Blog

Field notes.

Short, practical pieces on governing what AI assistants can reach and do.

Your agents are staff. Where's their handbook?

A new hire gets a badge, a desk, a handbook, a manager and a personnel file. Agents got the first two. What an Intelligence Resources team will need in week one.

Hold, don't refuse

A control that can only say no gets bypassed by the people it was written for. The third answer, and the four properties that make it safe.

A scoped token is not a code of conduct

Agent identity decides who may reach what. The failures that matter happen after that yes: combinations, order, and time. Why identity and policy need each other.

Permissions are not policy: the layer your AI assistant is missing

Permissions say who may. Guardrails say what looks bad. Neither decides what your company allows. A ten-point checklist for the policy layer between assistants and MCP servers.

We built an AI security layer and kept AI out of the decision

Using an LLM to police an LLM is non-deterministic, unauditable, and can be prompt-injected. Why the decision path has no model in it, with concrete examples.

The OIDC field nobody documents: groups_claim

Providers put group and role info in different claims. Hardcode "groups" and your SSO role mapping silently breaks for Cognito, Auth0, Google and more.

Three MCP attacks, refused

Prompt-injection exfiltration, tool poisoning and rug pulls, all blocked deterministically before the upstream is contacted. With repros you can run in a minute.

Aggrete vs other MCP security tools

Scanners, guardrails, gateways, and where Aggrete's deterministic, stateful, document-driven policy is genuinely different. Including what it does not do.

We compiled our handbook into a firewall for AI

The rules that should govern an assistant are already written down. Aggrete turns each clause into a deterministic, stateful rule, owned by whoever wrote it.

Per-user access: each assistant acts as the actual person

Stop sharing one master account. Each person's own credential and permissions are carried to the upstream, resolved per request through a hook you control.

How to stop prompt-injection exfiltration in MCP

Untrusted content can turn authorized tool calls into an exfiltration. Prompt filters miss it; a rule about the flow does not.

When a sales rep exports the whole pipeline

No single CRM read is sensitive. The volume is. An entity budget with per-user memory stops the mass export while normal selling passes.

What does my coworker earn, and their PTO?

A colleague's pay or leave balance is one prompt away. Self_comparison and min_group rules refuse it while your own record stays available.