446 karma · joined April 23, 2013
Building Tenuo (github.com/tenuo-ai/tenuo)
dev at tenuo.ai
Its integration for Claude Code: https://github.com/tenuo-ai/claude-governance
There are some well documented advantages of decomposition...that's why the industry favours microservices over monoloths.
The idea in my draft is to do the attenuation and verification before the call reaches the service, enforced at the boundary, like the proxy setup you're describing. And the token wouldn't be a bearer token per se; there's proof of possession, and the constraints narrow at each hop and travel with the token, so the boundary can verify the chain itself rather than rely on a central authority. The design is inspired by macaroons and other capability-based access control work.
Full draft's here if you want to pick it apart: https://datatracker.ietf.org/doc/draft-niyikiza-oauth-attenu...
This particular article was decently nuanced though.
Disclosure: I'm working on an open source authorization tool for agents.
Been saying this for a while and mostly getting blank stares. In-context "controls" as the primary safety mechanism is going to be a bitter lesson for our industry. What you want is a deterministic check outside the model's reasoning that decides allow/deny without consulting its opinion. Cryptographic if the record needs to survive a compromised orchestrator, and open source. If your control is a string the model can read, the model can ignore it. If it can write it, it can forge it. I'm surprised how strange that idea sounds to some people.
Disclosure: I'm working on an open source authorization tool for agents.
Lord Varys: Three great men sit in a room: a king, a priest, and a rich man. Between them stands a common sellsword. Each great man bids the sellsword kill the other two. Who lives, who dies? Tyrion Lannister: Depends on the sellsword. Lord Varys: Does it? He has neither crown, nor gold, nor favor with the gods. Tyrion Lannister: He has a sword, the power of life and death. Lord Varys: But if it's swordsmen who rule, why do we pretend kings hold all the power? When Ned Stark lost his head, who was truly responsible? Joffrey? The executioner? Or something else? Tyrion Lannister: I've decided I don't like riddles. [pause] Lord Varys: Power resides where men believe it resides. It's a trick. A shadow on the wall. And a very small man can cast a very large shadow.
[1] https://www.imdb.com/title/tt2070135/characters/nm0384152/ [2] https://www.goodreads.com/quotes/503606-oh-i-think-not-varys...
There are emerging proposals that get this right, and some of us are taking it further. An IETF draft[0] proposes cryptographically enforced argument constraints at the tool boundary, with delegation chains that can only narrow scope at every hop. The token makes out-of-scope actions structurally impossible.
Disclosure: I wrote the 00 draft
[0] https://datatracker.ietf.org/doc/draft-niyikiza-oauth-attenu...
Task-scoped "warrants", attenuating with delegation, and enforced cryptographically at tool call.
Macaroons/Biscuits for agents basically.