PTENES
Skip to content
MODULE 4.3

💸 Spending, isolation, and LGPD

A limit on spending, a limit on effort, a fenced area for the agent to work in, and only the minimum customer data. The last gates that almost nobody closes.

6
Topics
~35
Minutes
Practical
Level
Defense
Type
0 of 60%
1

Set a spending cap

Many AI services charge by usage: each question, each agent turn, each file it reads costs a little credit. An agent working on its own can make hundreds of turns in one night.

Without a cap, you find out how much you spent when the bill arrives. With a cap, you know the worst case before it happens.

22h1h4h7h expense monthly cap alert at 50% no cap: it keeps rising until someone notices 🔔 with a cap: stops at the limit

How to read the diagram: the two lines start out the same—the same agent is stuck repeating the task. The blue bell is the email alert at halfway to the limit: time to take a look. The amber line stays flat at the dashed line because the account stops accepting charges; the red one only stops when someone wakes up.

✗ No ceiling

  • ✗AI account linked to the main credit card, with no monthly limit.
  • ✗No usage alerts configured.
  • ✗Marcos left an agent checking documents overnight; a faulty file made it try again, and again.

✓ With a limit

  • ✓Monthly limit set in the account dashboard ("spending limit," "budget").
  • ✓Email alert at 50% and 80% of the limit.
  • ✓A virtual card just for AI, with a low limit. Marcos's loss stopped there.

💡 Can’t find where to set a limit?

Use a fixed monthly plan or create a virtual card in your bank's app just for AI services, with a limit of, for example, twice what you expect to spend. This solves the same problem without relying on the service dashboard.

🧢
Spending limit

monthly limit

🔔
Alert

at 50% and 80%

💳
Virtual card

only for AI

📉
Worst case

known in advance

2

Set a resource cap and stop the loop

Money isn’t the only thing an agent uses up. It uses time, attempts, sent messages, and computer memory. A loop without an end, it consumes all of this at the same time.

It happened on one of our projects: a tool running without a memory limit froze the entire server—and without a ceiling, it froze again on the next attempt. The fix was one line: a limit. Every agent needs its own.

LimitExample for Renata’s clinicWhen it hits the limit…
⏱️ Maximum timeconfirming the appointment takes no more than 10 minutesstops and tells you what's missing
🔁 Attemptsno more than 3 attempts per patientmark it "not confirmed" and move on
✉ Sendsno more than 40 messages per daystops everything and asks for approval
💾 Memory / machinelimit set by whoever installed itthe system stops only the agent, not the server

What to look for in the table: the last column. A good limit doesn’t just stop the agent: it says what to do when it stops—notify you, mark the task as pending, ask for approval. Stopping silently is almost as bad as not stopping.

🎯 Goal: give the agent written effort limits

Paste into the agent's fixed instructions. Adjust the numbers inside < > for your task.

REGRA: LIMITES DE ESFORÇO
1. Cada tarefa tem no máximo <10> minutos. Passou disso, pare e me diga o que concluiu e o que falta.
2. Se uma mesma ação falhar <3> vezes seguidas, não tente de novo. Registre o erro e me avise.
3. Nunca envie mais de <40> mensagens por dia. Chegou no limite, pare e peça aprovação.
4. Se perceber que está repetindo os mesmos passos sem avançar, pare. Repetição sem progresso é sinal de loop.
5. Ao parar por qualquer limite, escreva: qual limite, onde parou e o que sugere.
How to verify: ask the agent to deliberately do an impossible task (e.g., "confirm the appointment of a patient who isn't on the calendar"). The expected behavior is for it to try a few times, stop, and explain which limit it reached.
🌀
Loop

repeat without making progress

⏱️
Maximum time

per task

3️⃣
Attempts

few and limited

🗣️
Stop with a notification

never silent

3

Isolate the agent

Limiting what the agent can do is one part. The other is limiting where it can do. An isolated agent works in a walled-off space: if it makes a mistake or is tricked, the damage stays inside.

