THE FABRIQ JOURNAL / FEATURED RELEASE

An open-source text-to-SQL engine you can configure to your own data.

Ideas, experiments, and tools for the agentic world.

White butterflies in flight against a dark backgroundOPEN SOURCE · RELEASE

mnemiq

An open-source text-to-SQL engine you can run on your own data, see where it goes wrong, and adjust — the model, retrieval, semantic layer, and verifier are all settings rather than internals.

Read the release

Develop with mnemiq. Deploy with Fabriq’s per-user database controls and audit trail.

Build a production data agent
87 stories
Claude Monet’s Cliff Walk at Pourville: two figures above a blue sea and windblown coastal grass
MNEMIQ · ECOSYSTEM

Mnemiq: From Text-to-SQL to Governed Data Agents

How Mnemiq and an independent governance framework help teams evaluate identity, permissions, query safety, refusals, and auditability in data agents.

Read the story
Impressionist painting of a farm road past a red barn and a sunlit tree
ENGINEERING

How to Send Gmail From an AI Agent on Behalf of Your Users

Per-user OAuth, the Gmail scope that avoids a security assessment, MIME and base64url in Python, refresh-token traps, quotas, and why your agent should draft before it sends.

Read the story
Impressionist painting of a dirt road winding through a wildflower valley
ENGINEERING

Google OAuth Verification and CASA, Explained for AI Agent Startups

Which Gmail, Drive and Calendar scopes trigger which Google review, what CASA actually asks of an AI agent, how Limited Use treats model training, and how to ship before restricted approval lands.

Read the story
Impressionist painting of a weathered barn behind a split-rail fence
ENGINEERING

Slack for AI Agents: User Tokens vs. Bot Tokens, and Shipping to Many Workspaces

When a Slack agent should post as its bot and when it should read as the user, how to request both in one install, and the 2025 rate-limit and API-terms changes that decide distribution.

Read the story
Classic painting used as the article cover
ENGINEERING

Giving an AI Agent Access to Your Users' Google Drive Without Over-Scoping

Why the Google Picker plus drive.file should be your default instead of drive.readonly, how files.list, files.export and changes.list actually behave, and why a shared vector index leaks across users.

Read the story
Classic painting used as the article cover
ENGINEERING

Letting an AI Agent Book Meetings on Your Users' Calendars

Most scheduling agents ask for full calendar access when freebusy plus events.owned would do. The scope ladder, conferenceData for Meet links, recurrence, client-generated event ids, and sync tokens.

Read the story
Classic painting used as the article cover
IDENTITY

Which Identity Providers Support AI Agent Management?

Entra, Google Cloud IAM, Okta and Ping ship a distinct agent identity today. Auth0 and Keycloak give you delegation primitives instead. What each one does, checked against vendor docs.

Read the story
Classic painting used as the article cover
ENTERPRISE

Cross-App Access: The Enterprise Problem Behind Agent SaaS Sprawl

An employee-authorized agent accumulates OAuth grants across a dozen SaaS tenants, each surviving offboarding alone. The federation standards that make that governable are arriving now.

Read the story
Classic painting used as the article cover
DELEGATION

Agent-to-Agent Authorization: What Breaks When Delegation Chains Get Long

A2A standardizes how agents talk, not what authority travels with the request. What breaks at hop three, which mechanisms exist today, and the invariants worth enforcing before they do.

Read the story
Classic painting used as the article cover
WORKLOAD IDENTITY

Workload Identity for Agents: SPIFFE, SVIDs, and the End of Long-Lived Keys

SPIFFE gives a workload a cryptographic identity with no secret to steal. Here is how SVIDs, attestation and trust-domain federation work, and why they answer only half the question an agent raises.

Read the story
Classic painting used as the article cover
OVERSIGHT

Approval Gates That Don't Become Rubber Stamps

Human-in-the-loop is the most-cited agent safety control and the least-engineered one. A framework for deciding which actions warrant a gate, how to budget approvals, and what the approval artifact must contain.

Read the story
Classic painting used as the article cover
Isolation

Sandboxing Agents: What Each Isolation Boundary Actually Contains

Process sandboxes, containers, gVisor, microVMs, VMs and Wasm each stop something different. A boundary-by-boundary guide for agents that run code, drive browsers, or control a desktop.

Read the story
Classic painting used as the article cover
Supply chain

MCP Supply Chain Security: Tool Poisoning, Rug Pulls, and Registry Trust

A tool description is untrusted input the model treats as instruction. What the 2026 MCP supply chain incidents actually showed, and the adoption pipeline that survives them.

