Every action was permitted. The sequence was not.
A permission check asks "may this caller do this?" one call at a time. An agent can do harm with calls that each pass that check.
Built into the Swiftward service you run.
Who is calling
The user, the agent, or both. Each identity is either stated by your own system, in a header, or proven with a credential the gateway checks. Who is calling matters far more on a tool call than on a model call, because a tool call takes a real action in a real system.
Three levels of what they may do
| Level | Question |
|---|---|
| Roles and grants | may this identity act at all |
| Endpoint level | may it call this specific tool |
| Policy level | is this call, with these arguments, in this sequence, permitted |
An agent reads a customer record, looks up an external address, and sends a document to that address. Each call is allowed on its own. Together, on one customer, they are data exfiltration, and a check that looks at one call at a time never sees it.
MITRE ATLAS lists this as AML.T0086, Exfiltration via AI Agent Tool Invocation.
To catch it, the engine keeps state across calls and a rule tests the sequence. This is the same mechanism as business rules, applied to permissions instead of money.
When the agent belongs to another company
Everything above assumes you can look the caller up, and here you cannot. For agents that work across companies on a blockchain, the emerging answer is a public standard, ERC-8004, instead of any one company's registry.