Security & governance · Glossary term
What is Trust Boundary?
An interface where data, instructions, identity, or authority crosses between components or principals that operate under different trust assumptions.
Why does Trust Boundary matter?
A boundary crossing is where the system must authenticate actors, validate data, constrain permissions, and decide which claims can influence action.
Trust Boundary in practice
Draw boundaries around users, model context, retrieval sources, tools, networks, and data stores, then specify validation and authorization for every crossing.
What is the common confusion about Trust Boundary?
A network boundary is only one kind of trust boundary. Untrusted document text entering a privileged agent context also crosses one.
Learn Trust Boundary in the course
Start with
- Capstone 82 — Jailbreak Taxonomy
A safety harness without a taxonomy is a coin flip. Name the attack before you defend it. A model deployed without an attack model is a model defended against nothing in particular.
Lessons that name Trust Boundary in a title or section
- Skill Discovery and Progressive Disclosure
A skill becomes useful before its body is loaded. Its name and description earn a place in the catalog; its deeper files earn context only when the task reaches them.
Taught in Phase 19: Capstone Projects.
Also covered in Phase 13: Tools & Protocols.
Related terms
- Threat ModelA documented account of protected assets, trust boundaries, potential adversaries, assumed capabilities, attack paths, impacts, and…
- Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
- SandboxAn isolated execution environment that restricts an agent's access to files, processes, network destinations, credentials, and host…
- Indirect Prompt InjectionA prompt-injection attack delivered through content the system retrieves or observes, such as a webpage, document, email, image text, or…
- Data ClassificationAssigning data to documented sensitivity or impact classes so handling, access, retention, sharing, and incident rules follow the…
- Data ExfiltrationUnauthorized transfer of protected data from a system or trust zone to a person, tool, service, or storage location that is not permitted…
- Defense in DepthUsing independent preventive, detective, and corrective controls at several system boundaries so one failed control does not determine the…
- Skill DiscoveryA runtime pipeline that searches configured roots, identifies candidate skill directories, validates their package contract, attaches…
- Zero TrustA security model that grants no implicit trust from network location or asset ownership and instead evaluates each access request against…
Sources
More terms in Security & governance
- AI Risk Assessment
- Audit Log
- Content Provenance
- Data Classification
- Data Exfiltration
- Data Lineage
- Data Minimization
- Datasheet for Datasets
- Defense in Depth
- Indirect Prompt Injection
- Jailbreak
- Membership Inference
- Provenance Attestation
- Purpose Limitation
- Red Teaming
- Separation of Duties
- Software Bill of Materials (SBOM)
- Threat Model
- Zero Trust
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.