An open-source text-to-SQL engine you can configure to your own data.
Ideas, experiments, and tools for the agentic world.
OPEN SOURCE · RELEASEmnemiq
An open-source text-to-SQL engine you can run on your own data, see where it goes wrong, and adjust — the model, retrieval, semantic layer, and verifier are all settings rather than internals.
Develop with mnemiq. Deploy with Fabriq’s per-user database controls and audit trail.
Build a production data agent
Mnemiq: From Text-to-SQL to Governed Data Agents
How Mnemiq and an independent governance framework help teams evaluate identity, permissions, query safety, refusals, and auditability in data agents.
Read the story
How to Send Gmail From an AI Agent on Behalf of Your Users
Per-user OAuth, the Gmail scope that avoids a security assessment, MIME and base64url in Python, refresh-token traps, quotas, and why your agent should draft before it sends.
Read the story
Google OAuth Verification and CASA, Explained for AI Agent Startups
Which Gmail, Drive and Calendar scopes trigger which Google review, what CASA actually asks of an AI agent, how Limited Use treats model training, and how to ship before restricted approval lands.
Read the story
Slack for AI Agents: User Tokens vs. Bot Tokens, and Shipping to Many Workspaces
When a Slack agent should post as its bot and when it should read as the user, how to request both in one install, and the 2025 rate-limit and API-terms changes that decide distribution.
Read the story
Giving an AI Agent Access to Your Users' Google Drive Without Over-Scoping
Why the Google Picker plus drive.file should be your default instead of drive.readonly, how files.list, files.export and changes.list actually behave, and why a shared vector index leaks across users.
Read the story
Letting an AI Agent Book Meetings on Your Users' Calendars
Most scheduling agents ask for full calendar access when freebusy plus events.owned would do. The scope ladder, conferenceData for Meet links, recurrence, client-generated event ids, and sync tokens.
Read the story
Which Identity Providers Support AI Agent Management?
Entra, Google Cloud IAM, Okta and Ping ship a distinct agent identity today. Auth0 and Keycloak give you delegation primitives instead. What each one does, checked against vendor docs.
Read the story
Cross-App Access: The Enterprise Problem Behind Agent SaaS Sprawl
An employee-authorized agent accumulates OAuth grants across a dozen SaaS tenants, each surviving offboarding alone. The federation standards that make that governable are arriving now.
Read the story
Agent-to-Agent Authorization: What Breaks When Delegation Chains Get Long
A2A standardizes how agents talk, not what authority travels with the request. What breaks at hop three, which mechanisms exist today, and the invariants worth enforcing before they do.
Read the story
Workload Identity for Agents: SPIFFE, SVIDs, and the End of Long-Lived Keys
SPIFFE gives a workload a cryptographic identity with no secret to steal. Here is how SVIDs, attestation and trust-domain federation work, and why they answer only half the question an agent raises.
Read the story
Approval Gates That Don't Become Rubber Stamps
Human-in-the-loop is the most-cited agent safety control and the least-engineered one. A framework for deciding which actions warrant a gate, how to budget approvals, and what the approval artifact must contain.
Read the story
Sandboxing Agents: What Each Isolation Boundary Actually Contains
Process sandboxes, containers, gVisor, microVMs, VMs and Wasm each stop something different. A boundary-by-boundary guide for agents that run code, drive browsers, or control a desktop.
Read the story
MCP Supply Chain Security: Tool Poisoning, Rug Pulls, and Registry Trust
A tool description is untrusted input the model treats as instruction. What the 2026 MCP supply chain incidents actually showed, and the adoption pipeline that survives them.
Read the story
Architecting Against Prompt Injection: Why Filtering Fails and Structure Works
Detection-based defenses plateau under adaptive attack. The durable answer separates control flow from data flow so untrusted content structurally cannot choose which privileged action runs.
Read the story
The OWASP Top 10 for Agentic Applications, Explained for Builders
A builder's translation of ASI01–ASI10: the concrete failure behind each risk, a realistic scenario, and which layer of the stack actually mitigates it. Most of these are not model problems.
Read the story
Token Exchange for Agents: Delegation Without Impersonation (RFC 8693)
RFC 8693 lets an agent act for a user without becoming the user. The difference lives in one nested JWT claim, and getting it right decides whether your audit trail means anything.
Read the story
OAuth 2.1 for Agent Builders: What Changed and Why It Matters
OAuth 2.1 folds a decade of security guidance into one spec. For agent builders the load-bearing parts are discovery, runtime client registration, and audience-restricted tokens.