Read the story
Classic painting used as the article cover
AI Safety

Architecting Against Prompt Injection: Why Filtering Fails and Structure Works

Detection-based defenses plateau under adaptive attack. The durable answer separates control flow from data flow so untrusted content structurally cannot choose which privileged action runs.

Read the story
Classic painting used as the article cover
Security

The OWASP Top 10 for Agentic Applications, Explained for Builders

A builder's translation of ASI01–ASI10: the concrete failure behind each risk, a realistic scenario, and which layer of the stack actually mitigates it. Most of these are not model problems.

Read the story
Classic painting used as the article cover
DELEGATION

Token Exchange for Agents: Delegation Without Impersonation (RFC 8693)

RFC 8693 lets an agent act for a user without becoming the user. The difference lives in one nested JWT claim, and getting it right decides whether your audit trail means anything.

Read the story
Classic painting used as the article cover
IDENTITY

OAuth 2.1 for Agent Builders: What Changed and Why It Matters

OAuth 2.1 folds a decade of security guidance into one spec. For agent builders the load-bearing parts are discovery, runtime client registration, and audience-restricted tokens.

Read the story
Classic painting used as the article cover
CONNECTORS

Building a Connector: From OpenAPI Spec to Governed Agent Tools

Generating tools from an OpenAPI document is the easy 20%. This is the other 80%: operation selection, lossy schema mapping, per-user auth, pagination, backoff, idempotency, and write safety.

Read the story
Classic painting used as the article cover
Protocols

How to Build an MCP Server (Against the 2026-07-28 Spec)

A build guide written against the 2026-07-28 MCP specification: the stateless core, per-request capabilities, Extensions and Tasks, and what it takes to be a correct OAuth 2.1 resource server.

Read the story
Classic painting used as the article cover
TOOL DESIGN

Designing Tools Agents Can Actually Use

Tool schema design is the highest-leverage reliability work available to an agent team, and almost nobody does it deliberately. Naming, parameters, responses, errors, and the tool-count problem.

Read the story
Classic painting used as the article cover
GETTING STARTED

Building Your First Production Agent: A Guide That Doesn't Skip Authorization

A working support-triage agent built on the Anthropic Messages API tool-use loop, with identity, scoped authorization, and an audit record wired in from the first commit rather than retrofitted later.

Read the story
Classic painting used as the article cover
INTEGRATION LAYER

The Enterprise AI Agent Integration Layer

Connecting an agent to a tool is the easy half. The hard half is deciding whether this agent, acting for this person, should be allowed to take this action — and proving afterward what it did.

Read the story
Classic painting used as the article cover
BUYER GUIDE

10 Best AI Agent Integration Platforms

A ranking of AI agent integration platforms judged on more than connector count: agent identity, acting-user authority, action-level permissions, credential handling, and auditability.

Read the story
Classic painting used as the article cover
ALTERNATIVES

10 Best Composio Alternatives and Competitors for AI Agent Integrations

Composio leads on catalog size. This is a ranked look at the alternatives worth evaluating when the harder problem is authority: which agent, acting for which user, may take which action.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

Building Trust in Autonomous Systems

Trust doesn't come from claiming an agent is safe. It comes from proving it's governed — scoped, watched, recoverable, and owned by someone who can answer for it.

Read the story
Classic painting used as the article cover
FRAMEWORK

Agent Accountability Frameworks

Six named owners on paper is not the same as accountability. What matters is which roles can actually act in the first ten minutes of an incident, and which act afterward.

Read the story
Classic painting used as the article cover
ACCOUNTABILITY

Who Is Responsible for an AI Agent?

Naming a business owner isn't the same as giving them a way to act. The interesting failure is what happens when the accountable person has no switch to pull.

Read the story
Classic painting used as the article cover
COMPLIANCE

Preparing for Agent Compliance Regulations

Regulators will ask what a specific agent did on a specific day, not whether you have a policy. Build the evidence into how agents run now, because it can't be produced after the fact.

Read the story
Classic painting used as the article cover
BEST PRACTICES

Audit Logging Best Practices for AI Agents

Log agent identity, user context, tool calls, and the gate decision on every path a call can take. Tamper-resistant, connected across systems, and actually reviewable.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

What Is an Agent Audit Trail?

A record of what an agent actually did — the action, the tool, the data, the user, the gate decision, and the outcome. Trust requires evidence.

Read the story
Classic painting used as the article cover
AGENT SECURITY

Agent Credentials vs. Human Credentials

Agents aren't human users and shouldn't silently borrow their access. Why an agent credential is a structurally different object, and what a healthier model looks like.

