Another employee's HR data
An ordinary employee obtains salary or evaluation information through a broadly authorized agent.
The material risk is not only an incorrect answer. It is an unauthorized data access, action, transmission, or tool sequence that actually succeeds.
An ordinary employee obtains salary or evaluation information through a broadly authorized agent.
After denial by the primary database, the agent searches a DWH, file repository, RAG index, or email.
A read-only user causes an update, export, external transmission, or deletion through an agent tool.
The agent follows malicious instructions embedded in retrieved documents or web pages.
Equivalent requests receive different authorization outcomes after rephrasing or multi-turn prompting.
There is no reliable record of data sources, tool calls, denial decisions, or post-denial attempts.
The diagnostic scope, exclusions, data, accounts, and stop conditions are agreed before testing.