Read the story
Building a Connector: From OpenAPI Spec to Governed Agent Tools
Generating tools from an OpenAPI document is the easy 20%. This is the other 80%: operation selection, lossy schema mapping, per-user auth, pagination, backoff, idempotency, and write safety.
Read the story
How to Build an MCP Server (Against the 2026-07-28 Spec)
A build guide written against the 2026-07-28 MCP specification: the stateless core, per-request capabilities, Extensions and Tasks, and what it takes to be a correct OAuth 2.1 resource server.
Read the story
Designing Tools Agents Can Actually Use
Tool schema design is the highest-leverage reliability work available to an agent team, and almost nobody does it deliberately. Naming, parameters, responses, errors, and the tool-count problem.
Read the story
Building Your First Production Agent: A Guide That Doesn't Skip Authorization
A working support-triage agent built on the Anthropic Messages API tool-use loop, with identity, scoped authorization, and an audit record wired in from the first commit rather than retrofitted later.
Read the story
The Enterprise AI Agent Integration Layer
Connecting an agent to a tool is the easy half. The hard half is deciding whether this agent, acting for this person, should be allowed to take this action — and proving afterward what it did.
Read the story
10 Best AI Agent Integration Platforms
A ranking of AI agent integration platforms judged on more than connector count: agent identity, acting-user authority, action-level permissions, credential handling, and auditability.
Read the story
10 Best Composio Alternatives and Competitors for AI Agent Integrations
Composio leads on catalog size. This is a ranked look at the alternatives worth evaluating when the harder problem is authority: which agent, acting for which user, may take which action.
Read the story
Building Trust in Autonomous Systems
Trust doesn't come from claiming an agent is safe. It comes from proving it's governed — scoped, watched, recoverable, and owned by someone who can answer for it.
Read the story
Agent Accountability Frameworks
Six named owners on paper is not the same as accountability. What matters is which roles can actually act in the first ten minutes of an incident, and which act afterward.
Read the story
Who Is Responsible for an AI Agent?
Naming a business owner isn't the same as giving them a way to act. The interesting failure is what happens when the accountable person has no switch to pull.
Read the story
Preparing for Agent Compliance Regulations
Regulators will ask what a specific agent did on a specific day, not whether you have a policy. Build the evidence into how agents run now, because it can't be produced after the fact.
Read the story
Audit Logging Best Practices for AI Agents
Log agent identity, user context, tool calls, and the gate decision on every path a call can take. Tamper-resistant, connected across systems, and actually reviewable.
Read the story
What Is an Agent Audit Trail?
A record of what an agent actually did — the action, the tool, the data, the user, the gate decision, and the outcome. Trust requires evidence.
Read the story
Agent Credentials vs. Human Credentials
Agents aren't human users and shouldn't silently borrow their access. Why an agent credential is a structurally different object, and what a healthier model looks like.
Read the story
Managing Secrets for AI Agents
Secrets don't belong in prompts, configs, or repos. Scoping, separation, traceability, rotation, and revocation for the credentials agents hold.
Read the story
What Is Agent Credential Management?
The keys, tokens, and secrets agents use to reach enterprise systems, and the operational discipline that keeps them scoped, stored, rotated, and revocable.
Read the story
Permission Models for Autonomous Systems
Autonomy isn't binary. Reach and initiative are different questions, and the layer most models skip is whether an agent should act on its own or wait.
Read the story
Managing Agent Permissions at Scale
Templates, context-aware exceptions, automated reviews, and usage monitoring — bringing fragmented agent permissions into one governance model.
Read the story
Agent Permissions Best Practices
Least privilege, action-level scopes, user-aware permissions, approvals for high-risk actions, and reviews — treating permissions as dynamic controls.
Read the story
Agent Authorization vs. Authentication
Authentication verifies identity; authorization determines access. Why agents need both, and what changes when the actor making the request isn't a person.
Read the story
Role-Based Access Control for AI Agents
RBAC is a strong foundation for agent permissions, and a specific, predictable way it breaks. What belongs in a role, and what never should.
Read the story
Agent Authorization Explained
Authorization is not one decision but several, checked in sequence. A plain walkthrough of the layers, the intersection rule, and why the two most common failures sit at opposite extremes.
Read the story
Agent Offboarding and Decommissioning
The most overlooked part of agent governance: retiring agents cleanly so abandoned agents don't become invisible access paths.
