AI Cert Prep
Type to search documentation.

Agents and Workflows

D3 · Context, Tools and Permissions

Giving an agent the context it needs, the tools and connectors to do the work, and no more access than the task requires — with least-privilege thinking and workspace-agent scoping.

The second of the two heaviest domains — 18%, about 9 of 50 items. It tests two paired judgments: giving an agent enough context and tools to succeed, and giving it no more access than the task needs. Under-provision and the agent guesses; over-provision and you have handed a capable, literal worker keys to rooms it never needed to enter. The material rewards least-privilege thinking applied to a workspace agent that acts on your behalf and inherits reach you may not have thought about.

What you need to know

An agent needs four kinds of context: the task brief (from D2), the source documents for this task, relevant company knowledge (policies, standards, product facts), and prior decisions so it doesn’t relitigate settled questions. It needs tools and connectors to reach data and take actions — but each one is capability and blast radius. Least privilege means granting the minimum context and access the task requires and widening only on evidence of need. A workspace agent acts with real reach into shared files, connectors and systems, so its scope must be set deliberately: what it can read, what it can write, and where it must stop. Context and access are the two halves of the same setup: the right context makes the agent competent; the right access makes it safe.

Learning objectives

By the end of this page you should be able to:

  1. Identify the four kinds of context an agent needs and supply each from the right place.
  2. Distinguish context the agent needs from noise that degrades its work.
  3. Match tools and connectors to what the task actually requires.
  4. Apply least-privilege thinking to an agent’s access, separating read from write and internal from external.
  5. Scope a workspace agent deliberately, reasoning about the reach it inherits.
  6. Diagnose whether a failure came from missing context or from missing access.

3.1 The four kinds of context

An agent starts with only what you give it plus what its tools can fetch. Missing context is the most common cause of confidently wrong work — the agent fills the gap with a guess.

Context typeWhat it isWhere it comes fromSymptom when missing
Task briefGoal, done, constraints (D2)You, in the delegationWrong outcome, wrong scope
Source documentsThe specific inputs for this taskUploads, attached filesIt uses generic or invented facts
Company knowledgePolicies, standards, product facts, toneCompany-knowledge / connectorsOff-brand, off-policy output
Prior decisionsWhat’s already been settledProject notes, prior threadsIt reopens closed questions
text
what the agent knows
┌───────────────────────────────────────────┐
│ TASK BRIEF (why + what + done) │ you supply
│ SOURCE DOCS (the inputs for this task) │ you attach
│ COMPANY KNOW. (how we do things here) │ workspace provides
│ PRIOR DECISIONS(what's already decided) │ you point to
└───────────────────────────────────────────┘
gaps here ─► the agent guesses to fill them

Assessment signal

When a stem describes output that is competent-but-generic, off-brand, or reopens a decided question, the fix is almost always supply the missing context (source doc, company knowledge, or prior decision) — not a bigger model or more tools.

3.2 More context is not always better

Context has a cost. Dumping every document you have into the task buries the relevant signal and can actively mislead the agent toward whatever was longest or most recent. The skill is supplying what’s relevant and authoritative, not everything available.

Too little contextRight contextToo much context
Agent guesses missing factsAgent grounds its workSignal buried; agent over-weights irrelevant docs
Off-brand, generic outputOn-brand, specific outputContradictions between stale and current docs
Reopens settled questionsRespects prior decisionsAnchors on the wrong source

The connection to D2’s sources of truth is direct: name what’s authoritative and supply that, rather than everything and hoping the agent sorts it out. When in doubt, supply the specific source document and the relevant slice of company knowledge — not the entire drive.

3.3 Tools and connectors: matching capability to the task

Tools are how an agent reaches beyond the text in front of it — search, file access, connectors to shared systems, the ability to draft or send. Provisioning is a matching exercise: what does this task genuinely require?

