DashboardKnowledgeAgent infrastructure boundary

Agent infrastructure boundary

Category: preference
Confidence: 1.00
ID: 019fdd3e-42c3-7b3e-b46b-cd202668199b
Project ID: (global)
Cross-project: Yes
Recalled in other projects: 0
Source session: 0u3imAJmtplig6wtJ
Created: 2026-08-07 17:21:12
Updated: 2026-08-07 17:21:12

Content

Agent code, filesystem contents, and network egress must never leave infrastructure controlled by the operator. Vendor-managed execution may look simpler, but it violates the required security boundary unless the vendor only provides control-plane routing and the actual agent runtime and egress remain inside controlled infrastructure.

Move to: