
The agent boundary: deciding what an AI agent may touch
An agent will try whatever its input tells it to. A boundary limits what it can reach, for how long, and where the limit is enforced so the agent cannot argue with it.
3 posts

An agent will try whatever its input tells it to. A boundary limits what it can reach, for how long, and where the limit is enforced so the agent cannot argue with it.

How to put single sign-on in front of an old internal app without changing it, and why the identity headers it receives must be stripped and re-stamped at the boundary.

Zero-code authentication puts sign-in and access checks in front of a service instead of inside it. How sidecars, proxies and kernel interception compare, and when to use an SDK.