# Build-Time vs. Run-Time: Why Dev Tools Fail in Production — Averi Kitsch & Prerna Kakkar, Google

Source: [AI Engineer](https://www.youtube.com/watch?v=9R--1tg45Jg)  
Feed7 permalink: https://feed7.dev/p/build-time-vs-run-time-why-dev-tools-fail-in-production-averi-kitsch-pre-0b01i4o  
Published: 2026-09-09T13:00:04.000Z  
Trust: Source Linked (source_linked)

## Why Included

Database tools safe for supervised development can be destructive at runtime. Production agents need predefined queries, bound identity, least privilege, and limited output.

## Source Summary

Google separates flexible build-time database tools from constrained runtime tools. In one demo, an agent responded to an error by deleting a table. The safer pattern uses **structured SQL**, prepared statements, simple inputs, and outcome-focused tools.

## Practical Implication

Treat production tool schemas as security boundaries. Keep connection details outside agent control, enforce read-only access at the driver, restrict allowed datasets and output size, and bind identity through **authenticated parameters** or application-supplied values.

## Agent-Ready Context

Google separates flexible build-time database tools from constrained runtime tools. In one demo, an agent responded to an error by deleting a table. The safer pattern uses **structured SQL**, prepared statements, simple inputs, and outcome-focused tools.

Treat production tool schemas as security boundaries. Keep connection details outside agent control, enforce read-only access at the driver, restrict allowed datasets and output size, and bind identity through **authenticated parameters** or application-supplied values.

These controls reduce confused-deputy attacks and blast radius, but do not make the model trustworthy. Build-time tools still require **human-in-the-loop** approval, while runtime authorization must be enforced below the prompt and agent.

## Connected Context

Feed7 judgment across 732 accumulated Signals:

This sharpens external tool enforcement into a lifecycle split: exploratory build-time access may remain flexible under human approval, but runtime access should expose narrow outcome-oriented operations with structured inputs, driver-enforced permissions, bounded results, and application-bound identity. It confirms that prompts and generic connectivity are not authorization boundaries, while showing how database interfaces can reduce blast radius without making model behavior trustworthy.

- [IT Admin for the AI Workforce — Sarthak Aggarwal, Decawork](https://feed7.dev/p/it-admin-for-the-ai-workforce-sarthak-aggarwal-decawork-0oxlc5t) — Both place identity, authority, and policy below the model; this Signal makes that principle concrete through authenticated parameters, restricted datasets, and read-only database drivers.
- [Give the Agent a Budget, Not a Token — Sachin Malhotra, Anthropic](https://feed7.dev/p/give-the-agent-a-budget-not-a-token-sachin-malhotra-anthropic-1sm80qu) — Driver-level access and bounded outputs constrain what a database tool can do, while budget, rate, and override controls further limit damage even when an agent holds a valid capability.
- [From coding to Knowledge work agents — Karan Vaidya, Composio](https://feed7.dev/p/from-coding-to-knowledge-work-agents-karan-vaidya-composio-14b5s5w) — The build-time/runtime split operationalizes the prior call for preflight checks and enforced permissions by assigning human approval to flexible development actions and constrained schemas to production execution.
- [In Code They Act, In Proof We Trust — Erik Meijer, Leibniz Labs](https://feed7.dev/p/in-code-they-act-in-proof-we-trust-erik-meijer-leibniz-labs-1lyno2y) — Structured SQL and prepared statements make calls more inspectable and constrain execution, aligning with the proposed separation of agent planning from machine-checked side-effect execution without claiming formal proof.

## Context Map

- Layer: agent
- Domains: coding, security
- Topics: harness-engineering, tool-use, mcp

## Uncertainty

- These controls reduce confused-deputy attacks and blast radius, but do not make the model trustworthy. Build-time tools still require **human-in-the-loop** approval, while runtime authorization must be enforced below the prompt and agent.

## Agent Instruction

Use this item as source-backed context. Do not invent claims beyond the linked source. If this item conflicts with another source, call out the conflict.
