Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jensbontinck
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
jensbontinck
7mo ago
This is why governance has to be external to the model. If you ask the model "are you sandboxed?" it will confabulate an answer. If you rely on the model to self-enforce safety rules, it will sometimes comply and sometimes not, de
2.
▲
by
jensbontinck
7mo ago
Yes, but most are doing it wrong. The common approaches I've seen: 1
3.
▲
by
jensbontinck
7mo ago
This is a solid draft. glad to see it building on SPIFFE/WIMSE and OAuth rather than inventing new identity primitives. The "agents are workloads" framing in Section 3 is exactly right and should settle the debate about wheth
4.
▲
by
jensbontinck
7mo ago
A few patterns we've found effective deploying agents to production: 1. Proxy-based governance. Route all LLM traffic through a governance layer. The agent never holds API keys directly — the proxy holds them and issues scoped, short-l
5.
▲
by
jensbontinck
7mo ago
This is exactly right. We went down this path and the practical implementation ends up looking like capability tokens. short-lived, cryptographically signed credentials that encode what the agent is authorized to do for this specific task.