43 points smokel 1 day ago 4 comments

chris_money202 1 hour ago | parent

Its a good idea and enterprise customers will love it.

DeepYogurt 39 minutes ago | parent

What are these people running from? They're not! They're running to the world's toughest competition in town!

Joker_vD 21 minutes ago | parent

> An agent cannot be its own security authority. It must run within a boundary defined by the developer or organization and enforced independently of the agent itself.

...so make it its own security principal, distinct from the human user?

> Without a managed execution boundary, the agent may decide that changing the server configuration is the fastest way to complete the task and potentially break the production site.

It can decide that even with the execution boundary in place, you know. What matters if it can actually act that out.

All in all, a very sloppily written announcement. Almost as if it was written by—

3eb7988a1663 10 minutes ago | parent

Can I use this as a generic app permissions boundary or do I have to somehow fake it as an "agent"? We are well past the point where I need to be able to lock down that my music player has no ability to read my SSH keys or whatever.

Naturally, this will be gated to corporate customers - the plebs do not get access to better security unless they pay for a top tier license.