ஒரு AI agent தனது சொந்த அங்கீகாரங்களை (credentials) எடுத்துக்கொண்டு நேரடியாக வெளிப்புறச் சேவைகளைத் தொடர்பு கொள்ளும்போது, அது ஒரு ஊழியர் மென்பொருளைப் போல இல்லாமல், மேற்பார்வையாளர் இல்லாத ஒரு கார்ப்பரேட் கார்டு வைத்திருக்கும் ஒப்பந்ததாரரைப் போலச் செயல்படுகிறது. அது எதைத் தொட்டது, அந்த அணுகலை யார் அனுமதித்தது, அல்லது ஏன் ஒரு உரையாடல் மற்றொன்றை விட பத்து மடங்கு அதிக செலவைச் செய்தது என்பதை உங்களால் பார்க்க முடியாது. பதிவுகள் (logs) பல சேவைகளில் சிதறிக்கிடக்கின்றன. கேள்விகள் பெருகுகின்றன.

அந்த agent உண்மையில் எந்தக் கருவியைத் (tool) தூண்டியது? அந்தத் தரவுத்தளத்தைத் (database) தொட அதற்கு யார் அனுமதி வழங்கியது? திங்கட்கிழமை ஐந்து டோக்கன்களைப் பயன்படுத்திய நிலையில், செவ்வாய்க்கிழமை இயக்கம் ஏன் நாற்பதாயிரம் டோக்கன்களைச் செலவிட்டது? நாம் உண்மையில் எவ்வளவு செலவு செய்தோம்?

பயனர்கள், மாடல்கள் மற்றும் சேவைகளுக்கு இடையே ஒரு மையக் கட்டுப்பாட்டு அடுக்கு (central control layer) இல்லையென்றால், இந்தக் கேள்விகளுக்குப் பதில் கிடைக்காது. ஒவ்வொரு இணைப்பையும் ஒருமுறை பதிவு செய்யும், ஒரு agent-க்குத் தேவையான மிகக் குறுகிய செயல்பாடுகளை (functions) மட்டுமே வெளிப்படுத்தும் மற்றும் ஒவ்வொரு செயல்பாட்டையும் முழுமையாகப் பதிவு செய்யும் ஒரு ஒற்றை தளத்தை (single plane) உங்களுக்குத் தேவைப்படுகிறது. இந்தத் கட்டுரை, deco Studio-வை அந்த உள்ளூர் கட்டுப்பாட்டுத் தளமாகப் (local control plane) பயன்படுத்தி ஒரு மேம்பட்ட ஆய்வை (advanced lab) விளக்குகிறது. நீங்கள் அதை அமைப்பீர்கள், ஒரு பாதுகாப்பான Model Context Protocol server-ஐ இணைப்பீர்கள், சரியாக ஒரு அனுமதிக்கப்பட்ட செயல்பாட்டை மட்டும் வெளிப்படுத்துவீர்கள், மேலும் ஒரு agent தனது எல்லையைத் தாண்டிச் செல்ல முயலும்போது என்ன நடக்கிறது என்பதைக் காண்பீர்கள்.

சிதறிக்கிடக்கும் அங்கீகாரங்களின் (Credentials) சிக்கல்

ஒரு வழக்கமான குழு அமைப்பை கற்பனை செய்து பாருங்கள். ஒரு டெவலப்பர் ஒரு தனிப்பட்ட சாவியைப் (personal key) பயன்படுத்தி ஒரு search API-யுடன் ஒரு agent-ஐ இணைக்கிறார். மற்றொருவர், டெமோ பார்ப்பதற்குப் பாதுகாப்பானது என்று நினைத்து, அதே agent-ஐ ஒரு production database-உடன் இணைக்கிறார். மூன்றாவது நபர், agent இன்வாய்ஸ்களுக்கு (invoices) உதவலாம் என்பதற்காக ஒரு billing lookup tool-ஐச் சேர்க்கிறார். ஒவ்வொரு இணைப்பும் மற்றவர்களுக்குத் தெரியாமல் மறைந்திருக்கிறது. இப்போது அந்த agent-க்குத் தேடல், தயாரிப்புத் தரவு (production data) மற்றும் நிதிப் பதிவுகள் ஆகியவற்றிற்கு நேரடி அணுகல் உள்ளது, ஆனால் என்னென்ன செயல்பாடுகள் நேரலையில் (live) உள்ளன என்பதற்கான ஒருங்கிணைந்த பட்டியல் குழுவிடம் இல்லை.

