เมื่อ AI agent ถือครอง credentials ของตัวเองและติดต่อกลับไปยังบริการภายนอกโดยตรง มันจะทำตัวเหมือนผู้รับเหมาที่มีบัตรเครดิตบริษัทแต่ไม่มีหัวหน้างาน มากกว่าที่จะเป็นซอฟต์แวร์สำหรับพนักงาน คุณไม่สามารถเห็นได้ว่ามันไปแตะต้องอะไร ใครเป็นผู้อนุมัติการเข้าถึง หรือทำไมการสนทนาหนึ่งถึงมีค่าใช้จ่ายมากกว่าอีกครั้งถึงสิบเท่า บันทึกเหตุการณ์ (logs) กระจัดกระจายอยู่ตามบริการต่างๆ มากมาย และคำถามก็เพิ่มพูนขึ้นเรื่อยๆ
Agent เรียกใช้เครื่องมือใดกันแน่? ใครเป็นคนอนุญาตให้มันเข้าถึงฐานข้อมูลนั้น? ทำไมการทำงานเมื่อวันอังคารถึงใช้ไปถึงสี่หมื่นโทเคน ในขณะที่วันจันทร์ใช้เพียงห้าโทเคน? แล้วจริงๆ แล้วเราจ่ายเงินไปเท่าไหร่กันแน่?
หากไม่มีเลเยอร์ควบคุมส่วนกลาง (central control layer) คั่นกลางระหว่างผู้ใช้ โมเดล และบริการ คำถามเหล่านี้ก็จะยังคงไม่ได้รับคำตอบ คุณต้องการ control plane เพียงหนึ่งเดียวที่ลงทะเบียนทุกการเชื่อมต่อเพียงครั้งเดียว เปิดให้ใช้งานเฉพาะชุดฟังก์ชันที่จำกัดซึ่ง agent จำเป็นต้องใช้จริงๆ และบันทึกทุกการทำงานอย่างครบถ้วน บทความนี้จะพาคุณไปทำแล็บขั้นสูงโดยใช้ deco Studio เป็น local control plane ในเครื่องของคุณ คุณจะได้ติดตั้งมัน เชื่อมต่อกับ Model Context Protocol server ที่ปลอดภัย เปิดใช้งานฟังก์ชันที่ได้รับอนุญาตเพียงฟังก์ชันเดียว และดูว่าจะเกิดอะไรขึ้นเมื่อ agent พยายามเข้าถึงสิ่งที่อยู่นอกเหนือขอบเขตของมัน
ปัญหาของการมี Credentials ที่กระจัดกระจาย
ลองจินตนาการถึงการทำงานในทีมทั่วไป นักพัฒนาคนหนึ่งเชื่อมต่อ agent เข้ากับ search API โดยใช้คีย์ส่วนตัว อีกคนเชื่อมต่อ agent ตัวเดียวกันเข้ากับฐานข้อมูล production เพราะเห็นว่าตัวเดโมดูไม่มีอันตราย ส่วนคนที่สามเพิ่มเครื่องมือค้นหาข้อมูลการเรียกเก็บเงินเพื่อให้ agent สามารถ "ช่วยเรื่องใบแจ้งหนี้" ได้ การเชื่อมต่อแต่ละอย่างต่างก็มองไม่เห็นโดยคนอื่นๆ ตอนนี้ agent จึงสามารถเข้าถึงการค้นหา ข้อมูล production และบันทึกทางการเงินได้โดยตรง แต่ทีมกลับไม่มีรายการรวมที่ชัดเจนว่ามีการเชื่อมต่อใดบ้างที่ใช้งานอยู่
เมื่อ credentials อยู่ภายในตัว agent ระบบการกำกับดูแล (governance) ก็จะพังทลาย คุณไม่สามารถยกเลิกการเข้าถึงจากส่วนกลางได้ เพราะคีย์นั้นอยู่ในหน่วยความจำของ agent หรืออยู่ในไฟล์ environment ในเครื่องของมัน คุณไม่สามารถตรวจสอบการใช้งานได้ เพราะบริการภายนอกจะเห็นเพียงการเรียก API จาก client อัตโนมัติที่ไม่ระบุตัวตน ค่าใช้จ่ายที่น่าตกใจจะปรากฏขึ้นในบิลค่าบริการคลาวด์ในอีกหลายวันต่อมา และเมื่อถึงตอนนั้น ก็ไม่มีใครจำได้แล้วว่า prompt ไหนที่เป็นตัวกระตุ้นให้เกิดการใช้งานพุ่งสูงขึ้น
การสร้าง Control Plane ของคุณใน deco Studio
deco Studio แก้ปัญหานี้โดยทำหน้าที่เป็น local hub คุณรันมันบนเครื่องของคุณเอง และมันจะกลายเป็นที่เดียวที่ใช้เก็บการตั้งค่า (configurations) แทนที่จะกระจาย API keys และการนิยามเครื่องมือ (tool definitions) ไปตาม agent ต่างๆ คุณเพียงแค่ลงทะเบียนการเชื่อมต่อครั้งเดียวภายใน Studio จากนั้นคุณก็ตัดสินใจได้เลยว่า agent แต่ละตัวจะมองเห็นฟังก์ชันใดบ้าง
