Elytra AI Native

An agent shouldn't sign with a partner's name.

A few weeks ago an AI agent merged a change into the branch that deploys our website to production. Our own rule said no agent should be able to do that. The system recorded no violation: as far as the repository knew, one of the partners had merged the change.

The agent didn't get around anything. It was working with a partner's personal credential, and it carried out an ambiguous instruction with permissions it should never have had.

The review turned up three things. The branch was protected, but the protection checks the role, and the partner owned the project. The sign-off we took for granted before every merge was never a technical control, only an agreement between us. And the history had stopped being useful: changes from two agents and one person all showed the same author.

We decided every agent gets its own identity, with a role that lets it propose changes but not merge them. We tested it by authenticating as the agent, not by reading the documentation: creating a branch and proposing a change works; merging to production is refused.

The cost is that every change an agent makes now waits for a person to close it. And since our plan doesn't offer required approvals, the only real control is that the agent never reaches a role that can merge.

Elytra intelligent process redesign
Mexico
Registered office
Calle 18B # 251
Mérida, Yucatán
CP 97305
+52 246 208 6256
Colombia
Office
Cúcuta, Norte de Santander
CP 540003
+57 333 758 3244
Canada
Office
Montréal, Québec
H3C 0B4
+1 438 300 9091
Venezuela
Coming soon