{
  "schema_version": "1.1",
  "id": "s8:https://www.youtube.com/watch?v=wCIYViPd4SU",
  "slug": "tethered-our-agents-are-us-shu-fang-two-sigma-0c8u33i",
  "url": "https://feed7.dev/p/tethered-our-agents-are-us-shu-fang-two-sigma-0c8u33i",
  "title": "Tethered: Our Agents Are Us — Shu Fang, Two Sigma",
  "why_included": "Two Sigma runs remote agents under each employee’s real identity, adding trace propagation and controlled web access to preserve attribution and limit egress risk.",
  "summary": "At Two Sigma, **every employee** has provisioned cloud-agent infrastructure, and agents run with the employee’s identity rather than a separate service account. A propagated trace ID distinguishes agent activity and preserves the action chain while permissions remain tied to the user.",
  "practical_implication": "Builders deploying agents inside companies should reuse identity, namespaces, network controls, and tracing already present in the platform. Two Sigma routes search and fetch through **Web Grounding for Enterprise** inside its network boundary instead of giving agents unrestricted outbound access.",
  "agent_context": "At Two Sigma, **every employee** has provisioned cloud-agent infrastructure, and agents run with the employee’s identity rather than a separate service account. A propagated trace ID distinguishes agent activity and preserves the action chain while permissions remain tied to the user.\n\nBuilders deploying agents inside companies should reuse identity, namespaces, network controls, and tracing already present in the platform. Two Sigma routes search and fetch through **Web Grounding for Enterprise** inside its network boundary instead of giving agents unrestricted outbound access.\n\nThat index trades freshness for control: the talk reports data within **24 hours**, or **6 hours** for frequently updated sites. Curated retrieval reduces exposure but cannot eliminate prompt injection, and shared identity still requires reliable attribution and policy enforcement.",
  "source": {
    "name": "AI Engineer",
    "url": "https://www.youtube.com/watch?v=wCIYViPd4SU",
    "published_at": "2026-09-03T14:30:21.000Z"
  },
  "source_class": "video",
  "content_type": "Video",
  "layer": "infra",
  "domains": [
    "coding",
    "security"
  ],
  "topics": [
    "cloud-agents",
    "observability",
    "sandboxing"
  ],
  "verification": {
    "status": "source_linked",
    "label": "Source Linked",
    "method": "source_feed",
    "verified_at": null
  },
  "uncertainty": [
    "That index trades freshness for control: the talk reports data within **24 hours**, or **6 hours** for frequently updated sites. Curated retrieval reduces exposure but cannot eliminate prompt injection, and shared identity still requires reliable attribution and policy enforcement."
  ],
  "connected_context": {
    "meaning": "This grounds enterprise agent deployment in existing employee identity and platform controls rather than separate agent accounts. It complements the candidates’ sandbox focus with an attribution model: permissions stay user-scoped while trace IDs distinguish delegated activity. Controlled web grounding further narrows outbound access, but introduces a measurable freshness tradeoff and leaves prompt injection and policy enforcement unresolved.",
    "corpus_size": 691,
    "generated_at": "2026-09-05T10:07:29.500Z",
    "connections": [
      {
        "title": "Agent Runs now available in the Vercel MCP and CLI",
        "source_name": "Vercel",
        "source_url": "https://vercel.com/changelog/agent-runs-vercel-mcp-cli",
        "feed7_url": "https://feed7.dev/p/agent-runs-vercel-mcp-cli-06cfo04",
        "reason": "Vercel’s reasoning and tool-call traces complement Two Sigma’s propagated trace IDs by showing how attributed agent activity can become inspectable production evidence."
      },
      {
        "title": "From fork() to Fleet: Designing an Agent Sandbox Cloud — Abhishek Bhardwaj, OpenAI",
        "source_name": "YouTube",
        "source_url": "https://www.youtube.com/watch?v=OqM67QG_Ikk",
        "feed7_url": "https://feed7.dev/p/from-fork-to-fleet-designing-an-agent-sandbox-cloud-abhishek-bhardwaj-op-0np9ki3",
        "reason": "The sandbox-cloud design supplies process isolation, persistence, and recovery beneath Two Sigma’s identity-based controls; together they cover different security boundaries rather than substituting for one another."
      },
      {
        "title": "Gemini API Managed Agents: 3.6 Flash, hooks, and more",
        "source_name": "Google",
        "source_url": "https://blog.google/innovation-and-ai/technology/developers-tools/expanding-managed-agents-gemini-api-3-6-flash-hooks/",
        "feed7_url": "https://feed7.dev/p/expanding-managed-agents-gemini-api-3-6-flash-hooks-0xce1pm",
        "reason": "Gemini’s sandbox hooks and token caps offer concrete policy enforcement points for the user-scoped permissions and controlled execution model described here, while its reused environments add separate drift and cleanup risks."
      },
      {
        "title": "Cloud agents start 3x faster with builds",
        "source_name": "Cursor",
        "source_url": "https://cursor.com/blog/builds",
        "feed7_url": "https://feed7.dev/p/builds-1x27f44",
        "reason": "Cursor’s prepared snapshots reinforce reuse of managed platform infrastructure for cloud agents, but its stale-image fallback parallels the freshness tradeoff Two Sigma accepts in curated web retrieval."
      }
    ]
  },
  "lifecycle": "Current",
  "published_at": "2026-09-03T14:30:21.000Z",
  "modified_at": "2026-09-03T14:30:21.000Z",
  "supersedes": [],
  "expires_at": null,
  "formats": {
    "html": "https://feed7.dev/p/tethered-our-agents-are-us-shu-fang-two-sigma-0c8u33i",
    "json": "https://feed7.dev/p/tethered-our-agents-are-us-shu-fang-two-sigma-0c8u33i.json",
    "markdown": "https://feed7.dev/p/tethered-our-agents-are-us-shu-fang-two-sigma-0c8u33i.md"
  }
}