The task needs to…ProvideDo NOT provide
Answer from a supplied documentRead access to that documentWeb, write, or send tools
Synthesise current public informationWeb search (read-only)Any connector that can edit/send
Pull facts from a shared systemA read connector to that systemWrite access to it
Produce a draft for you to sendDraft/artefact creationAutonomous send
Actually send/publish after approvalThe send tool behind a checkpointUngated send

The pattern: read before write, draft before send, one system before many. Every step up that ladder adds capability and blast radius together, so take each step only when the task requires it.

3.4 Least-privilege thinking

Least privilege is the governing principle of the whole domain: grant the minimum access the task needs, and widen only on evidence of need. It is the opposite of the tempting “give it everything so it never gets stuck” default.

text
blast radius
low ◄──────────────────────────► high
read one read shared write send /
document system data publish / pay
│ │ │ │
start here ─┘ │ │
widen only if a run │ │
actually needs it ─────────┴─────────┘
gate anything on the right

Why it matters specifically for agents: an agent is autonomous and literal. If it can reach something, it may — to satisfy the goal — touch data or take an action you never intended. Narrow access means a misunderstanding stays contained. Broad access means a misunderstanding becomes an incident.

Least-privilege moveEffect
Grant read, not writeA misread can’t corrupt data
Scope a connector to one folder, not the driveLimits what’s exposed
Gate send/publish behind approvalIrreversible actions can’t fire unwatched
Time-box or spend-cap the runBounds runaway cost (developed in D4)

Assessment signal

“To be safe, give it broad access” is always the wrong reasoning in these stems. Broad access is broad blast radius. The correct answer starts from the minimum and widens on evidence — the phrase to reward is least privilege / only what the task needs.

3.5 An agent inherits reach — think about what it can touch

A workspace agent acts on your behalf and through the connectors and permissions it’s been given. That means it can reach whatever those connectors reach — which may be more than the immediate task suggests. Before delegating, ask what the granted access actually exposes.

You granted…The agent can therefore reach…Question to ask first
A connector to a shared driveEvery file in that drive, not just the one you meantCan I scope it to the folder?
Access to a channel or inboxThe whole history, including sensitive threadsDoes the task need the history?
A connector to a system of recordWhatever your permissions there allowShould the agent have all of my reach?
Send-on-your-behalfThe ability to act as you, externallyDoes this need a gate?

The principle: the agent’s reach is the union of the connectors you enable, and it will use any of them if the goal seems to call for it. Scope each connector to the narrowest slice that works.

3.6 Diagnosing missing context versus missing access

When an agent underperforms, distinguish the two failure families — the fixes are opposite.

text
Agent's output is wrong or incomplete
│
├─ Did it act on wrong/generic facts, go off-brand,
│ or reopen a settled question? ──► MISSING CONTEXT
│ fix: supply the source doc /
│ company knowledge / prior decision
│
└─ Did it say it "couldn't access", stop short of a
step, or fail to reach a needed system? ──► MISSING ACCESS
fix: grant the specific tool/connector
(least privilege), not everything

Confusing the two wastes effort: granting more tools won’t fix an off-brand answer (that’s context), and pasting more documents won’t fix “I don’t have access to the CRM” (that’s a connector). Read the symptom, then apply the matching fix.

Decision framework

Use the CARE provisioning checklist before every delegation: Context, Access, Reach, Evidence. Fill each and you provision an agent that is both competent and contained.

StepQuestionThe disciplined answer
C — ContextWhat must it know to do this well?Task brief + the specific source docs + relevant company knowledge + prior decisions — and nothing that buries the signal
A — AccessWhat tools does the task actually require?The minimum on the read→write→send ladder; draft not send unless gated
R — ReachWhat does that access let it touch beyond the task?Scope each connector to the narrowest slice; check inherited reach
E — EvidenceWhen do I widen access?Only when a real run demonstrably needs more — not “to be safe”

Apply it tomorrow: for any task, write the four rows. If Access or Reach is broader than the task needs, narrow it before you run — that is least privilege in practice.

