{
  "schema_version": "1.1",
  "id": "archive:https://www.youtube.com/watch?v=rbjWzZK2LU0",
  "slug": "give-the-agent-a-budget-not-a-token-sachin-malhotra-anthropic-1sm80qu",
  "url": "https://feed7.dev/p/give-the-agent-a-budget-not-a-token-sachin-malhotra-anthropic-1sm80qu",
  "title": "Give the Agent a Budget, Not a Token — Sachin Malhotra, Anthropic",
  "why_included": "Production agents need bounded write authority, infrastructure-stamped identity, and human-only overrides; a broad token and tool list cannot control blast radius.",
  "summary": "A cleanup agent’s empty pipeline stage removed its filter, matching and deleting about **200 workloads** used by **20 engineers** in **90 seconds**. The proposed alternative treats authority as budgets across action volume, rate, reversibility, and visibility.",
  "practical_implication": "Classify write verbs by how failures surface, rate-limit every write, and keep overrides outside agent sessions. Record aggregate behavior with trip wires, size limits using an undo test, and let a trusted proxy stamp agent and session identity.",
  "agent_context": "A cleanup agent’s empty pipeline stage removed its filter, matching and deleting about **200 workloads** used by **20 engineers** in **90 seconds**. The proposed alternative treats authority as budgets across action volume, rate, reversibility, and visibility.\n\nClassify write verbs by how failures surface, rate-limit every write, and keep overrides outside agent sessions. Record aggregate behavior with trip wires, size limits using an undo test, and let a trusted proxy stamp agent and session identity.\n\nThese are production safety primitives, not a guarantee against bad actions. Limits still need tuning by resource and namespace, while quiet or irreversible operations may require a separate human-held credential.",
  "source": {
    "name": "AI Engineer",
    "url": "https://www.youtube.com/watch?v=rbjWzZK2LU0",
    "published_at": "2026-08-22T14:00:06.000Z"
  },
  "source_class": "video",
  "content_type": "Video",
  "layer": "agent",
  "domains": [
    "coding",
    "security"
  ],
  "topics": [
    "harness-engineering",
    "tool-use",
    "sandboxing"
  ],
  "verification": {
    "status": "source_linked",
    "label": "Source Linked",
    "method": "source_feed",
    "verified_at": null
  },
  "uncertainty": [
    "These are production safety primitives, not a guarantee against bad actions. Limits still need tuning by resource and namespace, while quiet or irreversible operations may require a separate human-held credential."
  ],
  "connected_context": {
    "meaning": "This sharpens least privilege into quantitative, runtime authority limits: an agent may hold a valid write capability yet still be prevented from acting too broadly, too quickly, or irreversibly. The deletion incident supplies concrete production evidence for external identity, rate limits, trip wires, and human-held overrides, while leaving resource-specific tuning and quiet destructive actions unresolved.",
    "corpus_size": 545,
    "generated_at": "2026-08-23T18:04:57.010Z",
    "connections": [
      {
        "title": "IT Admin for the AI Workforce — Sarthak Aggarwal, Decawork",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=q-WOjZhOMCA",
        "feed7_url": "https://feed7.dev/p/it-admin-for-the-ai-workforce-sarthak-aggarwal-decawork-0oxlc5t",
        "reason": "Decawork establishes external identity and policy enforcement as security boundaries; this signal specifies budgets, trusted identity stamping, and trip wires that those boundaries can enforce."
      },
      {
        "title": "Project-scoped Tokens",
        "source_name": "Vercel",
        "source_url": "https://vercel.com/changelog/project-scoped-tokens",
        "feed7_url": "https://feed7.dev/p/project-scoped-tokens-1emgc6h",
        "reason": "Project-scoped credentials reduce where an agent can act, while action-volume, rate, and reversibility budgets further constrain what it can do inside that project."
      },
      {
        "title": "Gemini API Managed Agents: 3.6 Flash, hooks, and more",
        "source_name": "Google",
        "source_url": "https://blog.google/innovation-and-ai/technology/developers-tools/expanding-managed-agents-gemini-api-3-6-flash-hooks/",
        "feed7_url": "https://feed7.dev/p/expanding-managed-agents-gemini-api-3-6-flash-hooks-0xce1pm",
        "reason": "Gemini’s token caps bound model loops, whereas this signal shows that production safety also requires limits on side effects, aggregate writes, and reversibility."
      }
    ]
  },
  "lifecycle": "Current",
  "published_at": "2026-08-22T14:00:06.000Z",
  "modified_at": "2026-08-22T14:00:06.000Z",
  "supersedes": [],
  "expires_at": null,
  "formats": {
    "html": "https://feed7.dev/p/give-the-agent-a-budget-not-a-token-sachin-malhotra-anthropic-1sm80qu",
    "json": "https://feed7.dev/p/give-the-agent-a-budget-not-a-token-sachin-malhotra-anthropic-1sm80qu.json",
    "markdown": "https://feed7.dev/p/give-the-agent-a-budget-not-a-token-sachin-malhotra-anthropic-1sm80qu.md"
  }
}