Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apollo GraphOS Agent Services: Apollo Agrees Agents Need Explicit Rules — But Governance Stops at Access

Apollo GraphOS Agent Services: Apollo Agrees Agents Need Explicit Rules — But Governance Stops at Access On October 7, 2026, Apollo GraphQL launched GraphOS Agent Services at Apollo Summit in San Francisco: search, identity, policy, and audit services sitting between AI agents and enterprise systems — translating agent requests into API calls, brokering credentials, and enforcing controls field…

On October 7, 2026, Apollo GraphQL unveiled GraphOS Agent Services at the Apollo Summit in San Francisco. This service is composed of search, identity, policy, and audit tools, which act between AI agents and enterprise systems. GraphOS coordinates over 2 trillion operations per month. Intuit is currently piloting the service in a preview phase.

Apollo claims that the rules regarding what is safe to return are typically based on a developer's judgment, not the API itself, and agents do not have access to this judgment. Therefore, these rules need to be made explicit and consistently enforced, regardless of the AI model's decisions.

Apollo's new governance system ensures that agents can only access what they are explicitly permitted to access. The system does not manage the financial aspect of agent transactions. According to a Gartner Market Guide for Guardian Agents from February 2026, 80% of unauthorized AI agent transactions in the next eight years will likely result from internal policy violations, such as oversharing, unacceptable use, or misguided AI behavior, rather than malicious attacks.

Apollo's access policy can determine whether an agent can see or do something, but it cannot decide whether an action should be paid for. The system includes an audit trail of all activities, which logs the instruction, authority, score, band, and outcome. The company has tested the system with two GraphOS-shaped instructions on the scriptmasterlabs.com/api/harness/decide endpoint, and the results show that the heuristic cannot differentiate between authorized but wrong actions and malicious behavior. In both cases, the system recommended a human review or holding the action for further inspection.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Managing Cross-Functional Teams: A Practical Guide for Engineering Leaders

Cross-functional teams are where most modern software gets built. Product defines the problem, design shapes the experience, engineering builds the system, QA and security protect it, data measures…

  • Cross-functional teams combine product, design, engineering, QA, security, data, and operations.
  • Team charter addresses ownership, decision rights, and working agreements to prevent failure modes.

Implementing a JSON Parser

Ever wondered how applications understand and process data from APIs? The magic often lies in a data format called JSON. This human-readable format is widely used to transmit data over the internet.

  • JSON parser implemented using Deno and TypeScript
  • Tokenizing breaks JSON into meaningful tokens
  • Parsing creates Abstract Syntax Tree for structured data

Validate Google Hotel Center, Wego and trivago hotel feeds from CI

Validate Google Hotel Center, Wego and trivago hotel feeds from CI Hotel distribution feeds look simple until you need to send the same property data to multiple platforms.

  • Open-source CLI tool validates Google Hotel Center, Wego, trivago feeds.
  • Supports published-contract validation and readiness checks for platforms.
  • CLI integrates into CI pipelines for automated feed quality checks.

More from Friday 9 October →