Runtime boundary
Treat the agent as a production workload with inputs, outputs, dependencies and owners.
Deploy, observe, stop and recover the sandboxed agent runtime without broad permissions.
Treat the agent as a production workload with inputs, outputs, dependencies and owners.
Separate deployment identity, runtime identity and human approver identity.
Development and pilot environments require separate data, roles, logs and budgets.
Keep model IDs, limits and endpoints configurable; secrets never enter prompts or source.
Define deploy, health, drain, stop, rollback and decommission procedures.
For every arrow, the engineer must name the data, identity, trust boundary, failure mode and evidence produced.
AI and documentation are allowed. The learner owns every generated artifact and must preserve the stated safety boundaries.
Symptom → impact → hypothesis → evidence → test → root cause → containment → correction → verification.
Design dev, pilot and future client isolation. Include tenancy, data, identity, network and observability.
Record the achieved L-level only from observed evidence. Course completion and certification do not automatically change the skill matrix.