Inspiration
Security - that's the big question of today's various agentic AI solutions. In a world increasingly reliant (and thus potentially vulnerable) of AI agents, a great amount of care must be put into their ability to access, modify, and utilize resources that they interact with. This is why I picked to implement the Identity & Authorization middleware - a clear, robust system to clearly restrict agents' abilities to access their own workspaces in a multi-user environment not only provides the greatest value in Agent Launchpad, it is perhaps the most crucial middleware required in bringing the Launchpad one step closer to a true, production-friendly application.
What it does
My middleware implements user-based authentication and user-based agent ownership. This means every agent is owned by only one user and executes under strict, verifiable delegated authority:
- Multi-Tenant Identity & RBAC: Supports distinct user personas (
Admin,Developer, and read-onlyAuditor) with secure JWT sessions and complete resource isolation. - Workspace Isolation: Enforces physical and directory-level sandboxing (
/workspaces/<userId>/<agentId>), neutralizing directory traversal attacks (../) and cross-tenant leakage. - 3-State Granular Delegated Permissions: Gives operators granular control over 4 core permission scopes (
fs:read,fs:write,cmd:safe,cmd:privileged) across three configurable modes:OFF: Strictly blocks the action and automatically reverts unauthorized file writes.REQUIRE_APPROVAL: Triggers a real-time Human-in-the-Loop (HITL) gate for operator review.ON: Permits automated execution within safe boundaries.
- Human-in-the-Loop (HITL) Interception: Intercepts high-risk operations (e.g.,
chmod, privilege escalation, destructive commands, file modifications), pausing execution until approved or rejected via the UI. - Immutable Attribution & Audit Logging: Records an immutable audit log of all security evaluations, approvals, and executions with automated redaction of sensitive credentials (API keys, tokens, passwords).
How I built it
Modifications and extensions to the existing TypeScript backend and React frontend:
- Fastify & JWT Auth Middleware: Added session-based authentication hooks, role verification, and scoped endpoint guards.
- Policy Engine (
policy-engine.ts): Built a deterministic policy engine that parses prompt intents, evaluates delegated grants, inspects shell binaries, and flags dangerous commands. - Agent Principal & Approval Services (
agent-principal-service.ts,approval-service.ts): Created an asynchronous lifecycle manager for principal rotation, delegated grants, and non-blocking HITL approval promises. - Pre/Post-Execution File Integrity System (
workspace.ts): Designed automated workspace diffing and snapshots to verify write scopes and revert unauthorized file modifications on the fly. - Interactive UI Components: Added real-time Approval bars, granular Agent Settings modals with 3-state permission toggles, multi-persona quick logins, and searchable Audit Log viewers with agent-level and tenant-wide filtering.
Challenges we ran into
- Robust Model Action Extraction: Large Language Models output commands in varying formats (fenced code blocks, natural language, JSON, or inline shell backticks). Designing a resilient parser (
extractModelApprovalRequests) that accurately extracts dangerous commands without false positives was challenging. - Asynchronous Human-in-the-Loop Orchestration: Pausing the Codex runner mid-lifecycle while awaiting human input in the browser, handling timeouts, and gracefully resuming execution with structured follow-up interpretations.
- Post-Execution File Verification: Ensuring that when an agent attempts file edits with
fs:writedisabled or rejected, the system cleanly identifies and reverts all changed files without corrupting workspace state.
Accomplishments that we're proud of
- True Defense-in-Depth: Combining proactive prompt steering (
AGENTS.mdpermission injection), in-flight command interception, and post-flight file snapshot validation. - Seamless Persona Experience: Effortless switching between an Admin overseeing tenant health, a Developer managing their own agents, and a compliance Auditor reviewing immutable logs without write privileges.
- Non-Intrusive HITL Experience: The real-time approval bar fits naturally into the conversation stream, allowing human oversight without breaking the agentic workflow.
What we learned
- AI agent security cannot rely solely on prompt engineering or system instructions; deterministic code-level middleware and file-level integrity checks are still crucial.
- A 3-state permission model (
Off,Require Approval,On) offers somewhat of a balance between productivity and safety. - Clear audit trails are highly critical for building confidence in autonomous AI agents, especially for debugging and security purposes.
What's next for Identity and Authorization (Agent Launchpad)
- Time-Bound Grants: Auto-expiring grants that automatically downgrade privileged permissions after a set duration.
- Resource-Specific Access Control Lists (ACLs): Scoping file access down to specific subdirectories or file patterns (e.g.,
src/*vs.env).
Built With
- deepseek
- fastify
- typescript
Log in or sign up for Devpost to join the conversation.