அங்கீகாரங்கள் agent-க்குள் இருக்கும்போது, நிர்வாகக் கட்டுப்பாடு (governance) முறியடிக்கப்படுகிறது. சாவியானது agent-ன் நினைவகத்திலோ (memory) அல்லது அதன் உள்ளூர் சூழல் கோப்பிலோ (local environment file) இருப்பதால், உங்களால் மையமாக அணுகலைத் திரும்பப் பெற (revoke) முடியாது. வெளிப்புறச் சேவை ஒரு பெயர் தெரியாத தானியங்கி கிளையண்டிலிருந்து (anonymous automated client) வரும் API அழைப்பை மட்டுமே பார்ப்பதால், உங்களால் பயன்பாட்டைக் கணக்கெடுப்பு (audit) செய்ய முடியாது. செலவு அதிகரிப்பு குறித்த ஆச்சரியங்கள் பல நாட்களுக்குப் பிறகு ஒரு cloud bill-இல் தோன்றும், அதற்குள் எந்த prompt இந்த அதிகரிப்பைத் தூண்டியது என்பது யாருக்கும் நினைவிருக்காது.

deco Studio-வில் உங்கள் கட்டுப்பாட்டுத் தளத்தை உருவாக்குதல்

deco Studio ஒரு உள்ளூர் மையமாக (local hub) செயல்படுவதன் மூலம் இதைச் சரிசெய்கிறது. நீங்கள் இதை உங்கள் சொந்த இயந்திரத்தில் இயக்குவீர்கள், மேலும் இது கட்டமைப்புகள் (configurations) சேமிக்கப்படும் ஒரே இடமாக மாறும். API சாவிகள் மற்றும் கருவி வரையறைகளை (tool definitions) பல்வேறு agent-களுக்கு இடையே சிதறவிடுவதைத் தவிர்த்து, நீங்கள் Studio-க்குள் ஒருமுறை இணைப்பைப் பதிவு செய்கிறீர்கள். பின்னர் ஒவ்வொரு agent-ம் எந்தச் செயல்பாடுகளைப் பார்க்க முடியும் என்பதை நீங்கள் துல்லியமாகத் தீர்மானிக்கிறீர்கள்.

இதை ஒரு சுவிட்ச்போர்டை (switchboard) நிறுவுவது போலக் கருதலாம். அனைத்துக் கம்பிகளும் ஒரே அறைக்குள் செல்கின்றன. எந்தக் கோடுகள் எந்தத் துறைகளுடன் இணைக்கப்பட வேண்டும் என்பதை நீங்கள் தேர்ந்தெடுக்கிறீர்கள், மேலும் ஒவ்வொரு அழைப்பையும் நீங்கள் பதிவு செய்கிறீர்கள்.

deco Studio-வை உள்ளூர் முறையில் இயக்குவதன் மூலம் தொடங்குங்கள். அது செயல்பாட்டிற்கு வந்தவுடன், நீங்கள் கட்டமைப்பை மையப்படுத்துகிறீர்கள். ஒரு கருவியைப் பயன்படுத்த விரும்பும் ஒவ்வொரு agent-ம் இப்போது நேரடியாக வெளிப்புறச் சேவையைத் தொடர்பு கொள்ளாமல், கட்டுப்பாட்டுத் தளத்தைக் கேட்க வேண்டும். இது நீங்கள் உற்றுநோக்க (observe), வடிகட்ட (filter) மற்றும் பதிவு செய்ய (log) உதவும் ஒரு நெரிசலுக்கான புள்ளியை (chokepoint) உடனடியாக உருவாக்குகிறது.

ஒரு பாதுகாப்பான MCP Server-ஐ இணைத்தல்

இந்த ஆய்வில், நீங்கள் ஒரு Model Context Protocol server-ஐ இணைக்கிறீர்கள். மாடல்கள் வெளிப்புறக் கருவிகளுடன் தொடர்பு கொள்ள அனுமதிக்கும் ஒரு திறந்த தரநிலை (open standard) தான் MCP, ஆனால் தரநிலைகள் பாதுகாப்பை உறுதி செய்வதில்லை. இங்கே முக்கியமான படிநிலைத் தெரிவுத்திறன் (selectivity) ஆகும். சர்வர் வழங்கும் ஒவ்வொரு endpoint-யையும் நீங்கள் கண்மூடித்தனமாக வெளிப்படுத்தக் கூடாது. நீங்கள் சர்வரை deco Studio-வில் பதிவு செய்து, பின்னர் உங்கள் சோதனை agent-க்கு ஒரு அனுமதிக்கப்பட்ட செயல்பாட்டை மட்டும் வெளிப்படுத்துவீர்கள்.

உதாரணமாக, உங்கள் MCP server பத்து செயல்பாடுகளை வழங்கலாம்: file read, file write, database query, network fetch மற்றும் பிற. நீங்கள் ஒரு தீங்கற்ற செயல்பாட்டைத் தேர்ந்தெடுக்கிறீர்கள், ஒருவேளை ஒரு sandboxed calculator அல்லது செயற்கையான தரவுகளுக்கு எதிரான (synthetic data) read-only lookup, மற்றும் அதை மட்டும் வெளிப்படுத்துகிறீர்கள். மற்ற ஒன்பது செயல்பாடுகளும் agent-க்குத் தெரியாதவாறு மறைந்துவிடும். ஒருவேளை agent அவற்றைக் கேட்டால், கட்டுப்பாட்டுத் தளம் ஒரு கடுமையான மறுப்பைத் (hard refusal) தரும்.

