Blog
Design notes and how-tos on deploying AI agents with a permission manifest, sealed secrets and an audit trail. Every post is also Markdown: add .md to its URL.
2 results for security
Telling a model "never call external APIs" is a request. A manifest the runtime enforces is a guarantee. What changes when permission is syntax, and why security teams say yes to one and no to the other.
Most agent secret leaks are not clever. The model was asked for the key and it had the key. Sealed secrets remove the second half of that sentence, and change what a security review has to check.