A language model does not separate the data it reads from the instructions it receives: they are the same text. A document, an email or a web page can therefore carry a request that the agent carries out as though it came from you. It is called prompt injection, and it is why an agent is designed starting from its powers.
The method is the one used for any application that touches company data: which actions it may take, on which systems, with which credentials, and when a person has to approve. The choice of model comes afterwards, and it can be changed.