Your AI agent just provisioned a resource. Who owns it?
The environment has thirty-four resources, including a VPC, subnets, an RDS instance, and a load balancer that hasn’t seen any The post Your AI agent just provisioned a resource. Who owns it? appeared first on The New Stack .
Your AI agent just spun up a resource. Determining who holds ownership of that resource poses a challenge. A departed employee leaves a trail behind, but agents leave none of that. Once their task concludes, their ownership vanishes, just like a candle extinguished. This issue compounds as agents operate in unpredictable ways, owning resources for fleeting periods.
The solution remains consistent: a query, a policy, and a guardrail. The query utilizes CloudQuery's asset inventory to identify the owner of a tagged resource. By cross-referencing this owner with your identity directory, any non-human account stands out. The policy prevents agents from owning themselves by checking the owner tag against your identity directory. If the owner isn't a human account, the policy flags it.
However, this process doesn't address resources already built and abandoned by agents. In such cases, assigning a last day to agents' resources ensures they comply with the ownership rules. The environment's TTL automatically eliminates resources that exceed this limit. This approach guarantees that even older resources adhere to the established ownership guidelines.
Written by urgent.news from The New Stack's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.