Meta tags:
description= Give an AI agent access to your systems and it inherits your permissions — all of them. It can read... Tagged with ai, security, opensource, sre.;
keywords= ai, security, opensource, sre, software, coding, development, engineering, inclusive, community;
Headings (most frequently used words):
the, dev, community, it, in, your, ai, agent, has, same, database, access, you, do, that, problem, five, rules, clever, attack, death, by, thousand, small, cuts, what, deliberately, does, not, catch, other, half, nothing, happens, dark, try, thirty, seconds, no, install, top, comments, trending, on, hot,
Text of the page (most frequently used words):
the (99), and (36), that (25), you (24), for (20), agent (20), your (18), reeflex (16), dev (14), this (13), delete (13), rules (13), one (12), not (11), can (11), every (11), mode (10), with (9), gate (9), what (9), five (9), policy (8), code (8), are (8), decision (8), #comment (8), fullscreen (8), run (7), like (7), does (7), action (7), share (6), community (6), open (6), permissions (6), human (6), have (6), production (6), rule (6), 2026 (5), source (5), database (5), through (5), jul (5), agents (5), leo (5), david (5), more (5), products (5), whole (5), engine (5), public (5), all (5), everything (5), real (5), same (5), nothing (5), read (5), session (5), budget (5), actions (4), they (4), hide (4), will (4), but (4), still (4), when (4), copy (4), link (4), access (4), because (4), exit (4), enter (4), call (4), approval (4), just (4), irreversible (4), has (4), out (4), layer (4), make (4), runs (4), single (4), safety (4), batch (4), create (3), log (3), software (3), other (3), discuss (3), problem (3), security (3), joined (3), founder (3), deterministic (3), holds (3), before (3), zero (3), llm (3), path (3), follow (3), abuse (3), comments (3), well (3), post (3), via (3), report (3), impact (3), each (3), day (3), gets (3), something (3), less (3), deleting (3), 500 (3), from (3), model (3), exactly (3), right (3), menu (3), tools (3), alex (3), shev (3), systems (3), time (3), claude (3), n8n (3), install (3), don (3), wait (3), audit (3), broad (3), change (3), content (3), says (3), under (3), get (3), thing (3), already (3), isn (3), allowed (3), base (3), here (3), new (3), input (3), small (3), account (2), place (2), where (2), built (2), use (2), conduct (2), free (2), about (2), keep (2), coding (2), tls (2), oauth (2), them (2), governance (2), risky (2), may (2), person (2), reporting (2), hidden (2), reply (2), button (2), likes (2), scope (2), allows (2), then (2), judge (2), fits (2), two (2), second (2), catches (2), bad (2), instruction (2), perfectly (2), times (2), narrower (2), should (2), question (2), express (2), velocity (2), reversibility (2), live (2), steps (2), faster (2), instinct (2), query (2), weird (2), dropdown (2), expand (2), collapse (2), seog (2), terminal (2), skills (2), powered (2), against (2), endpoint (2), see (2), how (2), github (2), tell (2), wrong (2), clone (2), improves (2), standard (2), workflows (2), tool (2), wordpress (2), forever (2), keeps (2), safe (2), observe (2), hold (2), approve (2), api (2), verb (2), internal (2), magnitude (2), count (2), target (2), items (2), seconds (2), verdict (2), point (2), boring (2), doesn (2), hands (2), raised (2), who (2), which (2), record (2), happens (2), auditor (2), asks (2), changes (2), held (2), actually (2), thresholds (2), would (2), things (2), saying (2), floor (2), plain (2), attacker (2), per (2), product (2), reversible (2), customer (2), guard (2), default (2), won (2), most (2), catch (2), any (2), old (2), transaction (2), underneath (2), trick (2), prior_deletes (2), cumulative (2), fragmentation (2), readable (2), entire (2), into (2), many (2), ones (2), dangerous (2), hundred (2), looks (2), clever (2), attack (2), thousand (2), fails (2), risk (2), system (2), data (2), close (2), checked (2), authenticated (2), prompt (2), search (2), coders, stay, date, grow, their, careers, made, love, 2016, ruby, rails, powers, inclusive, communities, forem, terms, privacy, mlh, shop, postgres, contact, showcase, organization, accounts, advertise, help, education, tracks, videos, challenges, home, space, development, manage, career, silent, mic, drop, traditional, agentic, flow, state, programming, productivity, handshakes, flows, easier, learn, clicking, webdev, trending, hot, further, consider, blocking, confirm, child, sure, want, become, visible, permalink, frame, tight, job, layers, cover, blind, spots, tightly, scoped, permitted, 100, row, absolutely, baseline, least, privilege, got, important, trouble, kept, hitting, static, answers, dynamic, grant, routine, incident, 40th, hour, different, 1st, scale, outside, permission, put, threat, sentence, paranoid, than, mar, work, dallas, fort, worth, texas, location, building, creator, terminalskills, curated, cli, modern, devs, dismiss, preview, submit, templates, let, quickly, answer, faqs, store, snippets, template, trusted, user, personal, subscribe, top, seatbelt, acting, own, start, above, together, break, fork, trade, take, com, docker, compose, pip, npm, nodes, node, governs, covered, pretooluse, hook, woocommerce, plugin, graphql, adapters, roadmap, adapter, contract, spec, today, kill, switch, siem, export, always, response, trimmed, readability, also, carries, expiry, timestamp, decoration, created, resolvable, could, hold_id, requires, reason, irreversible_broad_prod, require_approval, curl, https, decide, ability, axes, blast_radius, externality, environment, session_id, sess, devto, authorization, bearer, eval, type, application, json, evaluation, token, making, trying, hard, try, thirty, itself, using, police, explainable, context, approves, hitl, private, supervisor, never, pattern, existing, workflow, flag, handover, recorded, approved, evidence, ail, loop, designate, yours, turn, watches, written, been, denied, traffic, enforce, monday, did, week, flip, enforcement, tuned, usable, life, instead, correct, paper, half, dark, think, loud, inspect, trust, govern, strong, ceiling, extend, afternoon, structural, destructive, patient, rotating, across, sessions, dilutes, publishing, price, edit, correctness, reading, 000, records, exfiltration, mass, natural, extension, pretend, part, first, claims, lying, deliberately, none, these, invented, decades, principle, pointed, management, engineering, fraud, checks, domain, proven, ideas, prior, deletes, plus, kind, sign, off, present, delete_session_budget, count_by_verb, object, r5_require_approval_budget, resistance, verbatim, repo, banks, caught, fifty, years, called, breaking, suspicious, slip, threshold, borrows, countermeasure, directly, hundredth, trips, limit, fragmenting, buys, smurfing, structuring, proudest, say, bulk, over, misaligned, hijacked, confused, figures, asking, request, innocent, death, cuts, invariant, unreachable, crashed, partitioned, misconfigured, goes, closed, machine, learning, score, signatures, takes, coffee, below, high, axis, matched, cases, tax, normal, else, systemic, permanent, block, wide, destruction, refused, outright, force, blocked, until, yes, big, looking, stays, way, overwhelming, majority, harmless, reads, pass, wants, turns, description, leave, past, gap, apache, front, resources, its, minute, identity, provider, guardrails, whether, was, toxic, legitimate, clean, equivalent, fine, specific, now, give, inherits, send, email, issue, refund, malicious, authorized, between, matters, sre, opensource, posted, mastodon, facebook, linkedin, copied, clipboard, pick, gem, boost, save, jump, fire, exploding, head, unicorn, add, reaction, algolia, navigation, skip,
Text of the page (random words):
your ai agent has the same database access you do that s the problem dev community skip to content navigation menu search powered by algolia search log in create account dev community close add reaction like unicorn exploding head raised hands fire jump to comments save boost pick as gem more copy link copy link copied to clipboard share to x share to linkedin share to facebook share to mastodon share post via report abuse leo david posted on jul 6 your ai agent has the same database access you do that s the problem ai security opensource sre give an ai agent access to your systems and it inherits your permissions all of them it can read every customer record delete every product send every email issue every refund not because it s malicious because it s authenticated it s authorized and nothing between the agent and your data asks the one question that matters is this specific action safe to run right now your identity provider already checked who the agent is your guardrails already checked whether the prompt was toxic but a perfectly authenticated agent with legitimate permissions and a clean prompt can still run the equivalent of delete from products and every layer you have says looks fine that gap is what we built reeflex to close it s open source apache 2 0 it runs in front of your resources and its entire base policy is five rules you can read in about a minute the five rules an agent wants to do something reeflex turns that action into a small boring description what verb how many things reversible or not does it leave the system and runs it past five rules r1 reads pass looking at internal data is allowed the gate stays out of the way for the overwhelming majority of actions which are harmless r2 big irreversible changes in production wait for a human force deleting a broad batch of products in production doesn t get blocked forever it gets held until a person