A structured look at what an attacker might want, how they could get it through your design, and what stops them.
You have done this if
Before launch you listed the ways a malicious document could steer the agent and added a control for each.
Say it in a review
We threat-modelled the retrieval path; the top risk was indirect prompt injection from shared documents.