SShortSingh.
Back to feed

Microsoft's Agent Governance Toolkit shares trust boundary with agents it governs

0
·1 views

Microsoft's open-source Agent Governance Toolkit enforces governance at the application middleware layer rather than the OS kernel, meaning the policy engine and the agents it oversees share the same process boundary. Security reviewer Venkat Peri of Advisor360°, who works on agentic AI infrastructure for wealth management, flagged this architectural limitation as significant. The shared trust boundary becomes a critical vulnerability when an agent is compromised via prompt injection or a poisoned tool result, since the attacker is already inside the containment perimeter. An alternative architectural approach, such as the one described by AI startup Zarel, treats the reasoning model as a remote oracle whose outputs are proposals validated against a schema rather than executable instructions. Under this model, permissions are derived from signed tokens and live database state rather than the model's own claims, preventing a compromised reasoner from taking unauthorized actions.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

How to Build a Reversible PII Redaction Layer to Protect Data Sent to LLM APIs

As AI agents increasingly process emails, tickets, and databases, sensitive personal data such as ID numbers and phone numbers routinely gets embedded in prompts and sent to third-party LLM APIs without deliberate intent. A developer reviewed multiple Vietnamese codebases and found a recurring pattern where raw ticket content containing customer PII was passed directly to API calls. To address this, they built a reversible redaction layer using Python and Microsoft Presidio, an open-source PII detection library, extended with custom recognizers for Vietnamese national ID numbers and mobile phone formats. The system replaces sensitive values with placeholder tokens before sending data to the LLM, stores the mappings in a local session vault, and restores real values only after the response is returned. The approach is framed as a compliance necessity given Vietnam's Decree 13/2023 and the Personal Data Protection Law taking effect on January 1, 2026, which impose real legal risk on uncontrolled cross-border data transfers.

0
ProgrammingDEV Community ·

Learn Python Collections by Building a Personal Expense Tracker

A new tutorial on DEV Community teaches Python developers how to manage collections of data by building a personal expense tracker. The project uses Python lists, dictionaries, and loops to record and display multiple expense entries. Users learn to store structured records by bundling item names and costs into dictionaries, then appending them to a list. A while loop keeps the program running, allowing continuous input until the user chooses to view a summary. The tutorial is aimed at beginners who already understand basic Python variables and the input() function.

0
ProgrammingDEV Community ·

EF Core vs Marten and Polecat: Choosing the Right .NET Data Tool

In .NET development, EF Core remains the default ORM for genuinely relational data — such as tables queried independently or schemas shared across services — but it adds complexity when used to model aggregates like orders with nested items and addresses. Tools like Marten (for PostgreSQL) and Polecat (for SQL Server) store entire domain objects as JSON documents in the same database already in use, eliminating the need for a separate document database. The common pain points of EF Core overuse include growing Include chains, AsSplitQuery workarounds, and frequent migrations for unsettled schemas — symptoms that suggest a document model may be more appropriate. With a document session, an aggregate is loaded by ID, modified, and saved in a single commit, avoiding the mapping overhead EF Core requires to reassemble a unified domain object from relational tables. The core guidance is to use EF Core where data is truly relational and reach for Marten or Polecat where the domain naturally treats an object as one cohesive unit.

0
ProgrammingDEV Community ·

Azure DocumentDB 0.109 Uses Native PostgreSQL Indexes to Match MongoDB Query Performance

Azure DocumentDB, a PostgreSQL extension, has demonstrated in version 0.109 that it can handle MongoDB-style queries involving filtering, sorting, and pagination using a single compound index scan. The test replicated an earlier MongoDB benchmark that highlighted the performance advantage of document models over normalized relational databases for one-to-many relationships. DocumentDB achieves this by leveraging PostgreSQL's extensibility to define native Extended RUM indexes suited for non-relational data schemas, rather than relying on standard RDBMS indexes. The execution plan confirmed that a single index scan covered all four query stages — $match, $sort, $limit, and $project — with no additional sort or filter operations required. This positions DocumentDB as a performance-compatible alternative to MongoDB for document-model workloads built on PostgreSQL.

Microsoft's Agent Governance Toolkit shares trust boundary with agents it governs · ShortSingh