only if the task changes data, and gate send. C. Always grant write because most tasks need it. D. Grant send but not read, to limit exposure.
Answer: B. The safe order climbs the ladder only as far as the task requires: read first, write only to change data, send always gated. Starting at send (A) exposes irreversible actions first. Write-by-default (C) over-provisions. Send-without-read (D) is incoherent — it can act but not ground its action.
Q13 · A team lead wants to widen an agent's access after it stalled on a real task. When is widening justified? (Select one)
A. Never; access should stay fixed forever. B. When a real run demonstrates the task genuinely needs the additional access, granted as narrowly as possible. C. Whenever it would be convenient. D. Only for senior staff regardless of the task.
Answer: B. Least privilege widens on evidence: a real run showing a genuine need justifies the narrowest additional grant that unblocks it. Fixed-forever access (A) ignores real needs. Convenience (C) is the over-provisioning trap. Seniority (D) isn’t the basis for task-scoped access.
Q14 · An agent's renewal drafts cite an outdated policy and pull details from unrelated accounts. Which TWO fixes address the two distinct causes? (Select two)
A. Supply the current policy as the authoritative source of truth (fixes the context gap). B. Scope the connector to the specific account records, removing reach to unrelated files (fixes the over-provisioning). C. Switch to a larger model to improve accuracy. D. Remove all checkpoints to speed the run. E. Grant write access to every account.
Answer: A and B. The outdated policy is a context gap fixed by supplying the current policy (A); the cross-account leakage is an access/reach problem fixed by scoping the connector to the right records (B). A larger model (C) fixes neither cause. Removing checkpoints (D) and granting broad write (E) increase risk.
Key takeaways
- An agent needs four kinds of context: task brief, source documents, company knowledge, prior decisions — gaps get filled with guesses.
- More context is not always better; excess buries the authoritative signal and can anchor the agent on the wrong source.
- Match tools to the task on the read→write→send ladder; each step up adds capability and blast radius together.
- Least privilege: grant the minimum access the task needs and widen only on evidence — “to be safe, give it everything” is always the trap.
- A connector exposes everything it reaches; a workspace agent inherits that reach and will use it, so scope each connector narrowly.
- Distinguish missing context (off-brand, generic, reopens decisions) from missing access (“can’t reach the system”) — the fixes are opposite.
- Use CARE — Context, Access, Reach, Evidence — to provision an agent that is both competent and contained.
Last updated Sep 18, 2026