Skip to main content

Security model (v1.0)

Sqube Agent Control is execution authorization infrastructure, not a guarantee that every side effect in a process is impossible without Sqube.

Enforcement boundaries​

LayerWhat it controlsBypass risk
SDK guardCalls wrapped with ExecutionGuard / engineHigh — any unwrapped call skips Sqube
InterceptorCentral hook around a code pathMedium — depends on integration
MCP adapterTool calls routed through the adapterMedium — direct MCP bypass possible
Future gatewayNetwork-level enforcementLower — outside agent process

Document and design for the boundary you actually deploy.

Defaults​

  • Fail closed on policy, identity, and storage errors unless on_error="fail_open" is explicitly set.
  • No secrets in evidence — parameters are hashed; summaries are redacted.
  • Deterministic policy — no LLM as the authorization authority.

Identity​

agent_id and principal are application-supplied unless you integrate a real identity provider. Sqube does not cryptographically prove agent identity in the local SDK alone.

Ledger integrity​

Event hash chains detect tampering of stored events. This supports audit and debugging; it is not a legal-grade proof without broader controls.

See Threat model for structured risks and mitigations.