The Data Gatekeeper
The data stays here — the workflow escapes anyway
The Data Gatekeeper comes from the security side. They worry about where information goes, who can see it, whether prompts leak secrets, whether retrieval-augmented generation is pulling from the right databases, and whether embeddings have become a shadow copy of sensitive data. Their map is full of arrows, buckets, vendors, access groups, retention periods, and places where someone has written 'TBD' in red.
Symptom
The Gatekeeper locks down one dimension of the risk while the workflow escapes through two others. The data cannot leave the approved environment — so the workflow adapts, using a different vendor, a different data path, a different interpretation of what counts as the same data.
Why It Matters
The Data Gatekeeper's ward holds. The workflow escapes anyway. The Gatekeeper is effective at what they control and powerless over what they don't — which is most of the attack surface in an AI ecosystem that rewards creative routing around restrictions.
What the Chapter Gives You
Why locking down data paths is necessary but insufficient, how workflows adapt to restrictions faster than policies adapt to workflows, and the pattern that makes every gate keepable but the perimeter unkeepable.
Want the full chapter? Grab the free cheat sheet, read an excerpt, or get the book.
Recognize this one in your codebase?
Free cheat sheet, excerpts, and interactive diagnostics.