Read the story
Classic painting used as the article cover
SECURITY PATTERNS

Managing Secrets for AI Agents

Secrets don't belong in prompts, configs, or repos. Scoping, separation, traceability, rotation, and revocation for the credentials agents hold.

Read the story
Classic painting used as the article cover
AGENT SECURITY

What Is Agent Credential Management?

The keys, tokens, and secrets agents use to reach enterprise systems, and the operational discipline that keeps them scoped, stored, rotated, and revocable.

Read the story
Classic painting used as the article cover
TECHNICAL GUIDE

Permission Models for Autonomous Systems

Autonomy isn't binary. Reach and initiative are different questions, and the layer most models skip is whether an agent should act on its own or wait.

Read the story
Classic painting used as the article cover
PLAYBOOK

Managing Agent Permissions at Scale

Templates, context-aware exceptions, automated reviews, and usage monitoring — bringing fragmented agent permissions into one governance model.

Read the story
Classic painting used as the article cover
BEST PRACTICES

Agent Permissions Best Practices

Least privilege, action-level scopes, user-aware permissions, approvals for high-risk actions, and reviews — treating permissions as dynamic controls.

Read the story
Classic painting used as the article cover
AUTHORIZATION

Agent Authorization vs. Authentication

Authentication verifies identity; authorization determines access. Why agents need both, and what changes when the actor making the request isn't a person.

Read the story
Classic painting used as the article cover
AUTHORIZATION

Role-Based Access Control for AI Agents

RBAC is a strong foundation for agent permissions, and a specific, predictable way it breaks. What belongs in a role, and what never should.

Read the story
Classic painting used as the article cover
AUTHORIZATION

Agent Authorization Explained

Authorization is not one decision but several, checked in sequence. A plain walkthrough of the layers, the intersection rule, and why the two most common failures sit at opposite extremes.

Read the story
Classic painting used as the article cover
AGENT SECURITY

Agent Offboarding and Decommissioning

The most overlooked part of agent governance: retiring agents cleanly so abandoned agents don't become invisible access paths.

Read the story
Classic painting used as the article cover
PLAYBOOK

Provisioning AI Agents at Scale

Identity, registration, scoped authorization, credentials, and monitoring by default: a repeatable six-stage path to production for hundreds of agents.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

What Is Agent Lifecycle Management?

Managing an agent from proposal through approval, production, change management, and retirement — so agents don't drift out of control.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

Agent Registry vs. Agent Inventory

Inventory and registry aren't rival terms fighting over one meaning. They're sequential records, and one has to feed the other before either is useful.

Read the story
Classic painting used as the article cover
PLAYBOOK

Building an Enterprise Agent Registry

From intake to authorization to periodic review — how to make approved, governed agent deployment a repeatable process.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

What Is an Agent Registry?

The formal system of record for approved agents — the control plane that defines which agents are recognized, governed, and allowed to operate.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

Agent Visibility vs. Agent Governance

A written rule that nobody can verify is being followed isn't governance yet. It's a document. Visibility is what turns it into something real.

Read the story
Classic painting used as the article cover
PLAYBOOK

Achieving Agent Visibility Across the Enterprise

When an agent misbehaves, the useful question isn't what logs exist. It's what to pull up first, in what order, and whether the pieces resolve to one story.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

What Is Agent Visibility?

Seeing where agents operate, what they access, what they do, and how they behave over time — the operational layer beyond a static inventory.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

Agent Inventory vs. CMDB

A CMDB confirms an agent exists. It has no field for what the agent is allowed to do, and that gap is exactly where a security review stalls.

Read the story
Classic painting used as the article cover
PLAYBOOK

Building an Enterprise Agent Inventory

A practical playbook for discovering, normalizing, and owning every agent across AI platforms, SaaS, cloud, and code.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

What Is an Agent Inventory?

A structured system of record for every agent: who owns it, what it can access, what it can do, and whether it's still approved to operate.

Read the story
Classic painting used as the article cover
AGENT SECURITY

The Rise of Shadow Agents

Shadow IT has an AI successor: shadow agents — autonomous systems running with real access but no visibility, ownership, or governance.

Read the story
Classic painting used as the article cover
AGENT DISCOVERY

Why Enterprises Need Agent Discovery

One unregistered vendor-portal agent, walked through end to end, shows exactly where discovery would have shortened an incident from days to hours.

Read the story
Classic painting used as the article cover
AGENT OPERATIONS

What Is Agent Discovery?

