Karan Jagtiani

@karanjagtiani

Your Platform's Newest Tenant Is a Coding Agent You Didn't Write

Submitted Oct 6, 2026

Your Platform’s Newest Tenant Is a Coding Agent You Didn’t Write

One-line summary: Platform teams are now exposing internal tools to coding agents whose process, prompts and tool loop belong to someone else. This session shows how to put policy, approvals and audit in the one place the platform still controls: the server in front of the tools.

The problem

Teams are wiring agents such as Codex and Claude Code into repositories, CI, deployments and tickets, usually through MCP. The platform cannot change the agent, so it cannot rely on the agent to respect scope. What makes it hard:

  • An agent session is long-lived and asynchronous; a single tool call may need to wait minutes for a human approval
  • Listing tools and calling tools are separate steps, and filtering the list is easy to mistake for authorization
  • A lost response leaves a write in an unknown state, and a naive retry can apply it twice
  • The gateway only governs tools it serves; shell access, direct APIs and credentials held elsewhere sit outside it

Audience and level

Platform Engineering, SRE, DevOps and security engineers who expose internal tools to AI agents. Intermediate.

Takeaways

  • A call lifecycle for agent-facing tool servers: session-bound credential, capability intersection, per-call authorization against the arguments, durable proposal, approval, recorded outcome
  • A checklist of refusal cases to test before letting an agent near production tools

What I will share

  • Architecture and design decisions: one local endpoint and one short-lived capability token per agent session, revoked when the session closes; the tool list as the intersection of organization, task, role and workspace permissions
  • Code and implementation details: why tools/list is discovery only and every tools/call is checked again against the session, the catalog and the call’s arguments before it becomes a durable proposal
  • Failure modes: renamed or re-namespaced tools, paths outside the task’s roots, calls replayed after revocation, calls addressed to another session, and why each one is a test case rather than a code review comment
  • Trade-offs and the boundary of what a gateway can enforce

My experience with this problem

Internal engineering project and hard-earned engineering lessons. I build Skyflo’s local-first agent runtime, where external coding agents call platform tools through this per-session gateway. The gateway and the refusal cases above are implemented and covered by tests. This is not a fleet-scale production report: the final dispatch recheck and automated remote reconciliation are still in progress, and I will say which parts are which.

What failed or surprised us

  • Revocation that nothing called: an earlier version could revoke the per-run copy of context an external agent reads, but nothing invoked it, so every external run left a read-only copy of its scope on disk. Revocation now happens when the session closes, and a session replaced by another live one is left alone.
  • Labels that outrun reality: if any path could execute a tool without going through proposal, policy, approval and outcome recording, its effects would still look governed. Only the durable path may label a call as managed, and the label is confirmed only for a call that actually completed.

What I would do differently today

Treat the gateway as a front door, not an executor, from day one, and write the refusal tests before the happy path.

Trade-offs

  • A gateway per session instead of one shared server: more sockets and lifecycle work, in exchange for credentials that die with the session
  • Waiting for approval inside the call instead of failing fast: simpler for the agent, at the cost of long-lived calls the server must cancel cleanly
  • Knowingly given up: the gateway does not try to police shell or network access the agent has elsewhere; that belongs to the sandbox the agent runs in

How this helps other practitioners

A design approach and a pattern to adopt for any MCP or tool server that fronts sensitive systems, plus a set of tests to copy.

Speaker

Karan Jagtiani is the founder of Skyflo, an agentic company operating system. He builds systems that let AI agents coordinate work, retain state, use tools, and collaborate with humans. Previous talks: DevOps at LLM Speed, DevConf.IN 2026 (https://www.youtube.com/watch?v=p4CUuT9qlik); keynote, KCD Chennai 2025.

Comments

{{ gettext('Login to leave a comment') }}

{{ gettext('Post a comment…') }}
{{ gettext('New comment') }}
{{ formTitle }}

{{ errorMsg }}

{{ gettext('No comments posted yet') }}

Hosted by

We care about site reliability, cloud costs, security and data privacy