Guardrails for an app that touches money

A layered defence for the A1 agent: prompt-injection checks, personal-data filters, role checks on every tool, and a red-team test suite.

A2AdvancedLockedAuth and guardrailsEvaluation and testing

Why this build, here

Mobile money fraud in Zambia already runs on social engineering. An AI agent is one more thing to talk into mistakes, including through documents and messages it reads. NRC numbers and phone numbers must not leak into logs or answers.

The build, step by step

  1. Attack your own agent

  2. Check permissions in code

  3. Filter input and output

  4. Separate instructions from data

  5. Make it a regression suite

The steps, checks and practice open with a code

You can see what this lesson builds. The detail of each step, the finished-when checks and interview scoring come with the K850 practice, along with weekly build sessions and code review.

Codes come with the K850 practice. Book a place

Read and run

Interview practice

Questions on this topic from AI Engineering Interview Questions, company-wise, with the companies it lists. Write your answer the way you would say it; Jev scores it and DeepSeek tells you what to add.

Scoring opens with an access code. You can still read the questions and prepare.

Chat on WhatsApp