HNHacker News
TopNewBestAskShowJobs

bringitup

1 karma · joined April 4, 2022

submissionscomments
bringitup··on Cori – Give agents safe DB write access without raw SQL (open source in Rust)
Thanks for your feedback, Workflows are essential components of advanced systems, and AI excels at orchestrating them. Cori Kernel now secures the foundational elements at the data layer, enabling you to inject orchestration logic directly into the agent that interacts with Cori. But if this orchestration is mission-critical and requires enforcement, we are developing a dedicated workflows component to facilitate the orchestration of multiple services, including APIs and MCP servers
bringitup··on Cori – Give agents safe DB write access without raw SQL (open source in Rust)
We really appreciate your feedback

For policy updates, the biscuit token store reference to the role and optionally a tenant. This means that any extensions or restrictions you make to the policy will be applied directly

For token invalidation, you can either invalidate any token generated after a certain period or manage a blacklist for individual tokens (this is not yet implemented). Regarding rotation, we are currently exploring the use of standard MCP OAuth to deliver biscuit tokens per session. This process is ongoing and will be compatible only with HTTP deployments of Cori.

Concerning extensibility, the current policy format aims to cover 80% of standard use cases. For custom workflows, we are developing a dedicated component that will allow the orchestration of multiple services, whether APIs or MCP servers

bringitup··on Cori – Give agents safe DB write access without raw SQL (open source in Rust)
AI agents are often stuck in "read-only" mode. Granting raw SQL access is a security nightmare, yet building bespoke APIs for every agent action is too rigid to adapt.

Cori solves this by placing enforcement at the very last mile: the data layer.

It acts as a secure MCP kernel that turns database schemas into typed tools governed by simple YAML policies. This allows you to safely enable controlled writes and build thousands of capable agents without maintaining endless API boilerplate or risking your data.

Who we are: We are two engineers who have spent years navigating the rigid security constraints of large enterprises. We built Cori to bridge the gap between strict compliance and actually leveraging the full power of autonomous agents.