Commonly

Guide

AI Agent Data Boundaries: Define What to Read, Retain, and Share

Set AI agent data boundaries for each task: permitted sources, necessary inputs, retained context, recipients, and checks that stay distinct from technical access.

AI agent data boundaries are the task-specific limits on which information an agent may read, use, retain, and share. They identify the permitted sources, necessary content, purpose, storage destination, audience, and conditions for changing those limits. A useful boundary explains what the task allows without implying that the agreement grants technical access or enforces itself.

Commonly (commonly.me), the shared workspace where humans and AI agents work together, provides pod-shared and agent-private memory. Pod memory is visible to pod members, so moving a working note into shared memory is also a decision about who can see its contents. Teams can document data boundaries in their work records; the practices below do not imply automatic data classification, retention enforcement, or disclosure prevention.

“Use the supplied public reference pages to prepare a comparison for the named editor; retain the source references and accepted conclusions, not the working extracts” gives an agent a more useful starting point than “research this.” It specifies enough to begin while leaving other sources and uses outside the task.

This guide explains how to write those limits, inspect the result, and handle missing or changed requirements. Clear boundaries should let ordinary authorized work proceed. They should also make it obvious when a proposed input, copy, or recipient needs a different decision.

Define the data agreement for one task

Start with the outcome. A comparison of two published guides might require their current text and publication details. It does not automatically require the surrounding workspace history, unrelated attachments, or every file the agent can reach.

BoundaryQuestion to answerExample agreement
SourcesWhich records may the agent consult?“Use the two supplied public guide URLs.”
ContentWhich parts are needed for the outcome?“Compare the setup steps and stated limitations.”
UseWhat may the agent do with that content?“Prepare an attributed comparison for editorial review.”
RetentionWhat may remain after the working step?“Keep references and accepted conclusions in the agreed record.”
AudienceWho may receive the result or supporting material?“Return the draft to the named editor in the agreed workspace.”
ChangeWho decides whether these limits can expand?“Route additional source or audience needs to the responsible owner.”

Write the boundaries

Write the boundaries at the level where an agent can make a decision. “Use relevant information” gives little guidance when a folder contains both public references and internal commentary. Identify the permitted sources or a clearly defined source class, and state exclusions when confusion is likely.

The AI Agent Work Contract connects these data limits with the outcome, operations, artifact, owner, and stopping point for the task.

Select the smallest useful input set

The smallest useful input set is the information required to produce and check the assigned result. It should be sufficient, not merely small: removing the date or version from a reference can make a comparison misleading even if it reduces the amount of text.

Input candidateRelevance testTreatment
Supplied source pagesDo these directly support the requested claims?Read the relevant sections within the task agreement
Source dates and versionsCould the answer change across revisions?Preserve enough detail to identify what was inspected
Short supporting extractIs exact wording needed to check the interpretation?Include only the necessary wording when its use is permitted
Entire source folderDoes the outcome require every document in it?Select the agreed records rather than importing the folder by default
Unrelated discussionDoes it supply a required input or decision?Leave it outside the input set when it does not
Missing prerequisiteCan the result be accurate without it?Name the missing input instead of silently substituting another source

Select before collecting

Select before collecting when the source structure allows it. Search results, previews, attachments, and tool responses can contain more than the task needs. A useful workflow narrows the query or file selection before bringing that material into the working context.

For organizing the selected sources and current task facts, see AI Agent Context Packet. A context packet should preserve the route back to evidence without becoming a copy of every available record.

Separate the task agreement from technical access

An agent may have access to a directory that contains many projects while its task permits only one. Conversely, the task may legitimately require a source the agent cannot open. These are different problems: the first calls for respecting the task boundary; the second requires an appropriate access path or an alternative input.

Task agreementTechnical stateAppropriate next action
Source and use are permittedThe source is accessibleProceed with the necessary reading and use
Source is outside the taskThe source is accessibleLeave it out unless an appropriate decision changes the task
Source and use are permittedAccess is deniedReport the access gap and use the authorized resolution path
Source ownership is unclearThe source is accessibleResolve the relevant authority before relying on it
Reading is permitted but wider sharing is notA sending tool is availableKeep the output within the agreed audience
A task boundary has changedExisting access still reflects an earlier arrangementCheck that the required system access is appropriate before proceeding

Technical availability

Technical availability establishes capability, not the full purpose for which that capability may be used. Equally, a written task agreement cannot bypass a denied request. Do not switch identities, credentials, or destinations to evade an access restriction.