Read the story
Provisioning AI Agents at Scale
Identity, registration, scoped authorization, credentials, and monitoring by default: a repeatable six-stage path to production for hundreds of agents.
Read the story
What Is Agent Lifecycle Management?
Managing an agent from proposal through approval, production, change management, and retirement — so agents don't drift out of control.
Read the story
Agent Registry vs. Agent Inventory
Inventory and registry aren't rival terms fighting over one meaning. They're sequential records, and one has to feed the other before either is useful.
Read the story
Building an Enterprise Agent Registry
From intake to authorization to periodic review — how to make approved, governed agent deployment a repeatable process.
Read the story
What Is an Agent Registry?
The formal system of record for approved agents — the control plane that defines which agents are recognized, governed, and allowed to operate.
Read the story
Agent Visibility vs. Agent Governance
A written rule that nobody can verify is being followed isn't governance yet. It's a document. Visibility is what turns it into something real.
Read the story
Achieving Agent Visibility Across the Enterprise
When an agent misbehaves, the useful question isn't what logs exist. It's what to pull up first, in what order, and whether the pieces resolve to one story.
Read the story
What Is Agent Visibility?
Seeing where agents operate, what they access, what they do, and how they behave over time — the operational layer beyond a static inventory.
Read the story
Agent Inventory vs. CMDB
A CMDB confirms an agent exists. It has no field for what the agent is allowed to do, and that gap is exactly where a security review stalls.
Read the story
Building an Enterprise Agent Inventory
A practical playbook for discovering, normalizing, and owning every agent across AI platforms, SaaS, cloud, and code.
Read the story
What Is an Agent Inventory?
A structured system of record for every agent: who owns it, what it can access, what it can do, and whether it's still approved to operate.
Read the story
The Rise of Shadow Agents
Shadow IT has an AI successor: shadow agents — autonomous systems running with real access but no visibility, ownership, or governance.
Read the story
Why Enterprises Need Agent Discovery
One unregistered vendor-portal agent, walked through end to end, shows exactly where discovery would have shortened an incident from days to hours.
Read the story
What Is Agent Discovery?
Identifying every AI agent operating across your enterprise — internal, third-party, SaaS-embedded, or API-connected — is the first layer of Agent Operations.
Read the story
AI Governance Has to Move From Policy to Runtime
Why written policy and model approvals can't govern systems that retrieve data, call tools, and take action in real time — and what runtime governance looks like.
Read the story
AI Agents and the EU AI Act: From Model Compliance to Runtime Governance
What the EU AI Act means for agentic systems — and why compliance must shift from model selection to runtime governance of what agents actually do.
Read the story
The Compliance Cost of Uncontrolled AI Agents
How misaligned agents quietly generate real financial risk — and why the true cost is far higher than most companies realize.
Read the story
The Real Cost of Rogue AI Actions: What Companies Are Seeing
Rogue agent actions are rarely dramatic. They're ordinary systems doing ordinary work with slightly too much reach, and the bill lands in three separate places.
Read the story
The 5 Types of Agent Hallucinations (and Why Permission Hallucination Is the Worst)
Not all hallucinations are equal. The five distinct failure modes of autonomous agents, and why permission hallucination is the one that actually causes incidents.
Read the story
How to Pass Context Safely (Without Leaking Sensitive Data or Executing Hidden Instructions)
How to share context between steps and agents without leaking sensitive data or executing hidden instructions.
Read the story
How to Handle Ambiguous User Requests (and Prevent Dangerous Interpretations)
Asking a clarifying question every time an agent is unsure is not safety, it's a tax users stop paying. The judgment that matters is choosing between ask, assume out loud, and refuse.
Read the story
Identity for AI Agents: A Technical Primer
A technical primer on identity for AI agents — what it means, why traditional IAM falls short, and how to build per-agent identity, scopes, MCP/OAuth integration, audit, and revocation.
Read the story
MCP, OAuth, and the Agent Permissioning Problem
MCP standardizes how agents call tools. OAuth standardizes how apps get tokens. Neither decides whether a specific agent should take a specific action for a specific user right now.
Read the story
Why AI Agents Need Permissioning, Audit Logs, and Revocation
The three controls that separate AI agent demos from AI agent deployments: per-action permissioning, immutable audit logs, and immediate revocation. Why each is non-negotiable.
Read the story
How to Build Agent Memory Without Letting It Drift or Corrupt Itself
A practical engineering guide for preventing hallucinations, contradiction, and self-reinforcing errors in agent memory systems.
