Intent does not grant access
Understanding a deletion request does not establish permission. Verify identity and ownership on the server and validate model outputs as untrusted inputs. Restrictions must survive a mistaken tool proposal or hostile instructions inside a retrieved document.
Make tools narrow
Prefer a read-order-status operation to unrestricted database queries. Restrict editable fields and batch size. Bind confirmation to the exact order and new address so that an old approval cannot authorize a different change.
Test misuse and recovery
Test altered customer IDs, repeated calls, exceeded limits and failures after a write but before the response. Logs should show the actual outcome, and idempotency should prevent duplicate execution. Prompt instructions alone are insufficient.