Your agent has delete_user()? Tool access is easy to check, runtime authorization is the hard part
BaraSlim · reddit · 2026-09-29
The author argues that checking which tools an agent can reach is easy—runtime authorization is the real challenge. A production authorization decision may need agent identity, tool identity, target resource and environment, current policy, execution context, budget, and approval state. The tool list answers what the agent can reach; the runtime decision answers what it can actually execute now—a fundamentally different architecture from static allowlists. Non-deterministic agents in production affect finances and reputation, and auditors don't care how the agent arrived at a bad decision; you should also monitor parameters, session state, budget limits, and infinite loops at execution time.
More from coding & agent
- When 'Looks Correct' Becomes 'Verified': The LLM Coding Acceptance Problem — T_hompson · 2026-09-29
- A naive video transcription fixer pipeline: extract audio+frames, ASR, then correct with a frontier model — capetorch · 2026-09-29
- bdsqlsz is vibe-coding DLSS5 weight training for his in-development 3D game — bdsqlsz · 2026-09-29
- We Built an On-Call Agent That Failed the Right Way — Memory Can Learn the Wrong Lesson — Similar-Split7292 · 2026-09-29
- Extending Jev Mode to Images: Constrained llama.cpp Outputs as Image Selections — opUserZero · 2026-09-29
- Scraping Xiaohongshu hit posts with Codex + a wired Android phone — huangyun_122 · 2026-09-29