Identifying every AI agent operating across your enterprise — internal, third-party, SaaS-embedded, or API-connected — is the first layer of Agent Operations.

Read the story
Winslow Homer painting, Rough Work (1883)
AI GOVERNANCE

AI Governance Has to Move From Policy to Runtime

Why written policy and model approvals can't govern systems that retrieve data, call tools, and take action in real time — and what runtime governance looks like.

Read the story
Abstract editorial illustration
COMPLIANCE

AI Agents and the EU AI Act: From Model Compliance to Runtime Governance

What the EU AI Act means for agentic systems — and why compliance must shift from model selection to runtime governance of what agents actually do.

Read the story
Coastal landscape painting
COMPLIANCE

The Compliance Cost of Uncontrolled AI Agents

How misaligned agents quietly generate real financial risk — and why the true cost is far higher than most companies realize.

Read the story
Vintage marine painting
AGENT SECURITY

The Real Cost of Rogue AI Actions: What Companies Are Seeing

Rogue agent actions are rarely dramatic. They're ordinary systems doing ordinary work with slightly too much reach, and the bill lands in three separate places.

Read the story
Winslow Homer, Pumpkin Patch (1878)
AI SAFETY

The 5 Types of Agent Hallucinations (and Why Permission Hallucination Is the Worst)

Not all hallucinations are equal. The five distinct failure modes of autonomous agents, and why permission hallucination is the one that actually causes incidents.

Read the story
Watercolor landscape painting
AGENT SECURITY

How to Pass Context Safely (Without Leaking Sensitive Data or Executing Hidden Instructions)

How to share context between steps and agents without leaking sensitive data or executing hidden instructions.

Read the story
Inland water, Bermuda watercolor
AI SAFETY

How to Handle Ambiguous User Requests (and Prevent Dangerous Interpretations)

Asking a clarifying question every time an agent is unsure is not safety, it's a tax users stop paying. The judgment that matters is choosing between ask, assume out loud, and refuse.

Read the story
Winslow Homer watercolour of a harbour under sail, used as the article cover
PRIMER

Identity for AI Agents: A Technical Primer

A technical primer on identity for AI agents — what it means, why traditional IAM falls short, and how to build per-agent identity, scopes, MCP/OAuth integration, audit, and revocation.

Read the story
Winslow Homer watercolour of a boy waiting beside a beached dory, used as the article cover
DEEP DIVE

MCP, OAuth, and the Agent Permissioning Problem

MCP standardizes how agents call tools. OAuth standardizes how apps get tokens. Neither decides whether a specific agent should take a specific action for a specific user right now.

Read the story
Landscape painting of cattle grazing in an open valley, used as the article cover
PRODUCTION

Why AI Agents Need Permissioning, Audit Logs, and Revocation

The three controls that separate AI agent demos from AI agent deployments: per-action permissioning, immutable audit logs, and immediate revocation. Why each is non-negotiable.

Read the story
Impressionist landscape painting
ENGINEERING

How to Build Agent Memory Without Letting It Drift or Corrupt Itself

A practical engineering guide for preventing hallucinations, contradiction, and self-reinforcing errors in agent memory systems.

Read the story
Watercolor seascape
ENGINEERING

How to Add Confidence Scores to Agent Outputs (So They Know When They Don't Know)

Most agents can't tell you when they don't know. How to add calibrated confidence scores so agents can defer, escalate, or ask.

Read the story
Watercolor marine scene
TECHNICAL GUIDE

Integrating Confidence Scores Into Real Agent Frameworks (LangChain, LangGraph, AutoGen, Instructor)

Wiring confidence scores into LangChain, LangGraph, AutoGen, and Instructor — without rebuilding your stack.

Read the story
Pastoral landscape painting
OBSERVABILITY

Building Agents with Observability: Metrics, Traces, Logs & Semantic Telemetry for LLM Workflows

Treat agents like distributed systems: the metrics, traces, logs, and semantic telemetry you need to debug LLM workflows in production.

Read the story
Summer landscape painting
PERFORMANCE

How to Optimize Agent Cost and Latency—Without Breaking Behavior

The engineering patterns that cut agent cost and latency without breaking behavior — model routing, lazy evaluation, caching, and context trimming — and where each one quietly goes wrong.

Read the story
Watercolor coastal scene
TECHNICAL GUIDE

Optimizing Agent Cost & Latency in Practice (LangChain, LangGraph, AutoGen Versions)

The fast-planner, lazy-retrieval, slow-executor pattern implemented end to end in LangChain, LangGraph, and AutoGen, plus how to measure whether it's actually working.

