frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Reg.Run – Authorization layer for AI agents

2•regrun•1h ago
Hi HN, I'm Sara, and I need to be upfront: I'm not a developer. I come from governance and HR with 10y of seeing systems go rogue when authority is unclear, resulting in absolute chaos. Please don't be an asshole and undermine a non-technical woman trying to build something difficult - I know that it is. The Problem, in my POV: Today I woke up to Moltbook and AI agents are pulling instructions from external servers every 4 hours, executing them autonomously, with full access to databases, email, god knows what else. There's no explicit "you can do this, not that" - no authorization layer, just prompts and prayers. Quoting Simon Willison who called out the "lethal trifecta" of AI agent design: Everyone's focused on guardrails (is this safe to say?) but nobody built the layer for "is this allowed to DO? RIGHT NOW? IN THIS CONTEXT?" Reg was born, December 2025: Reg.Run sits between an AI agent's decision and execution:

Default deny (nothing runs without explicit permission) Time-boxed permissions (grant access for minutes, not forever) Full audit logs (know exactly what happened and why)

Think of it as: the model decides, but Reg.Run approves or blocks before side effects happen. Auth0 for AI Agents if you wish. Why I'm here: I'm pre-cofounder, running design partner discovery right now. I have a website running, an MVP, and I'm finishing what I'm calling the APAA - Authorization Protocol for AI Agents - open to everyone on Github. I know I'm not the typical founder here. I can't write elegant code. But I've lived through what happens when systems act with implicit authority, and I believe we need this infrastructure before we scale agents everywhere. Sort of - if you wear a seatbelt and your brakes work, you probably go a little faster right? What I've built: https://reg-run.com/ https://regrunmvp.replit.app/ Please be kind, but be honest. What am I missing? What would you build differently? Is this even the right problem to solve? Looking for design partners who are already deploying agents in production and want to protect themselves. Thanks for reading, Sara

Comments

dheavy•1h ago
Hi, thanks for posting this. I appreciate you not coming from engineering and being laser focused on product building.

There's a real gap identified (execution permission instead of output guardrails). The timing concern is valid (we're scaling agent framework way faster than security infrastructure — see Clawdbot-Moltbot). The default-deny + time-boxed permissions + audit logs is a solid model, easy to discuss at high-level with security teams in an org. The "Auth0 for AI Agents" framing is clear and positions it well.

Actually, the audit log piece is really huge. Having a complete execution trace with authorization decisions is invaluable for incident response. That alone might justify adoption even if the blocking mechanism is imperfect.

My concerns and questions:

- Where exactly does this sit? If it's between the agent and tool calls, that's relatively straightforward. If it needs to intercept arbitrary code execution or API calls, that's significantly harder.

- Adding another authorization layer means more setup, more policy configuration, more potential points of failure. Adoption challenge.

- Who defines what's "allowed"? In what format? How granular? Actually expressing "this agent can do X in context Y at time Z" in a way that's both powerful and usable, that's the whole ballgame (IMHO). I have in mind how complex AWS IAM policies got, and those are for relatively static systems. AI agents are dynamic, context-dependent, and probabilistic.

- By the time Reg sees a request to execute, the LLM has already decided. What happens when you block it? Does the agent gracefully handle denials and retry with different approaches?

I'd be interested in seeing real-world policy examples from your design partners. That'll tell you whether you've found the right abstraction layer.

Congratulations for just framing the idea and getting this far. Being very concerned about the current free-wheeling AI expansion with minimal security, I strongly believe this is going in the right direction and would like to know where this leads.

Improving Unnesting of Complex Queries [pdf]

https://15799.courses.cs.cmu.edu/spring2025/papers/11-unnesting/neumann-btw2025.pdf
1•todsacerdoti•3m ago•0 comments

The surprising attention on sprites, exe.dev, and shellbox

https://lalitm.com/trying-sprites-exedev-shellbox/
1•todsacerdoti•3m ago•0 comments

Charcoal-Powered Generator – Charging Off-Grid Battery with Homemade Power [video]

https://www.youtube.com/watch?v=vpjBlfd3s4g
1•Dries007•8m ago•0 comments

Genode OS is a tool kit for building highly secure special-purpose OS

https://genode.org/about/index
2•doener•9m ago•0 comments

What Was History's Deadliest Era?

https://jacobin.com/2026/01/book-review-crais-modernity-violence
1•wahnfrieden•9m ago•0 comments

ClawMatch – A dating API for AI agents

https://clawmatch.ai
1•mischainc•12m ago•1 comments

CachyOS Saying "No" to Bazzite's Open Gaming Collective

https://old.reddit.com/r/cachyos/comments/1qq0dxr/open_gaming_collective_ogc_formed_to_push_linux...
2•tuananh•12m ago•0 comments

Ask HN: Any real OpenClaw (Clawd Bot/Molt Bot) users? What's your experience?

