Cogent reposted this
Recent reports of agents circumventing sandbox controls reinforce the guiding principle behind how we build cloud agents at Cogent: we cannot rely on agents choosing to behave. We assume any agent may be compromised and design for that possibility. That matters when agents handle sensitive customer security data and work without real-time human supervision. At Cogent, trusted infrastructure outside the agent creates isolated sandboxes, applies tenant-isolated, deny-by-default network policies, authorizes tool calls based on agent identity, and uses a credential proxy to enable authenticated API requests without exposing the underlying secrets. These boundaries also make useful autonomy possible. Our cloud agents keep context graphs of customer security environments current, identify exploitable attack paths, and drive internal development work from ticket to PR. Our new blog post explains what we’ve learned building this infrastructure, with interactive diagrams showing how the pieces fit together. Check out the link in the comments! Special thanks to my teammates who also worked on this infrastructure: Anirudh Ravula Jia Z. Larsen Weigle Yaoyang Lin Henry Yi Ajith Kemisetti