Read the story
Adirondacks landscape by Winslow Homer
TECHNICAL GUIDE

A Field Guide to Planning Algorithms for Agents

CoT, ToT, GoT, ReAct, PAL, and multi-stage planners — compared, stress-tested, and implemented.

Read the story
Rowboat realism marine painting
ENGINEERING

A Developer's Guide to Thinking in Agents, Not Apps

An app is safe to get wrong because a human reviews the output before anything happens. An agent removes that review by design — here's what that costs, concretely.

Read the story
Mount Washington landscape painting
DESIGN

How to Design a Great AI Persona: A Step-by-Step Guide

From psychology to prompts: how to engineer an AI persona users trust and your system can actually implement.

Read the story
Winslow Homer, The Blue Boy
DESIGN

The Big Five Personality Types — For AI Agents

Why your agent already has a personality, how to tune it, and what each of the Big Five traits really means.

Read the story
Winslow Homer, Boys in a Dory (1880)
USER EXPERIENCE

The New Digital Etiquette: How Humans Should Interact With AI Agents

A user's guide to clarity, boundaries, and avoiding weird misunderstandings with your digital coworkers.

Read the story
Abstract artistic composition
IMPLEMENTATION

Multi-Agent Patterns as Workflow Loops

The multi-agent patterns everyone diagrams (two-agent loops, group chat, manager-worker, hierarchies) all reduce to the same node-and-edge graph. What actually decides whether one runs safely is the termination logic, not the shape.

Read the story
Mediterranean watercolor painting with orange trees
ARCHITECTURE

From One Agent Runtime to Many: What Actually Needs to Stay Centralized

Decentralizing your agent stack isn't an all-or-nothing move. Execution should be allowed to fragment across teams; connectivity and identity shouldn't, and conflating the two is where these architectures go wrong.

Read the story
Tropical watercolor landscape
ARCHITECTURE

Agent Design Patterns: Which Ones Are Actually Worth Building

A working catalogue of single- and multi-agent design patterns, with an opinion attached to each one: what it buys you, what it costs, and whether a team shipping this quarter should reach for it.

Read the story
Tropical watercolor painting
NO-CODE

No-Code Agent Builders: What the Abstraction Buys You, and Where It Breaks

Visual and low-code agent builders trade control for speed on the common path. That trade holds for simple workflows and standard connectors, and comes apart exactly where multi-agent loops and custom logic start.

Read the story
Northeaster by Winslow Homer
AI SAFETY

The Dark Side of AI Personality: Traits You Should Never Give an Agent

Some personalities empower users. Others quietly manipulate, destabilize, or harm them.

Read the story
Boys and Kitten by Winslow Homer
USER EXPERIENCE

Why AI Agents Need Personality

And why \"a little charm\" makes automation more reliable, trustworthy, and usable.

Read the story
Winslow Homer painting of sailors in a boat on windy seas
FEATURED REPORT

The Hidden Risk of \"Hallucinated Permissions\" in AI Agents

Explore how autonomous agents invent access they never received, why legacy IAM cannot contain fabricated authority, and the guardrails enterprises need now.

Read the story
The Problem of Passing Context Between Agents
AGENT SECURITY

The Problem of Passing Context Between Agents (And Why It's So Dangerous)

Why context that's clean, correctly trusted, and honestly labeled at every hop can still combine into something no single agent was authorized to reveal.

Read the story
Winslow Homer painting of a ship navigating stormy seas
AGENT SECURITY

Why OAuth Alone Isn't Enough for AI Agents

OAuth checks whether a token is valid, not whether the action behind it is a good idea. That gap is where autonomous agents cause real damage.

Read the story
Painting of a ship sailing across blue seas
TOKEN LIFECYCLE

Token Refresh 101: How OAuth Refresh Tokens Actually Work

Why refresh tokens exist, how rotation protects your users, and what an invalid_grant error is actually telling you when it shows up in production.

Read the story
Watercolor of a child on a swing framed by trees
SECURITY PATTERNS

How to Store OAuth Tokens Securely (Without Leaking Secrets)

Token storage patterns for backends, browser apps, and native clients, plus the difference between deleting your copy of a token and actually revoking it.

Read the story
Vintage illustration of sailors navigating rough waters
INTEGRATION GUIDE

How Slack's OAuth Flow Works (and How to Call Their API With Python)

Understand Slack's authorization code flow from redirect to token exchange, then ship your first Web API call with the Python SDK.

Read the story