ให้คิดซะว่ามันเหมือนการติดตั้งแผงสวิตช์สายโทรศัพท์ สายไฟทั้งหมดจะวิ่งมารวมกันที่ห้องเดียว คุณเลือกได้ว่าสายไหนจะเชื่อมต่อกับแผนกใด และคุณสามารถเก็บบันทึกการโทรทุกครั้งได้
เริ่มต้นด้วยการรัน deco Studio ในเครื่องของคุณ เมื่อรันขึ้นมาแล้ว คุณก็สามารถรวมศูนย์การตั้งค่าได้ ทุก agent ที่ต้องการใช้เครื่องมือจะต้องถามผ่าน control plane แทนที่จะติดต่อกับบริการภายนอกโดยตรง สิ่งนี้จะสร้างจุดควบคุม (chokepoint) ที่ทำให้คุณสามารถสังเกตการณ์ กรองข้อมูล และบันทึก log ได้ทันที
การเชื่อมต่อ MCP Server ที่ปลอดภัย
ในแล็บนี้ คุณจะเชื่อมต่อกับ Model Context Protocol server โดย MCP เป็นมาตรฐานเปิดที่ช่วยให้โมเดลสามารถโต้ตอบกับเครื่องมือภายนอกได้ แต่มาตรฐานไม่ได้การันตีความปลอดภัย ขั้นตอนสำคัญในที่นี้คือการเลือกสรร (selectivity) คุณจะไม่เปิดเผยทุก endpoint ที่เซิร์ฟเวอร์มีให้โดยไม่ดูให้ดี คุณจะลงทะเบียนเซิร์ฟเวอร์ใน deco Studio จากนั้นจึงเปิดให้ agent ทดสอบของคุณเข้าถึงได้เพียงฟังก์ชันเดียวที่ได้รับอนุญาตเท่านั้น
ตัวอย่างเช่น MCP server ของคุณอาจมีสิบฟังก์ชัน เช่น การอ่านไฟล์, การเขียนไฟล์, การสอบถามฐานข้อมูล, การดึงข้อมูลผ่านเครือข่าย และอื่นๆ คุณเลือกการทำงานที่ไม่เป็นอันตรายเพียงอย่างเดียว เช่น เครื่องคิดเลขใน sandbox หรือการค้นหาข้อมูลแบบอ่านอย่างเดียว (read-only) จากข้อมูลจำลอง (synthetic data) และเปิดให้ใช้เพียงอย่างนั้น ส่วนอีกเก้าฟังก์ชันที่เหลือจะกลายเป็นสิ่งที่ agent มองไม่เห็น หาก agent ร้องขอฟังก์ชันเหล่านั้น control plane จะตอบปฏิเสธทันที
นี่คือการนำหลักการ "ให้สิทธิ์เท่าที่จำเป็น" (principle of least privilege) มาทำให้เป็นระบบอัตโนมัติ Agent จะได้รับความสามารถไม่ใช่ผ่านคำสั่งที่สุภาพ แต่ผ่านขอบเขตของซอฟต์แวร์
การทดสอบขอบเขต
สร้าง agent สำหรับทดสอบและกำหนดให้มันชี้ไปยัง deco Studio control plane ของคุณ มอบหมายงานที่ต้องใช้ฟังก์ชันเดียวที่ได้รับอนุญาต แล้วดูความสำเร็จของมัน บันทึก log ภายใน Studio จะแสดงให้เห็นตั้งแต่การร้องขอของโมเดล, การส่งต่อการเรียกใช้เครื่องมือผ่าน control plane, การทำงานของฟังก์ชัน และผลลัพธ์ที่ไหลกลับไปยังโมเดล คุณสามารถอ่านเส้นทางการทำงานทั้งหมดได้ในการติดตามผล (trace) เพียงครั้งเดียว
Now give the agent a second task that requires a function you deliberately excluded. The agent might attempt to reason its way around the limitation, or it might hallucinate that the tool exists. Either way, the call hits the control plane, the allowlist rejects it, and the execution fails. That failure is your proof that the boundary is software-enforced, not theoretical.