Read the story
How to Add Confidence Scores to Agent Outputs (So They Know When They Don't Know)
Most agents can't tell you when they don't know. How to add calibrated confidence scores so agents can defer, escalate, or ask.
Read the story
Integrating Confidence Scores Into Real Agent Frameworks (LangChain, LangGraph, AutoGen, Instructor)
Wiring confidence scores into LangChain, LangGraph, AutoGen, and Instructor — without rebuilding your stack.
Read the story
Building Agents with Observability: Metrics, Traces, Logs & Semantic Telemetry for LLM Workflows
Treat agents like distributed systems: the metrics, traces, logs, and semantic telemetry you need to debug LLM workflows in production.
Read the story
How to Optimize Agent Cost and Latency—Without Breaking Behavior
The engineering patterns that cut agent cost and latency without breaking behavior — model routing, lazy evaluation, caching, and context trimming — and where each one quietly goes wrong.
Read the story
Optimizing Agent Cost & Latency in Practice (LangChain, LangGraph, AutoGen Versions)
The fast-planner, lazy-retrieval, slow-executor pattern implemented end to end in LangChain, LangGraph, and AutoGen, plus how to measure whether it's actually working.
Read the story
A Field Guide to Planning Algorithms for Agents
CoT, ToT, GoT, ReAct, PAL, and multi-stage planners — compared, stress-tested, and implemented.
Read the story
A Developer's Guide to Thinking in Agents, Not Apps
An app is safe to get wrong because a human reviews the output before anything happens. An agent removes that review by design — here's what that costs, concretely.
Read the story
How to Design a Great AI Persona: A Step-by-Step Guide
From psychology to prompts: how to engineer an AI persona users trust and your system can actually implement.
Read the story
The Big Five Personality Types — For AI Agents
Why your agent already has a personality, how to tune it, and what each of the Big Five traits really means.
Read the story
The New Digital Etiquette: How Humans Should Interact With AI Agents
A user's guide to clarity, boundaries, and avoiding weird misunderstandings with your digital coworkers.
Read the story
Multi-Agent Patterns as Workflow Loops
The multi-agent patterns everyone diagrams (two-agent loops, group chat, manager-worker, hierarchies) all reduce to the same node-and-edge graph. What actually decides whether one runs safely is the termination logic, not the shape.
Read the story
From One Agent Runtime to Many: What Actually Needs to Stay Centralized
Decentralizing your agent stack isn't an all-or-nothing move. Execution should be allowed to fragment across teams; connectivity and identity shouldn't, and conflating the two is where these architectures go wrong.
Read the story
Agent Design Patterns: Which Ones Are Actually Worth Building
A working catalogue of single- and multi-agent design patterns, with an opinion attached to each one: what it buys you, what it costs, and whether a team shipping this quarter should reach for it.
Read the story
No-Code Agent Builders: What the Abstraction Buys You, and Where It Breaks
Visual and low-code agent builders trade control for speed on the common path. That trade holds for simple workflows and standard connectors, and comes apart exactly where multi-agent loops and custom logic start.
Read the story
The Dark Side of AI Personality: Traits You Should Never Give an Agent
Some personalities empower users. Others quietly manipulate, destabilize, or harm them.
Read the story
Why AI Agents Need Personality
And why \"a little charm\" makes automation more reliable, trustworthy, and usable.
Read the story
The Hidden Risk of \"Hallucinated Permissions\" in AI Agents
Explore how autonomous agents invent access they never received, why legacy IAM cannot contain fabricated authority, and the guardrails enterprises need now.
Read the story
The Problem of Passing Context Between Agents (And Why It's So Dangerous)
Why context that's clean, correctly trusted, and honestly labeled at every hop can still combine into something no single agent was authorized to reveal.
Read the story
Why OAuth Alone Isn't Enough for AI Agents
OAuth checks whether a token is valid, not whether the action behind it is a good idea. That gap is where autonomous agents cause real damage.
Read the story
Token Refresh 101: How OAuth Refresh Tokens Actually Work
Why refresh tokens exist, how rotation protects your users, and what an invalid_grant error is actually telling you when it shows up in production.
Read the story
How to Store OAuth Tokens Securely (Without Leaking Secrets)
Token storage patterns for backends, browser apps, and native clients, plus the difference between deleting your copy of a token and actually revoking it.
Read the story
How Slack's OAuth Flow Works (and How to Call Their API With Python)
Understand Slack's authorization code flow from redirect to token exchange, then ship your first Web API call with the Python SDK.
Read the storyNo stories match. Try another topic.