Common mistakes

MistakeWhy it happensWhat to do instead
Under-provisioning context, then blaming the modelYou assumed it “knew” your policiesSupply source docs, company knowledge and prior decisions
Dumping every document into the task“More context is safer”Supply the relevant, authoritative slice; excess buries signal
Granting broad access “to be safe”Fear of the agent getting stuckStart least-privilege; widen only on evidence of need
Giving write when read would doNot separating the twoRead before write; a misread can’t corrupt data
Enabling send instead of draftWanting end-to-end automationDraft for you; gate the send (D4)
Ignoring what a connector inheritsThinking only of the immediate fileThe agent can reach everything the connector reaches — scope it
Fixing an off-brand answer with more toolsConfusing context with accessOff-brand is a context gap; supply company knowledge
Fixing “can’t access” by pasting more textConfusing access with contextGrant the specific connector, least-privilege

Scenario challenge

Scenario. Amara, a customer-success lead on ChatGPT Work, wants an agent to draft renewal-summary emails for twelve accounts up for renewal this quarter. She connects the agent to the shared customer drive and to the team inbox so it “has everything it needs”, and gives it the goal. The drafts come back citing an outdated pricing policy, referencing details from unrelated customers’ files, and one draft quotes an internal margin note that should never leave the company. Amara wonders whether the agent is simply unreliable for this kind of work.

Expert reasoning trace.

  1. Separate context from access. Two distinct problems are tangled here: the outdated pricing policy is a context failure (it used stale knowledge), while referencing unrelated customers and quoting an internal margin note are reach failures (it touched data it should never have reached).
  2. Fix the context gap with authoritative sources, not more tools. The outdated policy means the current pricing policy wasn’t supplied as authoritative company knowledge; the agent fell back on whatever it found. Supply the current policy and name it as the source of truth (D2).
  3. Diagnose the over-provisioning. Connecting the whole shared drive and the whole team inbox handed the agent reach across every customer’s files and every internal thread. It’s a literal, autonomous worker: given a renewal task and access to everything, it pulled from everything.
  4. Apply least privilege / scoping. The task needs, per account, that account’s file — not the entire drive. Scope the connector to the specific renewal folder or the twelve account records, and remove the inbox connector entirely (drafting emails doesn’t require read access to the inbox history). The internal margin note should never have been reachable.
  5. Add the read/write and draft/send distinctions. The agent needs read access to account data and the ability to produce drafts. It does not need send — the emails should land as drafts for Amara to review and send, gating the one irreversible step.
  6. Provision, don’t abandon. The agent isn’t “unreliable for this work”; it was mis-provisioned. Re-run with scoped read access to the right records, the current policy as authoritative context, draft-only output, and the internal note out of reach — and the same agent produces safe, on-policy drafts.

The point. “Give it everything so it has what it needs” caused both the leakage and the noise. The fix is CARE: supply the right context (current policy), scope access to the account records, check reach so internal notes are unreachable, and widen only on evidence — none of which requires a different model.

Assessment traps

TrapWhy it is temptingThe discriminator
“Connect it to everything so it has what it needs”Feels thorough and avoids blockersBroad access is broad reach; scope to the task (least privilege)
“Off-brand output means we need a better model”Quality problem feels like capabilityOff-brand is a missing-context problem; supply company knowledge
“Paste all the documents in to be safe”More context seems saferExcess context buries signal and anchors on wrong sources
“Give write access so it can just finish”End-to-end automation is appealingRead before write; write is far larger blast radius
“A connector only exposes the file I mean”You think of the one documentA connector exposes everything it reaches — scope it
“‘Can’t access’ means paste more context”Any gap looks like a context gap‘Can’t access’ is a missing-tool problem; grant the specific connector

Practice questions

Each item states how many responses to select. Attempt before revealing.

