A retail bank gives its 600 relationship managers an assistant that looks up client accounts through a tool. The model supplies the account number as a tool argument, and the tool handler calls the core banking service with a shared service account that can read every client. The core banking service already holds each manager's book and enforces it when called with that manager's own credential. A conduct review found 14 lookups in one month of clients outside the requesting manager's own book, each after the manager typed a name that matched a different client. The regulator requires that a manager be prevented, not merely detected, from viewing a client outside their book, and managers must keep looking clients up by name. Which TWO changes meet the requirement? Select TWO.
- AAdd the manager's list of client account numbers to the system prompt and instruct the model to refuse lookups of any other account.
- BHave the tool handler check each requested account against the signed-in manager's book, taken from the session, and reject any mismatch. Correct
- CLog every lookup with the manager's identity and send compliance a daily report of the accounts accessed outside the manager's book.
- DMake the assistant ask the manager to confirm the client's full name and date of birth before it calls the lookup tool for any account.
- EReplace the shared service account with a delegated credential for the signed-in manager, so the banking service applies their access rights. Correct
Why A is wrong: Tempting because it gives the model the information it needs to stay inside the book. It is wrong because the restriction still depends on the model obeying an instruction, and a name collision or a crafted message can lead it to request another account; the regulator asked for prevention, which an instruction cannot guarantee.
Why B is correct: Correct. The authorisation decision moves out of the model and into code that attaches the manager's identity server-side from the session, so an account outside the book is refused whatever argument the model supplies, while lookup by name keeps working.
Why C is wrong: Tempting because an audit trail is useful and conduct teams expect one. It is wrong because logging and reporting detect a breach after the client data has been shown, and the regulator explicitly requires prevention rather than detection.
Why D is wrong: Tempting because a confirmation step would catch some mistaken name matches. It is wrong because the manager making the request is the person confirming, the step is still carried out by the model, and nothing stops a confirmed lookup of a client outside the book.
Why E is correct: Correct. A shared credential that can read every client gives the tool far more reach than any one manager holds; calling the banking service as the manager means its own entitlement checks refuse out-of-book accounts, enforcing the boundary outside the model.