Everyone will have agents working for them, and not just one. They’ll use different agents to read their mail, file expenses, pay vendors, write code, and trade their portfolios. That work requires real access to business systems: email, files, customer records, and bank accounts.
Anything an agent reads can influence its behavior. Attackers plant instructions in pull requests, support tickets, and forms to steal API keys, access tokens, and customer data. In a red-team test at a frontier AI lab, an agent asked to draft an out-of-office reply followed instructions in a planted email and sent a resignation letter to the user’s CEO instead. The pattern is the same: attackers supply the instructions, and agents supply the access.
Filters, confirmations, and sandboxes lower the odds of something going wrong. But none of them can tell you what an agent will never do. One failure is enough.
Basefield takes a different approach. It continuously monitors your agent’s actions using a dynamic task-based policy expressed in mathematical logic. With Basefield, your agents work freely and safely, without forcing you to hand-write policies or reason about edge cases. Every action is proven safe before it happens, and no interaction with untrusted emails or web content can ever compromise safety.
Sivanarayana Gaddam Rohit Sinha Founders