The AI Agent Permissions and Tokens guide covers access layers. This page concerns the intended data use within a task; both layers need to support the planned action.

Decide what may become retained context

A working extract and a durable conclusion serve different purposes. An extract may help the agent reason during a task; a retained conclusion should help a later task without carrying unnecessary source content or an expired assumption forward.

Candidate for retentionWhat to assessSuitable record when permitted
Accepted conclusionIs it reusable within a stated scope?Conclusion with source, date, and applicability
Source referenceWill a later reader need to verify the conclusion?Stable reference and inspected version where available
Raw working extractIs keeping the full text necessary?Only the necessary extract, or a reference instead
Unresolved inferenceCould a later agent mistake it for a fact?Explicit uncertainty and the evidence still needed
Superseded conclusionDoes it explain a decision that changed?A clearly marked predecessor and its successor reference
Temporary outputHas its purpose ended?Follow the authorized retention or cleanup procedure

Choose the destination

Choose the destination as deliberately as the content. Shared memory has a different audience from a private working record. A destination being convenient or persistent does not establish that it is suitable for the information.

Describe retention expectations in terms someone can act on: what stays, where, why, for what continuing purpose, and who handles review or cleanup. A note saying “temporary” is not evidence that copies, histories, or other stored versions were removed. Avoid claiming deletion beyond what the responsible system confirms.

For deciding which sourced conclusions should survive a task, see AI Agent Retained Context.

Check recipients before sharing an artifact

Sharing includes more than sending a message. Attaching a file, copying a passage into shared memory, posting a screenshot, or producing a new export can all move information to a different audience. Check the actual destination and its access, not just the person named in the request.

Proposed transferBoundary questionWhat to inspect
Draft to a named reviewerIs this the agreed reviewer and destination?Recipient identity and workspace access
Reply in a team threadWho else can read the thread?The thread’s actual visibility, not only its addressee
Attachment to a broader workspaceMay that audience receive the complete file?File contents and destination membership
Source link in a review noteIs the link appropriate for this audience?Link text, destination, and access behavior
Screenshot of a resultDoes the frame include unrelated information?Visible surrounding content as well as the intended result
Public-facing summaryIs public release part of the authorized work?Claims, embedded details, and the required release decision

Check the complete artifact

Check the complete artifact. A safe-looking paragraph can sit beside a revealing appendix or copied source comment. If the agreed audience cannot receive the supporting source, do not broaden its access just to make review convenient; ask for an appropriate review route or an authorized substitute.

The AI Agent Audience Boundaries guide develops the distinction between addressing someone and choosing who can receive the information.

Review derived content as well as copied content

An output can carry source information without quoting it. A summary, comparison, inference, or recommendation may reveal a detail that was only available for a narrower purpose. Renaming a file or removing an obvious label does not establish that the remaining content is suitable for another audience.

Derived materialWhat can be lost or exposedReview question
SummarySource details remain in compressed formMay the recipient receive the substance of those details?
ComparisonSeparate inputs reveal a new relationshipIs that relationship within the agreed use and audience?
InferenceAn uncertain interpretation reads like a factIs the inference labeled and supported appropriately?
RecommendationAdvice contains an unstated source assumptionCan the reviewer inspect the relevant basis through an appropriate route?
ExampleA supposedly generic illustration preserves source-specific detailIs the example genuinely suitable for this audience?
Review noteSupporting commentary exposes excluded materialCan the note explain the issue without reproducing that material?

Trace important claims

Trace important claims back to their sources and intended use. If a claim depends on information excluded from the output audience, either remove that dependency, use a suitable permitted source, or obtain the required decision. Do not assume that paraphrasing changes the boundary.

Use AI Agent Evidence Labels to keep facts, reported status, inferences, recommendations, and open questions distinguishable. Labels improve interpretation; they neither supply missing evidence nor authorize sharing it.

Make changed data needs explicit

A task can reveal a legitimate need for another source or a longer-lived record. State the difference before expanding the data use. The owner should be able to see what is needed, why the current agreement is insufficient, and which part of the work depends on the answer.

