Coding-agent restrictions should be enforced outside the model that interprets them, Mozilla.ai argues in a new article about agent infrastructure. A rule in AGENTS.md can steer behavior, but it remains an instruction the model may misread, reinterpret or treat as optional.

That distinction matters as agents receive repository access, tools and credentials. Existing account permissions are often broader than the task at hand: permission to write to a repository does not authorize every possible change. Mozilla’s preferred design keeps non-negotiable checks independent of the agent’s reasoning, so a forbidden operation is blocked even when the model believes it has found a reasonable exception.

The article also calls for recording each policy decision alongside the attempted action. A tool trace can show what an agent requested, but without the applicable rule and its version, investigators may not know why the system allowed or denied it. The agent’s own retrospective explanation is not an independent audit record.

Mozilla connects this approach to Otari and its Agent Guardrails work. Open infrastructure is not automatically trustworthy, the article cautions, but it can let organizations inspect and retain their rules and audit history while changing models or agent products.