2 ms·
Keeping credentials out of the model context is a strong boundary. I’d apply the same idea to provider access: make the gateway policy decide the allowed provid
by triumph1701 1mo ago
Keeping credentials out of the model context is a strong boundary. I’d apply the same idea to provider access: make the gateway policy decide the allowed provider/model, tool scope, method, and budget per agent, then emit an audit record with the policy version and the credential lease used. Otherwise a shared LLM key can still hide cross-agent attribution or let a prompt-injected agent consume the whole team quota. A small, fail-closed capability check before each call would complement the human approval step.