Then maybe it's a knowledge / understanding issue, because I've trawled through the article multiple times seeing if I'd missed just that. What I do see is:
- "deleted our production database and all volume-level backups in a single API call to Railway, our infrastructure provider" (implying permissions across all environments)
- "The AI agent was set to complete a routine task in the PocketOS staging environment" (implying it needed (only) staging environment permissions, no description of specific "routine task", no reason it would need productive access)
- "I decided to do it on my own to 'fix' the credential mismatch" (This is the AI part of the fuckup: The decision to delete data over a credential issue is something even a Junior engineer probably wouldn't jump to, so that's on the AI and on Anthropic, whose safeguards failed)
What am I missing here? What is a "routine task in [a] staging environment", why does it need admin permissions? Why does the agent have permissions for the prod environment if it's supposed to work in the staging one?