News

Field note 43 · Detection science

Collusion Monitoring Must Preserve Privacy

Cross-agent visibility can improve security while creating a dangerous central record of prompts, identities, and business activity.

Editorial illustration for Collusion Monitoring Must Preserve Privacy

Monitoring should separate metadata, protected content, derived features, and escalation access by purpose.

Why this question matters

Collusion detection benefits from joining events across agents and organizations. The same data can reveal private intentions, commercial strategy, personal identity, and confidential transactions. Centralizing raw content may create more risk than the detector removes.

A layered design can keep routine analysis on bounded metadata and privacy-preserving features, then retrieve protected evidence only when risk and authorization justify escalation. Retention should follow the decision need rather than indefinite analytical possibility.

Signals worth observing

  • Routine detectors ingest full prompts when metadata would suffice.
  • Analysts can browse unrelated principals and tasks.
  • Derived features cannot be traced back under controlled review.

Practical control direction

  1. Minimize collection by hypothesis and risk tier.
  2. Separate detection access from evidence-unsealing authority.
  3. Use short retention and auditable escalation paths.
AgentCollusion lensA Guardian Agent should be accountable for what it observes as well as what it blocks.

Sources and further reading

Next field note: A Guardian Agent Must Be Independent Enough to Disagree