AMELFI

An illustrated field guide Nº 1

What happens when every agent
gets its own door?

you lose the building.

Field notes on the agent-to-tool boundary — and the case for one governed gateway between your agents and your private tools.

The pitch, drawn by hand · four minutes
agents, everywhere one governed door → not approved? bounced. fig. 0 — the whole idea
Fig. 1

The sprawl you already have

MCP is becoming the default way agents reach tools. So every team builds its own server — its own auth, its own tool list, its own credential handling, its own audit story. Or none.

Security can't approve that pattern at scale. Not because MCP is risky, but because thirteen half-built copies of the same boundary are.

every box = a security review nobody did

who owns this? ? ? many boundaries, zero reviews
Fig. 2

Tools you can't see can't be called

Most systems deny a forbidden call after the agent finds the tool. The gateway treats discovery itself as authorization: an agent's tool list contains only what policy allows it to call.

Everything else isn't greyed out. It simply isn't there — powered by default-deny Cedar policy, where an explicit deny always wins.

hidden ≠ denied later. hidden = never offered.

what the agent sees these exist. it will never know.
Fig. 3

The agent never holds the key

Credentials stay behind a broker. At call time the gateway resolves the right mode — service account, user-delegated OAuth, agent-scoped, or workload-mapped — and hands the agent an opaque reference.

Secret material never appears in prompts, logs, traces, or audit events. There is no credential for an agent to leak — and nothing for a prompt injection to steal from the agent's context.

agents carry a claim ticket, not the key

secrets stay here useless if stolen the broker, roughly
Fig. 4

Every decision, written down

Allow or deny, every decision lands in a metadata-only audit trail: who, what, when, why, and which policy version decided. Searchable, exportable to your SIEM — payloads and secrets never recorded.

When something goes wrong, you don't grep thirteen servers. You revoke the tool, credential, agent, or session — and the ledger shows exactly what the blast radius was.

  • Stable machine reasons for every deny
  • Emergency disable with blast-radius preview
  • Revocation that reaches live sessions
deny reason: on the record the ledger never sleeps
Fig. 5

Runs in your basement, not ours

Helm chart into your Kubernetes. Your PostgreSQL, your Valkey, your identity provider, your secret manager, your telemetry. In fully self-hosted mode there is no required vendor egress at runtime — the governed path works with the internet unplugged.

Rust data plane, Cedar authorization, signed artifacts with SBOMs. Boring on purpose, everywhere an operator has to trust it.

your infra. your keys. our gate.

optional. self-hosted means self-hosted

Bring us one boundary. We'll govern it together.

The pilot: 4–6 weeks, your infrastructure, one real MCP server or internal API. One allowed call, one denied call, one revocation — proven end to end with your security team watching.

We reply to every postcard — early design partners shape the roadmap.

Postcard received.

We'll write back to schedule a walkthrough and scope your pilot boundary.