Dev.to AI 🤖 Ai 👁 0 📖 1 min read

When there is no rule, the answer is no

When an AI agent asks Verax for something there is no rule for, the answer is no. Nothing is allowed by default. That covers the obvious case, like an agent trying to export your customer list. It also covers a quieter

When an AI agent asks Verax for something there is no rule for, the answer is no. Nothing is allowed by default.

That covers the obvious case, like an agent trying to export your customer list. It also covers a quieter one. The agent gets refused, then tries the same thing under a different tool name. A new name has no rule either, so it gets refused again.

What that looks like in the policy

The policy Verax starts from names four tools and nothing else:

{
  "version": 1,
  "default": "deny",
  "rules": [
    { "id": "memory-get",    "tool": "memory.get",    "requires": ["verax:read"] },
    { "id": "memory-put",    "tool": "memory.put",    "requires": ["verax:memory"] },
    { "id": "audit-explain", "tool": "audit.explain", "requires": ["verax:read"] },
    { "id": "message-read",  "tool": "message.read",  "requires": ["verax:read"] }
  ]
}

A call to anything else, including a tool that exists on a server attached behind Verax, is refused before that server sees it. Two rules for the same tool are refused when the policy loads, so a second rule cannot quietly widen the first.

A refusal is a record too

Refusals are signed and recorded the same way approvals are: which agent, which tool, what time. When something goes wrong, the attempts that were stopped usually tell you more than the ones that went through.

The record stays on your machine. verax verify reads it with no server running and nothing on the network, and says how many signatures verify and whether the chain is unbroken.

What it doesn't do: the same system keeps the record and signs it, and no independent audit has been done.

Episode 2 of the series, animated in three.js and voiced with ElevenLabs.

Source (Apache-2.0): https://github.com/verax-ai/verax

📰 Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.