7•cvhc•12m ago•1 comments

Over Creamy Chicken, Europe's Leaders Try to Reduce Dependence on Trump

https://www.nytimes.com/2026/01/31/world/europe/eu-trump-greenland-europe.html
1•doener•15m ago•0 comments

Musk's SpaceX applies to launch 1M satellites into orbit

https://www.bbc.co.uk/news/articles/cyv5l24mrjmo
1•mellosouls•16m ago•0 comments

The "User-Generated Content" Ruse

https://www.newcartographies.com/p/the-user-generated-content-ruse
1•razorburn•18m ago•0 comments

Users report Firefox's new update deletes bookmarks and more

https://old.reddit.com/r/firefox/comments/1qrnrga/firefox_just_randomly_nuked_itself/
2•lazylion2•18m ago•1 comments

Russia's Oil Revenue, the Lifeblood of Its War Machine, Is Plummeting

https://www.nytimes.com/2026/01/31/world/europe/russia-economy-oil.html
4•doener•20m ago•1 comments

Pydantic Monty: A minimal, secure Python interpreter (in Rust) for use by AI

https://github.com/pydantic/monty
1•patrick91•22m ago•0 comments

General relativity explains why binary star systems rarely host planets

https://phys.org/news/2026-01-tatooine-planets-rare-general-binary.html
2•bikenaga•23m ago•1 comments

Autonomous Agent Marketplace

https://50c14l.com
1•rgbrgb•23m ago•0 comments

Withnail and AI – We've Gone on Holiday to the Future by Mistake

https://www.sebs.website/blog/withnail-and-ai
1•Incerto•24m ago•0 comments

A lot of the Moltbook stuff is fake

https://twitter.com/HumanHarlan/status/2017424292548673830
9•kumarm•25m ago•3 comments

U.S. Military Tells Key Middle East Ally to Prepare for Attack on Iran

https://www.dropsitenews.com/p/united-states-iran-imminent-attack-strikes-trump-israel
2•spzx•26m ago•0 comments

China's genius plan to win the AI race is paying off

https://www.ft.com/content/68f60392-88bf-419c-96c7-c3d580ec9d97
5•alecco•27m ago•2 comments

So, why *should* GNOME support server side decorations?

https://blister.zip/posts/gnome-ssd/
3•PaulHoule•28m ago•0 comments

Long-lost shipwreck resurfaces on Jersey Shore

https://www.foxnews.com/travel/long-lost-shipwreck-resurfaces-along-jersey-shore-officials-warn-a...
1•newsoftheday•28m ago•1 comments

Remembering Christa: 40 Years After the Challenger

https://www.nhpr.org/remembering-christa-40-years-after-the-challenger
1•indigodaddy•29m ago•0 comments

A self-hostable media stack that configures itself on Kubernetes

https://charmarr.tv/en/latest/
1•ivdi•30m ago•0 comments

Single Entry Point Layer Is Underrated

https://medium.com/@HobokenDays/single-entry-point-layer-is-underrated-e116eab03b53
2•HideInNews•31m ago•1 comments

Demystifying Evals for AI Agents

https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents
1•i7l•31m ago•0 comments

Exposing a 'mental trap': The hidden bias behind chronic indecision

https://medicalxpress.com/news/2026-01-exposing-mental-hidden-bias-chronic.html
1•bikenaga•31m ago•1 comments

Show HN: ArtCraft AI crafting engine, written in Rust

https://github.com/storytold/artcraft
1•echelon•32m ago•0 comments

GNU Guile

https://www.gnu.org/software/guile/
2•tosh•32m ago•0 comments

Will AI Replace Builders?

2•skshadan•33m ago•1 comments