← AI Feed
AI Feed

Sixteen thousand merges, blocked

Agents that inherit the user's permissions, a protocol a gateway can police without reading the body, and a vendor naming the piece it cannot build.

How we organise

Cloudflare puts its workforce on agents

Every employee works in a browser wired to internal systems. An agent there inherits the permissions of whoever uses it. Review agents blocked 16,000 merges.

We tell a client to ask whose permissions its agents hold. The builder’s is the wrong answer. Then the blast radius is the most privileged person who ever touched the agent.

How we build

The next generation of MCP

The handshake is gone and the protocol is stateless. New headers carry the method. A gateway can police a call without reading the body.

Our position is that central control of agent traffic is now bought rather than built. The prior question is smaller. Do agent calls pass any point where they could be counted?

Fourteen years of control planes

The control plane is the part nobody budgets for. It decides whether the system scales. Design it for static stability.

We judge a platform by what its running agents do when the control plane goes down. Most orchestration layers stop. Nobody finds that out until the layer is unreachable.

How we assure

An access model for agents

Authorise each action against the task and its accumulated state. Capability can only narrow. Touch protected data and it goes for good.

We read the admission that this cannot yet be built for several principals at once. That sentence is worth the architecture around it. A vendor naming what it cannot build tests every vendor that names nothing.

Anthropic loosens a biology classifier

A rewritten constitution cut false positives on biology questions by roughly 85 per cent. Dual-use queries stay blocked. Some low-risk ones still are.

We ask a client for its own refusal rate. A refusal generates no ticket and no cost line. Nobody measures the work that should have proceeded.