Data classification scheme
A data classification scheme is applied to all data accessible to the agent. The agent's authorization is constrained by classification.
All data the agent may encounter is classified according to a documented scheme — typically public, internal, confidential, restricted — and the agent's authorization is constrained by classification. The agent cannot access data at a classification level above its authorization, and classification boundaries are enforced at the retrieval and prompt layers.
Classification scheme is documented and applied to all data sources accessible to the agent; agent authorization levels are mapped to classification tiers; enforcement is tested as part of pre-deployment evaluation.