Vibeleaderboard
← All Intel
Intel / video

How Many Credentials Should Your AI Agent Have? Zero. — Jim Clark, Docker

Source
youtube.com
Author
AI Engineer
Date
Why it matters

Gives a pattern for limiting what agents can touch: split workflows into sandboxes that never mix untrusted input with dangerous tools, and route tools through one gateway. Credentials are issued only when needed.

Key takeaways · AI-distilled
  • Clark argues that an is a simple loop, so safety comes from controlling which and tools flow into it. That makes the , not the harness, the boundary to manage.
  • His newsroom example splits one workflow into separate researcher, fact-checker and publisher sandboxes, and his coding- example grants signing keys only while the agent is committing.
  • Giving each sandbox a single MCP gateway endpoint creates one control point for tools, resources and prompts, and Clark says it also makes harnesses interchangeable.
  • Cross App Access (XAA) with Okta ties agent identity and authorization grants to an organization's existing SSO, which supports Clark's position that the right number of credentials stored in a sandbox is zero.
Terms in this piece · Glossary
  • agent harness — The scaffolding around a model that turns it into a working agent — the loop, the tools it can call, and the rules for when to stop.
  • context window — The maximum amount of text a model can consider at once — its working memory for the current conversation or task.
  • sandbox — An isolated environment where AI-generated code or agent actions run without being able to touch anything real.
  • AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
Read the source www.youtube.com
More from AI Engineer
Recommended reads
Comments

Checking sign-in…

Loading comments…