frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: How are you enforcing permissions for AI agent tool calls in production?

1•amjadfatmi1•1h ago
I’m seeing more teams ship agentic systems that can call real tools (DB writes, deploys, email, billing, internal APIs). Most of the safety patterns I hear are prompt rules + basic validation + “human-in-the-loop for risky stuff.”

My question: in a real production environment, what’s your enforcement point that the agent cannot bypass? Like, what actually guarantees the tool call isn’t executed unless it passes policy?

Some specific things I’m curious about:

Are you enforcing permissions inside each tool wrapper, at a gateway/proxy, or via centralized policy service?

How do you handle identity + authorization when agents act on behalf of users?

Do you log decisions separately from execution logs (so you can answer “why was this allowed?” later)?

How do you roll out enforcement safely (audit-only/shadow mode -> enforcement)?

What failure modes hurt most like policy bugs, agent hallucinations, prompt injection, or tool misuse?

Would love to hear how people are doing this in practice (platform/security/infra teams especially)

God Emperor Trump

https://en.wikipedia.org/wiki/God_Emperor_Trump
1•KnuthIsGod•1m ago•0 comments

Seeking alignment on product boundaries for an early-stage social platform

https://github.com/wakaka-stack/product-v--foundational-veto
1•kensei•2m ago•1 comments

Package Management Is a Wicked Problem

https://nesbitt.io/2026/01/23/package-management-is-a-wicked-problem.html
1•zdw•3m ago•0 comments

Show HN: EchoDeck – A unified feed for RSS and Nostr to break information silos

https://www.echodeck.io
1•JoeyPro•7m ago•1 comments

Toilet Maker Toto's Shares Get Unlikely Boost from AI Rush

https://finance.yahoo.com/news/toilet-maker-toto-shares-unlikely-055450977.html
1•zdw•8m ago•0 comments

Built a Sandbox for Agents in Rust

https://github.com/vrn21/bouvet
1•vrn21•9m ago•0 comments

10GbE in 2026 Is Finally Hitting the Tipping Point

https://www.servethehome.com/10gbe-in-2026-is-finally-hitting-the-tipping-point/
1•ksec•9m ago•0 comments

My Time at Amazon

https://beccaselah.substack.com/p/my-time-at-amazon-part-i
1•vinhnx•14m ago•0 comments

agentlib – A simple framework for building agents

https://github.com/jacobsparts/agentlib
1•kristianpaul•15m ago•0 comments

The Project

https://zenodo.org/records/18357627
1•KaoruAK•19m ago•0 comments

Ancient giant kangaroos could hop when they needed to

https://phys.org/news/2026-01-ancient-giant-kangaroos-hindlimb.html
1•gmays•21m ago•0 comments

I produced a better way to get agents to make quality code, not just syntax

https://ai-lint.dosaygo.com
1•keepamovin•29m ago•1 comments

Shark attack truth: Why experts won't admit population boom

https://www.news.com.au/technology/science/animals/shark-attack-truth-why-experts-wont-admit-popu...
1•SirLJ•50m ago•1 comments

The 2026 Linux Summer Games [video]

https://www.youtube.com/watch?v=URbW3j_GYKg
1•zdw•52m ago•0 comments

Yat Another HTTP Proxy Analyzer

https://github.com/jp/Hermes-Proxy
1•gros_pigeon•56m ago•1 comments

ICE flew 2-year-old to Texas despite court order to release her from custody

https://kstp.com/kstp-news/top-news/ice-flew-2-year-old-to-texas-despite-court-order-to-release-h...
6•therobots927•59m ago•0 comments

Nvidia and Linux, a Question

1•mashally•1h ago•2 comments

Europeans Can Turn 2 Car Seats into 4 Child Seats, but It's Illegal in America

https://www.theautopian.com/why-europeans-can-convert-two-car-seats-into-four-child-seats-but-its...
7•josephcsible•1h ago•1 comments

Need Feedback for Idea

1•molozey•1h ago•0 comments

"People are going to stop and ask you, 'How can I help?' Let them."

https://www.npr.org/2026/01/20/nx-s1-5683170/let-them-the-small-bit-of-advice-that-made-a-big-dif...
1•NaOH•1h ago•0 comments

NASA about to send people to the moon – in a spacecraft not everyone thinks safe

https://www.cnn.com/2026/01/23/science/artemis-2-orion-capsule-heat-shield
2•everybodyknows•1h ago•1 comments

Have We Been Wrong About Language for 70 Years? New Study Challenges Theory

https://scitechdaily.com/have-we-been-wrong-about-language-for-70-years-new-study-challenges-long...
1•mikhael•1h ago•0 comments

Health insurance execs shift blame for costly, confusing health care system

https://www.statnews.com/2026/01/22/health-insurance-execs-blame-high-costs-hospitals-doctors-pha...
2•brandonb•1h ago•0 comments

Get Shit Done

https://github.com/glittercowboy/get-shit-done
1•davidkimai•1h ago•0 comments

Fuggerei

https://www.fugger.de/en/fuggerei
1•thunderbong•1h ago•0 comments

Ask HN: How are you enforcing permissions for AI agent tool calls in production?

1•amjadfatmi1•1h ago•0 comments

Caroline Ellison Former Alameda CEO Released from Prison After 440 Days

https://www.sec.gov/enforcement-litigation/litigation-releases/lr-26450
49•sizzle•1h ago•23 comments

The Epic Survey of Mason and Dixon

https://www.nspe.org/career-growth/pe-magazine/march-2014/the-epic-survey-mason-dixon
1•MrBuddyCasino•1h ago•0 comments

Agency Recruiters can sell retained searches

https://talnet.co/posts/how-agency-recruiters-can-sell-retained-searches-20260242311174
1•bouia•1h ago•0 comments

Turn any developer into a low performer

https://pipify.lovable.app/
1•thedeep_mind•1h ago•1 comments