says yes r3 system wide destruction is refused outright an irreversible systemic change in production delete everything isn t a thing you approve it s a thing you re scope it s the one permanent block r4 everything else is allowed by default if no high risk axis matched the action runs the gate is a floor for the dangerous cases not a tax on the normal ones r5 the session has a delete budget more on this one below because it s the rule that catches the clever attack that s the whole policy no machine learning risk score no thousand hidden signatures five rules in plain readable code that you can audit in the time it takes to make coffee and one invariant underneath all five the gate fails closed if the decision engine is unreachable crashed partitioned misconfigured nothing goes through a safety layer that fails open is a safety layer you don t have the clever attack death by a thousand small cuts here s the rule we re proudest of say your policy holds any bulk delete over 20 items an agent misaligned hijacked or just confused by a bad instruction figures out it can delete 500 products by asking a hundred times for 5 each every single request looks innocent under most systems all hundred go through banks have caught this trick for fifty years it s called structuring or smurfing breaking one suspicious transaction into many small ones to slip under the reporting threshold reeflex borrows the countermeasure directly r5 keeps a cumulative budget per session the hundredth batch of five trips the same limit the single batch of 500 would have fragmenting a dangerous action buys the attacker exactly nothing we keep saying the policy is readable so here is r5 the entire fragmentation guard verbatim from the repo r5 session delete budget fragmentation resistance r5_require_approval_budget if prior_deletes object get input cumulative count_by_verb delete 0 prior_deletes input magnitude count delete_session_budget not input approval present enter fullscreen mode exit fullscreen mode prior deletes this session plus this batch against one budget that s the whole trick and it s the kind of code an auditor can actually sign off on none of these rules are invented each one is a decades old safety principle pointed at a new target change management r2 safety engineering r3 transaction thresholds and fraud velocity checks r5 new rules for a new domain old proven ideas underneath what it deliberately does not catch this is the part most security tools won t tell you so here it is first the base policy does not catch everything and any tool that claims it does is lying an agent reading 10 000 customer records is just a read r1 allows it that s exfiltration and the base rules don t see it a mass read guard is a natural extension but it s not on by default and we won t pretend it is publishing one product at the wrong price is a single reversible edit allowed correctness of content isn t something impact rules can judge a patient attacker rotating across sessions dilutes the per session budget the five rules govern structural destructive impact and they do it well they are a strong floor not a ceiling the policy is plain code extend it in an afternoon we think saying this out loud is the whole point a gate you can t inspect isn t a gate you can trust the other half nothing happens in the dark two things make the rules usable in real life instead of just correct on paper observe mode turn reeflex on and it changes nothing it watches every action gets a verdict written to the audit log but everything still runs you get a report of what would have been held or denied on your real traffic before you enforce a single thing install it on a monday read what your agents actually did all week then flip enforcement on with thresholds you ve already tuned the decision is yours when a rule says wait for a human reeflex doesn t make the second call it hands you the decision with the context to make it in five seconds a human approves it hitl or an agent you designate does a private model a supervisor agent your call never the agent that raised the hold we call that pattern ail agent in the loop or your existing approval workflow does it we flag you rule and every handover is recorded who approved what when under which rule that record happens to be exactly the evidence an auditor asks for the decision path itself has zero llm in it same action in same verdict out every time we re not using ai to police ai the whole point is a layer that s boring deterministic and explainable try it in thirty seconds no install we run a public evaluation endpoint with a public token this is a real engine making a real decision an agent trying to hard delete 50 items in production curl s https api dev reeflex io v1 decide h content type application json h authorization bearer reeflex eval