Q1 · An agent produces competent but generic, off-brand copy. Which fix is MOST appropriate? (Select one)

A. Grant it more tools and connectors. B. Supply the relevant company knowledge — brand voice, style guide and product facts — as authoritative context. C. Switch to a larger model. D. Give it write access to the website.

Answer: B. Off-brand output is a missing-context symptom: the agent lacks the company knowledge that defines the brand. More tools (A) and write access (D) add access, not context. A larger model (C) still won’t know your brand without being told.

Q2 · Which four kinds of context does an agent typically need? (Select one)

A. Task brief, source documents, company knowledge, prior decisions. B. Temperature, top-p, max tokens, seed. C. Model, region, plan tier, language. D. Font, colour, layout, length.

Answer: A. The four context types are the task brief, the source documents for the task, relevant company knowledge, and prior decisions already settled. B lists sampling settings, C lists account/config facts, and D lists formatting — none is the context an agent reasons from.

Q3 · A task only needs the agent to answer questions from one attached report. What access should it get? (Select one)

A. Web search plus write access to the shared drive. B. Read access to that report and nothing more. C. A connector to every company system, to be safe. D. Send-email capability so it can share the answer.

Answer: B. Least privilege: the task needs read access to the one document, so grant exactly that. Web and write (A), broad connectors (C) and send (D) all add blast radius the task never requires.

Q4 · What is least-privilege thinking for an agent? (Select one)

A. Grant every possible tool up front so it never stalls. B. Grant the minimum access the task requires and widen only on evidence of need. C. Grant access based on the seniority of the person delegating. D. Grant write access by default and read only if asked.

Answer: B. Least privilege starts from the minimum and expands only when a real run demonstrates a need. Granting everything (A) maximises blast radius. Seniority (C) isn’t the basis for an agent’s task access. Write-by-default (D) inverts the safe order of read-before-write.

Q5 · You connect an agent to a whole shared drive to give it one file. What is the risk? (Select one)

A. None; it will only open the file you meant. B. The agent can reach every file in the drive and may pull from files you didn’t intend. C. It will run more slowly. D. It will use a different model.

Answer: B. A connector exposes everything it reaches, and an autonomous agent may use any of it toward the goal — so it can surface data far beyond the one file. It will not politely restrict itself to your intended file (A). Speed (C) and model (D) are unaffected by scope.

Q6 · An agent reports it 'cannot access the CRM' and stops. What is the correct fix? (Select one)

A. Paste more background documents into the task. B. Grant a scoped read connector to the CRM records the task needs. C. Use a bigger model. D. Lower the temperature.

Answer: B. ‘Cannot access’ is a missing-access problem; grant the specific connector, scoped least-privilege to the records required. Pasting documents (A) addresses context, not access. Model size (C) and temperature (D) don’t grant access.

Q7 · Why can supplying too much context hurt an agent's output? (Select one)

A. It never hurts; more context is always better. B. Excess and stale documents bury the relevant signal and can anchor the agent on the wrong source. C. It changes the model’s price. D. It disables the agent’s tools.

Answer: B. Dumping everything in buries the authoritative signal and can make the agent over-weight irrelevant or outdated material. More context is not always better (A). It doesn’t change pricing (C) or disable tools (D).

Q8 · A task requires the agent to send an email after you approve it. How should access be arranged? (Select one)

A. Give it autonomous send so it can finish end to end. B. Give it draft creation now, with the send tool available only behind an approval checkpoint. C. Give it write access to the whole mail system. D. Give it no tools; it can describe the email in text.

Answer: B. Draft-before-send with the irreversible send gated behind approval is the least-privilege, safe arrangement. Autonomous send (A) removes the gate on an irreversible action. Whole-system write (C) is far broader than needed. No tools (D) under-provisions a task that must produce and eventually send a draft.

Q9 · An agent reopens a question the team settled last month. Which context was missing? (Select one)

A. Prior decisions — what has already been settled. B. A larger context window. C. Web search access. D. Write access to the project.

