Genuine question, not a hypothetical. The domain-specific servers give an agent focused tools over a real account; the code-mode server gives it broad API coverage. Either way, when an agent asks for something ten times larger than usual, say a DNS change on the production zone or a deploy to every Worker, what stops it today: the API token's scope, a prompt, or noticing afterwards?
I am building mnki, an open-source trust layer with a fourth answer: bounded authority checked outside the model before the call runs (this agent, for this principal, these zones, these operations, until this date), a human approval on a phone for the cases that deserve one, and a signed record of every decision. It runs on Workers itself and sits in front of an MCP server as a proxy or gateway, so it works with yours unchanged.
Twenty minutes to hear how you think about per-agent limits above token scopes would help me; a reply here is fine too. Reference implementation, Apache-2.0: https://github.com/MNKIAgentOS/agent-trust; integration paths: https://mnki.com/docs/integrations. Thank you for splitting the servers by domain; the smaller surfaces are the ones enterprises can reason about.
Genuine question, not a hypothetical. The domain-specific servers give an agent focused tools over a real account; the code-mode server gives it broad API coverage. Either way, when an agent asks for something ten times larger than usual, say a DNS change on the production zone or a deploy to every Worker, what stops it today: the API token's scope, a prompt, or noticing afterwards?
I am building mnki, an open-source trust layer with a fourth answer: bounded authority checked outside the model before the call runs (this agent, for this principal, these zones, these operations, until this date), a human approval on a phone for the cases that deserve one, and a signed record of every decision. It runs on Workers itself and sits in front of an MCP server as a proxy or gateway, so it works with yours unchanged.
Twenty minutes to hear how you think about per-agent limits above token scopes would help me; a reply here is fine too. Reference implementation, Apache-2.0: https://github.com/MNKIAgentOS/agent-trust; integration paths: https://mnki.com/docs/integrations. Thank you for splitting the servers by domain; the smaller surfaces are the ones enterprises can reason about.