Someone else's agent, in your repo
Blog post from Agent Relay
A live cross-company test of the Ratify Protocol and Agent Relay explored a more controlled alternative to granting external AI agents broad API keys, GitHub App permissions, or service-account access. The system issued a signed, verifiable permission certificate limiting an agent to a specific repository and folder, allowing it to make changes and open a pull request while preventing it from exceeding its delegated authority; any work delegated to a sub-agent received still narrower permissions and a shorter time window. During the run, the repository owner revoked the certificate remotely, and the agent’s subsequent commands were blocked within seconds despite the certificate having hours remaining. Revocations were delivered as signed metadata in a standard agent-to-agent message, then verified against keys exchanged during setup, avoiding separate shutdown integrations for each partner. Public records of certificates, revocations, signed receipts, repositories, and the deployment container image are available to support independent reproduction and testing.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.