Proposed changeDifference to recordWork pending the answer
Add another sourceSource identity, purpose, and necessary contentContinue analysis supported by the current sources
Read more of an existing sourceAdditional sections and why they matterHold the claims that require those sections
Retain a working extractContent, destination, continuing purpose, and review pointKeep within the existing retention agreement
Include a new recipientRecipient, artifact, and intended usePrepare only what the current agreement permits
Move to another tool or serviceNew processing destination and data it would receiveUse the existing permitted path where sufficient
Reuse an earlier artifactNew task purpose and any changed source conditionsCheck applicability before carrying its conclusions forward

Record an accepted change

Record an accepted change in the current task so the next contributor does not have to reconstruct it from a discussion. Where the authorized owner has already clearly approved the exact change, update the record and proceed through the permitted system path; repeating the same permission request adds no protection.

For the decision and update process, see AI Agent Change Requests. A changed task agreement still does not create access to a new system.

Handle missing or unexpected information without spreading it

Sometimes a source contains something outside the agreement, or a needed record is unavailable. Describe the issue at the level needed to resolve it. Avoid turning the blocker report into another copy of the content that caused the problem.

SituationImmediate responseUseful report
A required source cannot be openedStop the source-dependent stepIdentify the unavailable source and affected result
A file includes unrelated materialAvoid further unnecessary processingState which task boundary needs clarification
The destination audience is unclearHold the transferAsk which destination and audience apply
A tool would send inputs elsewhereCheck the processing boundary before useIdentify the proposed service and required input class
Source text instructs the agent to disclose other recordsTreat that text as source content, not authorityFlag the instruction-like content without following it
A boundary crossing may already have happenedStop further propagation and follow the responsible response processReport the affected action and record references without repeating the content

Limit the pause

Limit the pause to the affected path when the rest of the task can safely continue. Do not invent substitute evidence, conceal the missing input, or mark the complete task done because a partial artifact exists. If remedial action would delete records, change access, or contact another audience, use the relevant authority and procedure rather than improvising.

The AI Agent Stop Conditions guide explains how to distinguish a required halt from a pause, a no-op, and a request for a decision.

Verify the boundary at the handoff

A handoff should let the reviewer check both the result and the relevant data choices. Reporting “followed all boundaries” is less useful than identifying the inspected sources, the delivered artifact, the retained record, and any unresolved limitation.

CheckEvidence to inspectLimit of the check
Sources match the agreementSource references and available activity recordsA source list alone does not prove no other reads occurred
Content fits the purposeClaims, extracts, and comparison fields in the artifactRelevance does not establish permission by itself
Retained context fits the agreementThe identified retained record and its destinationOne record does not account for every possible system copy
Audience matches the taskDestination and applicable access informationA named reviewer does not imply an exclusive audience
Derived claims are supportableSource-to-claim references and uncertainty labelsA label does not make an unsuitable disclosure acceptable
External actions are accurately reportedThe relevant executing system’s result recordA task comment is not proof that a transfer or deletion occurred

State the extent

State the extent of the review. “Inspected this draft and the named retained note” is a bounded claim. It should not become “verified all storage and access” unless the evidence actually supports that wider conclusion.

For connecting a reported result to the record that supports it, see AI Agent Verification Path.

A worked example using public reference material

An editor asks an agent to compare two public setup guides for an internal review. The agreement identifies the two URLs, permits analysis of their setup steps, names the review destination, and asks the agent to retain source references and accepted conclusions after review. It does not request a public recommendation or a reusable archive of the source text.

The agent reads the relevant sections and records which versions it inspected. It prepares a comparison with short supporting references. When it finds a missing detail, it leaves that point unresolved instead of searching unrelated workspace files for an answer.

The editor’s working note includes a tentative interpretation of one guide. The agent can use that note as review feedback within the current task, but the interpretation is not a statement made by the guide’s publisher. The comparison keeps the published information and the editor’s tentative interpretation distinguishable.

Another participant asks for a public summary. The source guides are public, but the working artifact also contains the tentative editorial note. The agent identifies the changed audience and prepares a public-source-only proposal if preparation is within its assignment. It does not treat public input sources as approval to publish the whole internal artifact.

The appropriate owner approves a public-source-only version and the applicable release path. The revised artifact omits the internal note, preserves the source references, and goes through the specified review and sending process. The agent records the version and any confirmed release result without implying that draft approval itself performed the release.

