Inspiration

Security - that's the big question of today's various agentic AI solutions. In a world increasingly reliant (and thus potentially vulnerable) of AI agents, a great amount of care must be put into their ability to access, modify, and utilize resources that they interact with. This is why I picked to implement the Identity & Authorization middleware - a clear, robust system to clearly restrict agents' abilities to access their own workspaces in a multi-user environment not only provides the greatest value in Agent Launchpad, it is perhaps the most crucial middleware required in bringing the Launchpad one step closer to a true, production-friendly application.

What it does

My middleware implements user-based authentication and user-based agent ownership. This means every agent is owned by only one user and executes under strict, verifiable delegated authority:

  1. Multi-Tenant Identity & RBAC: Supports distinct user personas (Admin, Developer, and read-only Auditor) with secure JWT sessions and complete resource isolation.
  2. Workspace Isolation: Enforces physical and directory-level sandboxing (/workspaces/<userId>/<agentId>), neutralizing directory traversal attacks (../) and cross-tenant leakage.
  3. 3-State Granular Delegated Permissions: Gives operators granular control over 4 core permission scopes (fs:read, fs:write, cmd:safe, cmd:privileged) across three configurable modes:
    • OFF: Strictly blocks the action and automatically reverts unauthorized file writes.
    • REQUIRE_APPROVAL: Triggers a real-time Human-in-the-Loop (HITL) gate for operator review.
    • ON: Permits automated execution within safe boundaries.
  4. Human-in-the-Loop (HITL) Interception: Intercepts high-risk operations (e.g., chmod, privilege escalation, destructive commands, file modifications), pausing execution until approved or rejected via the UI.
  5. Immutable Attribution & Audit Logging: Records an immutable audit log of all security evaluations, approvals, and executions with automated redaction of sensitive credentials (API keys, tokens, passwords).

How I built it

Modifications and extensions to the existing TypeScript backend and React frontend:

  • Fastify & JWT Auth Middleware: Added session-based authentication hooks, role verification, and scoped endpoint guards.
  • Policy Engine (policy-engine.ts): Built a deterministic policy engine that parses prompt intents, evaluates delegated grants, inspects shell binaries, and flags dangerous commands.
  • Agent Principal & Approval Services (agent-principal-service.ts, approval-service.ts): Created an asynchronous lifecycle manager for principal rotation, delegated grants, and non-blocking HITL approval promises.
  • Pre/Post-Execution File Integrity System (workspace.ts): Designed automated workspace diffing and snapshots to verify write scopes and revert unauthorized file modifications on the fly.
  • Interactive UI Components: Added real-time Approval bars, granular Agent Settings modals with 3-state permission toggles, multi-persona quick logins, and searchable Audit Log viewers with agent-level and tenant-wide filtering.

Challenges we ran into

  • Robust Model Action Extraction: Large Language Models output commands in varying formats (fenced code blocks, natural language, JSON, or inline shell backticks). Designing a resilient parser (extractModelApprovalRequests) that accurately extracts dangerous commands without false positives was challenging.
  • Asynchronous Human-in-the-Loop Orchestration: Pausing the Codex runner mid-lifecycle while awaiting human input in the browser, handling timeouts, and gracefully resuming execution with structured follow-up interpretations.
  • Post-Execution File Verification: Ensuring that when an agent attempts file edits with fs:write disabled or rejected, the system cleanly identifies and reverts all changed files without corrupting workspace state.

Accomplishments that we're proud of

  • True Defense-in-Depth: Combining proactive prompt steering (AGENTS.md permission injection), in-flight command interception, and post-flight file snapshot validation.
  • Seamless Persona Experience: Effortless switching between an Admin overseeing tenant health, a Developer managing their own agents, and a compliance Auditor reviewing immutable logs without write privileges.
  • Non-Intrusive HITL Experience: The real-time approval bar fits naturally into the conversation stream, allowing human oversight without breaking the agentic workflow.

What we learned

  • AI agent security cannot rely solely on prompt engineering or system instructions; deterministic code-level middleware and file-level integrity checks are still crucial.
  • A 3-state permission model (Off, Require Approval, On) offers somewhat of a balance between productivity and safety.
  • Clear audit trails are highly critical for building confidence in autonomous AI agents, especially for debugging and security purposes.

What's next for Identity and Authorization (Agent Launchpad)

  • Time-Bound Grants: Auto-expiring grants that automatically downgrade privileged permissions after a set duration.
  • Resource-Specific Access Control Lists (ACLs): Scoping file access down to specific subdirectories or file patterns (e.g., src/* vs .env).

Built With

Share this project:

Updates

Submission history