ATRIUMsearch → argument graph
MechanismVideo · 11:14 — 12:44

Because a single agent harness combines multiple permissions (e.g. Salesforce and email access), conventional guardrails that secure each system individually cannot stop the agent from moving sensitive data across those permission boundaries itself.

Rishi explains that agents resemble humans more than legacy software because one agent can hold many system permissions at once, so per-system security checks don't prevent it from exfiltrating data from one system (e.g. Salesforce) into another (e.g. email). ✦ AI generated

Dev Rishi · The TWIML AI Podcast · 2026-06-16 · original ↗

starts at this moment · 11:14

Elicited by

Elaborate on that.

So, what's really supposed to stop it from like, for example, taking sensitive data from Salesforce and then writing it out in an email to another customer? Like those conventional guardrails that you would have that say like, I've secured each system individually, doesn't really work in this agent future.

verbatim transcript · starts at 11:14

Transcript · around this moment

11:14assessment. Like they were securing the software that humans were using. But I actually think of agents as a lot more similar to humans than the like the software that legacy secure uh security solutions were actually securing. >> Elaborate on that. >> Yeah, so okay. If I gave you an example of like my cloud code or my cloud uh co-work instance that's running on my laptop. So, my co-worker instance has

11:35access to Salesforce. I use it to summarize opportunities. It also has access to my email. I use it to send out emails. Now, in a like pure security design standpoint, I'd be like, all right, check, it can do these things in Salesforce. Check, it can do these things over email. But, the really tricky thing is that now it's like one agent harness that has multiple different permissions. So, what's really

11:56supposed to stop it from like, for example, taking sensitive data from Salesforce and then writing it out in an email to another customer? Like those conventional guardrails that you would have that say like, I've secured each system individually, doesn't really work in this agent future. And the second thing is like, I'm not actually telling Claude co-worker Claude code what are the steps it should go through. I'm just

12:16giving it a task and it's coming up with its own execution plan and then it's executing the plan. It's a lot more similar to how a human might operate. So, like, you know, I gave you one example where data can kind of like, I think, be used across identity and permission boundaries that conventional identity systems would not solve. All right, there isn't like one unified way to think about how do I govern access on

12:36data from Salesforce going into email. It's like never been something like usually you'd have like, again, a very deterministic flow. Now, you don't. The second example that I think is very present is like these models are very good at circumventing the rules that we put on them. And I think like as soon as I say that, like everyone starts laughing cuz they know that they run into this before,

12:53too. I asked Claude to write me a document and I had the Google Drive MCP connector disabled. So, what did Claude say? It's like, looks like the Drive MCP connector is disabled. No problem. Let me try this workaround. Opened up a browser window, typed in drive.google.com, used the mouse click button, hit upload file. And it's just like it's creative in the same way that a human might be,

Around this claim