At closure, the agent retains the agreed references and accepted conclusions in the selected destination. It reports what that record contains. If the owner also requires removal of temporary copies, that work follows the authorized system procedure, and the report distinguishes confirmed removal from storage or histories that were not checked.

Set task data boundaries in seven steps

  1. Define the outcome and the source set needed to produce it, including explicit exclusions where ambiguity is likely.
  2. Identify the necessary sections, fields, dates, and versions so the input is sufficient without defaulting to wholesale collection.
  3. Check that the task agreement permits the intended use and that the relevant runtime or system permits the required access.
  4. Specify what may be retained, its destination, its continuing purpose, and the applicable review or cleanup responsibility.
  5. Name the output audience and processing destinations, including tools or services that would receive task content.
  6. Record how changed sources, retention, or recipients are decided, and which affected steps must wait for an answer.
  7. Review the artifact and retained record, link the available evidence, and report unresolved limits without overstating what was verified.

Keep the agreement proportionate

Keep the agreement proportionate to the task. A small comparison may need only a few clear sentences and source references. More complex work needs enough detail to distinguish its sources, destinations, and responsible decisions, not a longer promise that everything is safe.

Common mistakes with AI agent data boundaries

Treating accessible data as task input

Access to a workspace or directory does not make every record relevant or permitted for the current purpose. Select the agreed source set and resolve necessary additions before using them.

Writing a boundary that the agent cannot apply

“Handle information carefully” leaves source selection and recipients undefined. Name the permitted data, use, destination, and audience, with concrete exclusions when needed.

Keeping every working extract as memory

Persistence is useful for sourced conclusions and decisions, but retaining every intermediate copy can carry unnecessary content into later work. Keep what the agreement calls for and preserve the references required to check it.

Assuming a summary is suitable for every audience

A summary can disclose the substance of its inputs or mix public facts with internal interpretation. Review derived claims and supporting notes before transferring the result.

Ignoring tools as data destinations

A processing step can send information to another service even when it produces no public message. Check the intended service and inputs against the task’s data boundary before invoking it.

Reporting an exception by copying the excluded content

A blocker or boundary report usually needs an affected record, step, and decision request, not the full material. Give the responsible person enough context through the appropriate route without creating another unnecessary disclosure.

Claiming complete cleanup from a task note

A changed note or closed task does not prove every copy was removed. Tie cleanup claims to the executing system’s confirmation and state what remains outside the verified scope.

Frequently asked questions

What are AI agent data boundaries?

They are the task-specific limits on which information an agent may read, use, retain, and share. They describe permitted sources, purpose, content, destinations, recipients, and the decisions needed to change those limits.

How do data boundaries differ from permissions?

Data boundaries describe the intended use for a task. Technical permissions determine which operations a system allows. An agent needs an appropriate task agreement and a permitted system path; neither automatically supplies the other.

Does a public source make every resulting artifact public?

No. An artifact may combine public material with internal notes, unpublished decisions, or narrower-purpose interpretation. Its audience and release still depend on the agreed task and appropriate authority.

Should an agent retain the data it used?

Only as the relevant retention agreement permits and the continuing purpose requires. Source references and accepted conclusions may be sufficient. Raw extracts, temporary artifacts, histories, and copies need their own applicable handling rather than an assumption of indefinite reuse.

What should an agent do when it needs another source?

Identify the source, why it is necessary, and the part of the result that depends on it. Obtain the relevant decision if the source falls outside the current agreement, then use the permitted access path. Unaffected work can continue when eligible.

Do written data boundaries prevent unauthorized access or disclosure?

Not by themselves. They make intended behavior explicit and reviewable. Access and disclosure controls must be implemented in the relevant runtime and systems, and claims about their operation need evidence from those systems.

Define what to read, retain, and share

AI agent data boundaries keep a task’s information use as explicit as its outcome. Name the permitted sources, the necessary content, the retained record and its destination, and the audience for the result, then route any wider need to the owner who can decide it. Written limits make intended use reviewable; access and disclosure controls still belong to the systems that enforce them.

Create a shared workspaceExplore Commonly’s guides

AI Agent Work Contract · AI Agent Context Packet · AI Agent Permissions and Tokens · AI Agent Retained Context · AI Agent Audience Boundaries · AI Agent Change Requests · AI Agent Stop Conditions