You don’t have to set this up alone. You need to know what to ask: "Does the agent run in isolation? In which folder? What’s excluded?".

🆕 New here? What is a “sandbox”?

Sandbox (in English, sandbox) is a closed-off space where the agent can make changes freely without reaching the rest of the computer — like a sandbox where a child can play without making a mess in the house. A common way to set this up is called container (container): a "box" with only the files and programs the agent needs. The simplest version is a limited folder: the agent can see only one folder, and nothing outside it.

sandbox agent 📁 working folder 📅 calendar (copy) ✉ personal email 🏦 bank 🔑 key file 🖼️ family photos ✕ if it is deceived, the damage stays inside the fence

How to read the diagram: The dashed amber fence is the agent’s limit. Inside is only what the task requires—notice that the schedule is a copy. The red line shows the agent trying to reach the key file: it hits the fence. The four gray boxes outside are on the same computer, but the agent can’t see them.

1

Basic level: separate account and folder

The agent uses an email account of its own and can see only one folder. Anyone can do this.

2

Intermediate level: separate computer or user account

A system user account just for the agent, or an old dedicated machine, with no login to the bank or your personal accounts.

3

Technical level: container

Set up by whoever installs it. You ask and check: "what's included?", "what's excluded?", "who turns it off?".

🏖️
Sandbox

walled-off space

📦
Container

box with the minimum

📁
Restricted folder

the simplest isolation

📋
Copy

instead of the original

4

Understand the LGPD in one page

The LGPD (General Data Protection Law) explains how a company can use people’s data. It applies equally whether a customer spreadsheet is read by an employee or an AI agent. You’re still responsible.

This is not legal advice. It’s the minimum a business owner needs to keep in mind before connecting an agent to customer data.

The idea behind the lawIn plain languageIn practice, with the agent
Personal dataeverything that identifies someone: name, phone number, CPF, emailRenata’s entire schedule is personal data
Sensitive datahealth, religion, biometrics, racial origin, among others — extra care required"had this procedure" is health data
Legal basisan accepted reason to use the data: consent, contract, legal obligation…a reminder about a scheduled appointment fits into service; sending a promotion requires consent
Purposeuse only for what was agreeda phone number given to confirm an appointment doesn’t become a marketing list
Needuse as little as possiblethe reminder agent doesn’t need the CPF (topic 5)
Data subject rightsthe person can ask to see, correct, or delete their datayou need to know where the agent stored copies

What to look for in the table: the right-hand column. Almost every safeguard comes down to a simple question: "Why does the agent need this?" and "Where does it store it?" If you can’t answer, it’s not time to turn it on yet.

⚠️ Attention: health is sensitive data

Clinics, medical offices, gyms, and salons that record allergies or treatments handle sensitive data. Pasting that history into any AI chat "just to summarize it" is the kind of carelessness the law penalizes. When in doubt, talk to whoever handles the legal side of your business before turning on the agent.

🪪
Personal data

identifies someone

🩺
Sensitive data

health and related matters

📜
Legal basis

accepted reason

🎯
Purpose

only what was agreed

5

Show the agent only what it needs

Two techniques solve most of it: minimize (remove the columns the task doesn't use) and anonymize (replace the name with a code). The agent does the same work; anything leaked is worth much less.

Do this before before the data reaches the agent, in your spreadsheet. Asking the AI to "anonymize" data you already pasted into the chat won’t help: they’re already there.

✗ What Renata was going to send

Nome: Ana Paula Souza
CPF: 000.000.000-00
Telefone: (00) 90000-0000
Procedimento: peeling químico
Alergia: ácido salicílico
Faltou: 3 vezes

✓ What she sent

Código: P-014
Tipo de sessão: facial
Faltou: 3 vezes

The question was “which patients miss appointments most often?” The code is enough to answer it. Only she has the table that links P-014 to a name.

🎯 Goal: decide, column by column, what the agent can see

Paste into the AI chat. Send only the column names from your spreadsheet — never the data. Replace what’s between < >.

