vladimir_gor
3 hours ago
Really interesting direction. What resonated with me is that you're treating agent security as an information-flow problem rather than a prompt-classification problem. It was not so obvious to me.
A key question I agree isn't just "is this tool call allowed?", but "given everything the agent has read so far, is this information now allowed to flow to this destination?" That feels like a much more fundamental abstraction.
The part I'm particularly curious about is how this will work with policy authoring at scale. What would be the main adoption challenge?
arseny_info
3 hours ago
great question, very practical.
we have a layered answer here: 1) we ship over a dozen "batteries" now (and plan to grow the number) - they contain base annotations for popular services and helper scripts where relevant; 2) we also ship a skill helping you write your own policies for custom services or adopt the default ones based on your specific needs. The criteria "what's acceptable for each particular scenario" varies, there is no "one size fits all" solution; 3) finally, there is a designed placeholder to cover the rest via wildcard AI annotator if needed. The difference between that and regular "auto mode" in coding agents is that APPA's annotator emits local label (e.g. "does this call require a trusted env?"), not wide allow/block, while decision making stays within label algebra.