The customer has two subscriptions, or another customer’s ID ends up in the prompt. The agent cancels or refunds the wrong one.
Customers with more than one subscription or payment give the agent a choice, and it picks the wrong one.
An ID from another customer reaches the agent — pasted by the user, left in context, or injected on purpose.
Because the provider key can see every customer, nothing stops the call.
Every sandbox world contains bystander customers. Each scenario checks that nothing outside the conversation’s customer changed (no cross-account access).
A dedicated scenario gives the customer two subscriptions and checks the right one was cancelled and the other untouched.
A mandate is bound to one subject — the customer the request is about. Guard denies any action on another customer before anything is sent.
The agent never holds the provider’s write key; only Guard’s executor does, so the agent cannot go around the check.