public 2026 d action verb delete ability wordpress delete post axes reversibility irreversible blast_radius broad externality internal magnitude count 50 target environment production agent session_id sess devto enter fullscreen mode exit fullscreen mode decision require_approval rule reeflex policy irreversible_broad_prod reason irreversible broad change in production requires human approval enter fullscreen mode exit fullscreen mode response trimmed for readability the live one also carries a hold_id and an expiry timestamp that s not decoration the engine just created a real resolvable hold you could approve through the api the gate is free forever everything that keeps you safe the engine the five rules human approval observe mode the kill switch audit siem export is open source and always will be what s covered today claude code every tool call via a pretooluse hook wordpress woocommerce a standard plugin and n8n workflows database and graphql adapters are on the roadmap and the adapter contract is a public spec so you don t have to wait for us pip install reeflex claude governs a claude code agent npm i n8n nodes reeflex a gate node for your n8n workflows enter fullscreen mode exit fullscreen mode run your own engine with one docker compose up or start against the public endpoint above see how it all fits together at reeflex io and the code is on github at github com reeflex io reeflex break it fork it tell us where the rules are wrong the clone that improves the rules is a clone that improves the standard and that s a trade we ll take every time reeflex a seatbelt for the ai acting on your systems top comments 2 subscribe personal trusted user create template templates let you quickly answer faqs or store snippets for re use submit preview dismiss collapse expand alex shev alex shev alex shev follow building ai powered tools creator of seog ai terminalskills io curated terminal skills and cli tools for modern devs location dallas fort worth texas work founder at seog terminal skills joined mar 7 2026 jul 6 dropdown menu copy link hide this is the right place to be paranoid agent permissions should be narrower than the human s day to day database access because the agent will run more steps faster with less instinct for when a query is weird like comment like comment 2 likes like comment button reply collapse expand leo david leo david leo david follow founder of reeflex open source governance for ai agents deterministic gate that holds risky actions before they run zero llm in the decision path joined jul 6 2026 jul 6 dropdown menu copy link hide exactly right and well put more steps faster with less instinct for when a query is weird is the whole threat model in one sentence narrower permissions for agents should absolutely be the baseline least privilege got more important not less with agents the trouble we kept hitting is that permissions are static answers to a dynamic question a grant can express this agent may delete products it can t express deleting 3 products is routine deleting 500 is an incident or the 40th delete this hour is different from the 1st scale velocity and reversibility live outside the permission model so i d frame it as scope the permissions as tight as the job allows then judge the impact of what still fits through the two layers cover each other s blind spots and the second one is what catches the day the tightly scoped agent gets a bad instruction and does something perfectly permitted 100 times in a row like comment like comment 2 likes like comment button reply code of conduct report abuse are you sure you want to hide this comment it will become hidden in your post but will still be visible via the comment s permalink hide child comments as well confirm for further actions you may consider blocking this person and or reporting abuse leo david follow founder of reeflex open source governance for ai agents deterministic gate that holds risky actions before they run zero llm in the decision path joined jul 6 2026 trending on dev community hot tls handshakes and oauth flows are easier to learn by clicking through them security tls oauth webdev traditional coding vs agentic coding the flow state problem ai productivity programming discuss the silent mic drop discuss community dev community a space to discuss and keep up software development and manage your software career home dev challenges dev videos dev education tracks dev help advertise on dev organization accounts dev showcase about contact free postgres database dev shop mlh code of conduct privacy policy terms of use built on forem the open source software that powers dev and other inclusive communities made with love and ruby on rails dev community 2016 2026 we re a place where coders share stay up to date and grow their careers log in create account
|