Vou ligar um agente de IA a uma planilha de clientes e quero dar a ele o mínimo de dados.
Tarefa do agente: <ex.: identificar quem mais falta às consultas e sugerir horários de lembrete>.
Colunas da planilha (só os nomes, sem dados): <ex.: nome, CPF, telefone, e-mail, data de nascimento, procedimento, alergias, faltas, valor pago>.

Para cada coluna, responda em uma tabela:
coluna | a tarefa precisa? (sim/não) | se sim, dá para trocar por código ou faixa? | é dado sensível pela LGPD?
Depois, me diga qual seria a planilha mínima para essa tarefa.
How to verify: The minimal spreadsheet should have less than half the original columns and no health, ID, or contact columns—unless the task is specifically to contact someone. In that case, keep the phone number and remove the rest.
✂️
Minimize

only the useful columns

🔢
Anonymize

name becomes code

🗝️
Key table

stays with you

⏮️
Before

in the spreadsheet, not in chat

6

Close the four doors

Most problems with agents don’t come from a sophisticated attack. They come from four doors open: a secret in chat, an extension accepted without reading, an account without a limit, and too much customer data.

This checklist brings together what you saw in modules 4.2 and 4.3. Go through it for the agent you chose at the beginning of the course—it goes straight to the “security” section of the Trail 5 spreadsheet.

🎯 Goal: leave with all four gates checked for your agent

Copy this into a document. Mark [x] for what's already done and write the expected date for anything that's left.

AS QUATRO PORTAS — agente: <nome/tarefa do seu agente>   data: <____>

PORTA 1 · SEGREDOS
[ ] Nenhuma senha, chave ou token colado em chat ou documento compartilhado.
[ ] Regra "segredos" nas instruções do agente (módulo 4.2).
[ ] Sei onde revogar cada chave: <lista>.

PORTA 2 · EXTENSÕES
[ ] Revisei extensões, plugins e apps conectados; removi o que não uso.
[ ] Cada um que ficou: sei quem publicou e o que pede combina com o que faz.

PORTA 3 · GASTO E ESFORÇO
[ ] Teto mensal na conta: R$ <____>. Alerta em 50%: [ ]
[ ] Cartão só para IA ou plano fixo: [ ]
[ ] Regra "limites de esforço" nas instruções (tempo, tentativas, envios).
[ ] O agente roda isolado: pasta/conta/contêiner <qual>.

PORTA 4 · DADOS DE CLIENTES
[ ] O agente toca dados de clientes? <sim/não>. Dado sensível? <sim/não>
[ ] Planilha mínima: só as colunas que a tarefa usa; nomes trocados por código quando der.
[ ] Sei onde o agente guarda cópias, para atender quem pedir para apagar.

Porta que ainda está aberta: <____>. Quem fecha: <____>. Até: <____>.
How to verify: no blank lines. An item without [x] is acceptable if it has an owner and a date on the last line. A gate with no [x] means the agent should not be turned on yet.

💡 How Marcos used it

Marcos went through the checklist with Júlia, the office assistant, on a Friday afternoon. It took 25 minutes. They found two open doors: an AI account with no spending cap and a spreadsheet containing every client’s CPF that the agent didn’t even use. They closed both before leaving.

Quick test (optional): Renata wants an agent to find out which patients miss the most appointments. What should she give it?

🗝️
Secrets

outside the chat

🧩
Extensions

only the verified ones

💸
Ad spend

with a cap and guardrails

👥
Customer data

only the minimum

🎓 Module summary

✓
Every expense has a cap — limit, alert, and a card just for AI.
✓
Every effort has a cap — time, attempts, and sends; stop with a notification.
✓
An isolated agent makes mistakes within the fence — folder, account, or container.
✓
The LGPD applies to the agent — and you’re responsible.
✓
Only the minimum, with codes — and all four doors checked.

Next track:

Track 5 — Own the outcome