Do this with synthetic tasks first. Build a fake database full of generated user profiles. Let the agent query it. Verify the allowlist and the denials. Only after you trust the boundary should you even consider pointing the agent at production systems. Rushing to real data before you verify the wall is how secrets leak.
Reading the Full Path of a Run
deco Studio lets you inspect every layer of an execution. You see the raw model request: the prompt, the context window, the formatting. You see the tool call the model decided to make. You see the control plane route that call, the function execute, and the payload return. Finally, you see how the model consumes that result to form its answer.
This visibility answers the basic audit questions. You know which tool fired because the control plane logged it. You know who granted access because the configuration records sit in one local registry. You know why the run was expensive because you can count the tokens.
Counting What Matters
For every run, track four specific metrics. First, input and output tokens. These drive the bulk of model costs, and you need exact counts, not rough estimates. Second, separate model latency from tool latency. The time between your prompt and the model's response is different from the time the external service takes to answer a tool call. Confusing the two leads to misdiagnosed slowdowns. Third, calculate cost based on verified provider rates. Do not guess. Check your provider's pricing sheet and match it against the measured tokens. Fourth, compare successful calls against rejected unauthorized calls. A high rejection count means your agent is probing boundaries or your allowlist is misaligned with legitimate needs.
These numbers turn agent operations from a black-box subscription into an observable system. You can budget, optimize, and explain.
The Difference Between Local Control and Local Execution
Here is a lesson that trips up even careful builders. Running deco Studio on your machine gives you local control over configuration, but it does not guarantee local execution of the model itself. If you configure the agent to call an external provider such as OpenAI, Anthropic, or any hosted API, your prompts leave your machine. Studio manages the gate, but the data still crosses the network.
Always track these boundaries. Know which parts of the pipeline stay on localhost and which bits travel to someone else's server. If your data is sensitive, local control of the tool layer is not enough. You also need to know where the model inference happens. Do not confuse the comfort of a local dashboard with the reality of a remote model.
Instructions Are Not Authorization
One dangerous shortcut is trying to secure an agent through prompting. Telling the model, "Never call the delete function," is not a security control. It is a suggestion. Models can misinterpret instructions, jailbreak prompts, or simply make reasoning errors. Real security lives at the software boundary.
Use allowlists inside deco Studio to define exactly which functions are callable. Enforce those limits with server-side checks inside the control plane. The agent should discover its capabilities the way a user discovers file permissions: by hitting a hard limit, not by reading a friendly note. Security belongs in architecture, not in natural language.
Start Small, Stay Skeptical
Build your control plane one step at a time. One MCP server. One exposed function. One synthetic task. Verify that the agent succeeds where it should and fails where it must. Read the trace. Confirm the token counts. Then add the next tool.
Control is not a switch you flip. It is a habit of proving boundaries before you trust them. deco Studio gives you the local plane to practice that habit. Use it to turn a swarm of autonomous agents into a managed, observable, and bounded system.
Source: Controlling AI Agents in deco Studio: Tools, Permissions, and Cost
ชุมชนการเรียนรู้เพิ่มเติม: GyaanSetu AI บน Telegram