இது 'குறைந்தபட்ச அதிகாரக் கொள்கையை' (principle of least privilege) இயந்திரமயமாக்குவதாகும். ஒரு மென்மையான அறிவுறுத்தல் மூலம் அல்லாமல், ஒரு மென்பொருள் எல்லையின் (software boundary) மூலம் agent திறனைப் பெறுகிறது.

எல்லையைச் சோதித்தல்

ஒரு சோதனை agent-ஐ உருவாக்கி அதை உங்கள் deco Studio கட்டுப்பாட்டுத் தளத்திற்குத் திருப்புங்கள். அனுமதிக்கப்பட்ட அந்த ஒற்றைச் செயல்பாட்டைத் தேவைப்படும் ஒரு பணியை அதற்குத் தாருங்கள். அது வெற்றிகரமாகச் செயல்படுவதைக் கவனியுங்கள். Studio-விற்குள் உள்ள பதிவுகள் (logs), மாடல் கோரிக்கை (model request), கட்டுப்பாட்டுத் தளம் வழியாகக் கருவி அழைப்பு வழிசெலுத்தல் (tool call routing), செயல்பாட்டின் இயக்கம் (function execution) மற்றும் மாடலுக்குத் திரும்பும் முடிவு ஆகியவற்றைத் காண்பிக்கும். முழுப் பாதையையும் நீங்கள் ஒரே தொடர்ச்சியான தடயத்தில் (continuous trace) படிக்கலாம்.

Now give the agent a second task that requires a function you deliberately excluded. The agent might attempt to reason its way around the limitation, or it might hallucinate that the tool exists. Either way, the call hits the control plane, the allowlist rejects it, and the execution fails. That failure is your proof that the boundary is software-enforced, not theoretical.

Do this with synthetic tasks first. Build a fake database full of generated user profiles. Let the agent query it. Verify the allowlist and the denials. Only after you trust the boundary should you even consider pointing the agent at production systems. Rushing to real data before you verify the wall is how secrets leak.

Reading the Full Path of a Run

deco Studio lets you inspect every layer of an execution. You see the raw model request: the prompt, the context window, the formatting. You see the tool call the model decided to make. You see the control plane route that call, the function execute, and the payload return. Finally, you see how the model consumes that result to form its answer.

This visibility answers the basic audit questions. You know which tool fired because the control plane logged it. You know who granted access because the configuration records sit in one local registry. You know why the run was expensive because you can count the tokens.

Counting What Matters

For every run, track four specific metrics. First, input and output tokens. These drive the bulk of model costs, and you need exact counts, not rough estimates. Second, separate model latency from tool latency. The time between your prompt and the model's response is different from the time the external service takes to answer a tool call. Confusing the two leads to misdiagnosed slowdowns. Third, calculate cost based on verified provider rates. Do not guess. Check your provider's pricing sheet and match it against the measured tokens. Fourth, compare successful calls against rejected unauthorized calls. A high rejection count means your agent is probing boundaries or your allowlist is misaligned with legitimate needs.

These numbers turn agent operations from a black-box subscription into an observable system. You can budget, optimize, and explain.

The Difference Between Local Control and Local Execution

Here is a lesson that trips up even careful builders. Running deco Studio on your machine gives you local control over configuration, but it does not guarantee local execution of the model itself. If you configure the agent to call an external provider such as OpenAI, Anthropic, or any hosted API, your prompts leave your machine. Studio manages the gate, but the data still crosses the network.

Always track these boundaries. Know which parts of the pipeline stay on localhost and which bits travel to someone else's server. If your data is sensitive, local control of the tool layer is not enough. You also need to know where the model inference happens. Do not confuse the comfort of a local dashboard with the reality of a remote model.

Instructions Are Not Authorization

One dangerous shortcut is trying to secure an agent through prompting. Telling the model, "Never call the delete function," is not a security control. It is a suggestion. Models can misinterpret instructions, jailbreak prompts, or simply make reasoning errors. Real security lives at the software boundary.

Use allowlists inside deco Studio to define exactly which functions are callable. Enforce those limits with server-side checks inside the control plane. The agent should discover its capabilities the way a user discovers file permissions: by hitting a hard limit, not by reading a friendly note. Security belongs in architecture, not in natural language.

Start Small, Stay Skeptical

Build your control plane one step at a time. One MCP server. One exposed function. One synthetic task. Verify that the agent succeeds where it should and fails where it must. Read the trace. Confirm the token counts. Then add the next tool.

Control is not a switch you flip. It is a habit of proving boundaries before you trust them. deco Studio gives you the local plane to practice that habit. Use it to turn a swarm of autonomous agents into a managed, observable, and bounded system.

Source: Controlling AI Agents in deco Studio: Tools, Permissions, and Cost

விருப்பத்திற்குரிய கற்றல் சமூகம்: Telegram-இல் GyaanSetu AI