Answer: A. Relitigating a settled question is the signature of missing ‘prior decisions’ context; supply the record of what’s decided. A bigger window (B) doesn’t help if the decision was never provided. Web (C) and write (D) are access, not the missing context.

Q10 · Which TWO moves best reduce an agent's blast radius without necessarily reducing its ability to do the task? (Select two)

A. Grant read access instead of write when the task only reads. B. Scope a connector to the specific folder rather than the whole drive. C. Give it every connector available. D. Enable autonomous send for convenience. E. Remove the definition of done.

Answer: A and B. Read-instead-of-write (A) and scoping a connector to the needed folder (B) both shrink blast radius while leaving the task fully doable. Every connector (C) and autonomous send (D) enlarge blast radius. Removing the definition of done (E) harms the task and does nothing for safety.

Q11 · An agent drafting customer emails quotes an internal margin note that should never leave the company. What is the ROOT cause? (Select one)

A. The model hallucinated the note. B. The agent had reach into internal data it should never have been able to access; scope its access so the note is unreachable. C. The temperature was too high. D. The definition of done was too strict.

Answer: B. The agent could quote the note because it had reach to it — an over-provisioning/scoping failure; the fix is to make internal data unreachable. It didn’t hallucinate a real internal note it was given access to (A). Temperature (C) and a strict definition of done (D) are unrelated to the leak.

Q12 · Applying the read→write→send ladder, which is the correct default posture? (Select one)

A. Start at send and remove access if problems appear. B. Start at read, add write only if the task changes data, and gate send. C. Always grant write because most tasks need it. D. Grant send but not read, to limit exposure.

Answer: B. The safe order climbs the ladder only as far as the task requires: read first, write only to change data, send always gated. Starting at send (A) exposes irreversible actions first. Write-by-default (C) over-provisions. Send-without-read (D) is incoherent — it can act but not ground its action.

Q13 · A team lead wants to widen an agent's access after it stalled on a real task. When is widening justified? (Select one)

A. Never; access should stay fixed forever. B. When a real run demonstrates the task genuinely needs the additional access, granted as narrowly as possible. C. Whenever it would be convenient. D. Only for senior staff regardless of the task.

Answer: B. Least privilege widens on evidence: a real run showing a genuine need justifies the narrowest additional grant that unblocks it. Fixed-forever access (A) ignores real needs. Convenience (C) is the over-provisioning trap. Seniority (D) isn’t the basis for task-scoped access.

Q14 · An agent's renewal drafts cite an outdated policy and pull details from unrelated accounts. Which TWO fixes address the two distinct causes? (Select two)

A. Supply the current policy as the authoritative source of truth (fixes the context gap). B. Scope the connector to the specific account records, removing reach to unrelated files (fixes the over-provisioning). C. Switch to a larger model to improve accuracy. D. Remove all checkpoints to speed the run. E. Grant write access to every account.

Answer: A and B. The outdated policy is a context gap fixed by supplying the current policy (A); the cross-account leakage is an access/reach problem fixed by scoping the connector to the right records (B). A larger model (C) fixes neither cause. Removing checkpoints (D) and granting broad write (E) increase risk.

Key takeaways

  • An agent needs four kinds of context: task brief, source documents, company knowledge, prior decisions — gaps get filled with guesses.
  • More context is not always better; excess buries the authoritative signal and can anchor the agent on the wrong source.
  • Match tools to the task on the read→write→send ladder; each step up adds capability and blast radius together.
  • Least privilege: grant the minimum access the task needs and widen only on evidence — “to be safe, give it everything” is always the trap.
  • A connector exposes everything it reaches; a workspace agent inherits that reach and will use it, so scope each connector narrowly.
  • Distinguish missing context (off-brand, generic, reopens decisions) from missing access (“can’t reach the system”) — the fixes are opposite.
  • Use CARE — Context, Access, Reach, Evidence — to provision an agent that is both competent and contained.

Last updated Sep 18, 2026