Give your AI the task, not your company
Every AI tool you adopt asks for the same thing: access to everything. Read all the repositories. Read all the mail. Join every channel. Saying yes is faster than working out what the job needs, so most companies say yes.
Here is what that costs, a smaller ask, and what to do this week without buying anything.
Every tool asks for everything
A code-review bot wants your repositories. A support agent wants the help desk and the customer records. An assistant wants mail, calendar and chat. None of these asks is unreasonable alone: the vendor does not know which three repositories matter this week, so it asks for all of them. The broad grant is one click. The narrow grant is a small project.
So the narrow grant never gets made. Each tool ends up holding a key to far more than its job needs, and nobody can say what any of them can see, or what any of them has read.
The math: every tool times every byte
The risk does not add up tool by tool. It multiplies. If three tools can each reach four systems, you do not have three exposures. You have twelve paths to your data, and a fourth tool adds four more, whether or not it needs any of them.
We found the same shape in our own system. In qbrin’s own deployment, one organisation carried 357 agents, and every one of them searched the same corpus. Retrieval was narrowed by organisation and by nothing else. That was the default behaviour, not a decision anyone had made. It is what happens when scoping is optional and the broad grant is the easy one.
What goes wrong
Two things, and neither needs a clever attacker.
One leaked key. Keys leak. They end up in a build log, a laptop backup, a vendor’s support ticket. How much a leak costs is decided on the day you issue the key, not the day it leaks. A key that opens everything gives away everything. A key that opens one job’s slice gives away that slice.
One over-eager agent. An agent is trying to finish its task. Told to tidy up a release, and holding the right to merge code, it may merge. Nothing about that is malicious. It was allowed to, and nobody asked whether it should, or on what evidence.
We tested that second failure with a real agent framework. In our proof, a LangGraph agent receives five merge requests, all well formed. One carries a valid human approval and a passing build. The other four carry, in turn, no evidence at all, evidence for a different repository, an approval that has gone stale, and an agent that belongs to another tenant.
Without a check, the framework ran all five. With qbrin checking each call before the merge tool could run, the valid one ran and the other four were refused, each for a named reason: evidence missing, evidence unbound, evidence stale, cross-tenant. No language model made that decision. This is a small proof of one mechanism. We built it, and nobody outside qbrin has reproduced it yet. The full table is on the agent authorization proof page.
The fix, in three verbs
The fix is to change the direction of the connection. Your tools stop connecting to your systems. They connect to one place that does, and that place hands each of them what its job needs and checks what it does.
Know. List every identity that can act: people, AI agents, API keys, connections, and the tools nobody registered. You cannot narrow what you cannot see. qbrin’s Know builds that one inventory and scores each identity for exposure.
Scope. Give each AI the sources its job needs, and no more. A scope can only narrow, never widen, and before you switch one on you can preview what it would have cut from the agent’s last 30 days of cited documents. That is Scope.
Check. Before an agent acts, it sends the proposed action and the evidence behind it. qbrin answers go, hold, or ask a person, and every decision leaves a receipt. That is Check, and it is the part behind the proof above.
The AI proposes. qbrin checks the proof against current evidence, permissions and policy. A person approves what matters.
What this does not solve
We would read this section first, so it comes before the pitch.
- A tool that holds its own grant is not narrowed by qbrin. If a code-hosting app or a mail connector was authorised straight to your systems with its own OAuth grant, qbrin is not in that path and cannot shrink it. Know shows it as residual exposure. You close it by changing the grant at the source.
- Know and Scope are in early access. They are built, but they are not generally available yet. Check is live, with a public sandbox that runs in shadow mode: nothing is enforced, no real grant is issued, and the receipts do not persist.
- Scope narrows sources only, for now. There is no folder, time-range or field-level redaction yet. A scoped agent also loses graph lookup, because the graph does not record which source a fact came from, so there is nothing to filter on.
- A check is only as good as its evidence. It can refuse a merge that has no approval. It cannot tell you whether your approval process is a good one.
What to do this week, with no product at all
You can capture most of the benefit with a spreadsheet and an afternoon.
- List every AI tool and every key. Every assistant, bot, plug-in and automation that touches your systems, and every key, token and grant it holds. Your mail, chat and code hosts each list the apps authorised on them. Start there, and include the tool someone tried once and forgot.
- Write one sentence for each. What job does it do, and what does it need to read to do it? “Reviews pull requests on three repositories.” If nobody can write the sentence, that tells you something.
- Cut each grant to its sentence. Where the tool lets you, pick repositories instead of all of them, one channel instead of every channel, read-only instead of read and write.
- Remove the rest. Revoke the keys of tools nobody uses. Rotate any key that lives somewhere you cannot account for.
- Keep a person in front of the irreversible. Money moving, code reaching production, anything sent in your name.
- Date the list and give it an owner. Read it again next quarter. New tools will have arrived.
Do only that and you have shrunk both sides of the multiplication: fewer tools, and less for each one to read.
If you want a tool for it
qbrin builds the three verbs: Know (early access), Scope (early access) and Check (live, with a public sandbox). The principle holds without us. Give your AI the task, not your company.
Comments
Sign in with GitHub to reply. Threads live in a public repository, so anyone can read them without an account.