← Daily
📝 article evilmartians.com · August 25, 2026

Access control for AI agents on Rails: gating SQL with Action Policy

Giving an AI assistant read-only SQL is fine until it returns data the requesting user should never see. Evil Martians moved the data boundary from the prompt into Action Policy, keeping open-ended SQL while enforcing real authorisation.

An AI assistant with read-only SQL is a superhero. Until it fails privacy responsibilities and leaks sensitive data to everyone. We noted this possibility in an internal tool, moved the data boundary from prompt to Action Policy, and kept open-ended SQL: Access control for AI agents on Rails: gating SQL with Action Policy

Read on evilmartians.com →

More from this day

+ Feature your site