PLATFORM / Shadow AI

The AI agent firewall

Make Fabriq the only path to your tools — unauthorized agents never get in, because there’s nothing for them to connect to.

Get a demoExplore the workflow ↓
01 / IDENTITY02 / POLICY03 / AUDIT
FABRIQ / RIPPLEIDENTITY · PERMISSIONS · VISIBILITY
Know what is acting on your behalf.FABRIQ / AUDIT
01 / THE CONTEXT

If it is not registered,
it has no way in.

Employees adopt agents faster than security can review them — and every one connects to company data.

AT THE GATEWAYIllustrative agents
  • support-triageSlackZendeskroutes throughregistered · owner: Support · scoped per user
  • research-agentGoogle DriveNotionroutes throughregistered · owner: Research · scoped per user
  • release-agentGitHubJiraroutes throughregistered · owner: Platform · scoped per user
  • browser extension agentno routeunregistered · no owner, no scopes
  • personal automation scriptno routeunregistered · no credential it can use

Registered agents get a scoped route. Anything else has nothing to authenticate with, so there is no call to catch.

02 / IN PRACTICE

Know what is acting on your behalf.

ONE PATH IN · THREE WAYS OUTIllustrative calls · every one arriving at the same gateway
A CALL ARRIVESAn agent asks for a toolon behalf of an employee, at the only endpoint your tools answer
Is the agent registered?no →yes ↓
Is it scoped for this person and this action?no →yes ↓
Does the action need a named approver?yes →no ↓
EVERY CHECK PASSEDStart an approved agentresearch-agent, owned by Research, running for the employee who asked — with a vault-held credential and a line in the audit trail.Allowed
Start an unapproved agentpersonal-automation.py · started on a laptopNo route

Nothing is registered under that name, so there is no credential it can use and no endpoint that answers it. Nothing to detect, because nothing connects.

Google DriveReach a tool it was never givensupport-triage · drive.readRefused

A registered agent still only reaches what it was scoped to, for the person it is acting for. Refused at the gateway and written to the trail.

Approve a new agentmarketing-digest · awaiting registrationHeld

A named human approver has to say yes first. Until someone does, the agent has no route — which is why approval is built to take minutes.

Illustrative · the path is the same whichever agent knocks.

03 / WHAT CHANGES

Control, in the details.

01

Make Fabriq the only path in.

When tool credentials live only in Fabriq’s vault, unregistered agents have nothing to authenticate with.

02

Prevention, not detection.

No hunting rogue agents: no key, no route, no way in.

03

An approved-agent registry.

Only registered, owned, scoped agents route through — approval takes minutes.

04

One audit trail for everything that runs.

Every sanctioned call is attributed, policy-checked, and logged.

05

A fast yes for new tools.

Governance easier than the workaround, so nobody routes around you.

06

Least privilege for what you approve.

Registered agents get scoped grants, per user and per action — not blanket access.

AGENT REGISTRY

An approved agent has a way in.

crm-bot-01 direct access
mail-agent-02 direct access
👻 unknown-bot calls your CRM
👻 zap-agent forwards mail
AGENTIC FABRIQ
the only path to your tools
CRM
Gmail
Slack
THREE LAYERS. ONE DECISION.

The boundary travels with the work.

Explore the context attached to every request.

What is this agent allowed to do?

approved-agent has a defined purpose and a bounded set of tools.

QUESTIONS

A closer look.

How is this different from DLP or CASB?+

Those detect and chase. Centralize your tool credentials in Fabriq and there’s nothing to detect — unauthorized calls simply fail.

Won’t people just work around it?+

Only if approval is slow — registering an agent takes minutes, so the sanctioned path stays the easy path.

Will this block the tools employees like?+

The goal is the opposite: registering an agent takes minutes, so the approved path stays faster than the workaround — people stop routing around you.

What if someone connects an unauthorized agent?+

It has no managed identity, no brokered route, and no key your systems accept. Its calls fail, and no data moves.

Do we have to move every credential at once?+

No — start with the systems that matter most. Every credential you centralize closes that door for good, and coverage grows tool by tool.

YOUR NEXT CHAPTER

Give your agents
room to move.

See Fabriq in action
Integration HubInternal AgentsCoding Agents