posts

Universal agents will live or die on permissions

In Google's outline for Gemini at Work, the premise is a universal interface: one prompt box to handle knowledge retrieval and code execution while delegating tasks to sub-agents, with persistent memory retained across devices and systems of record. Centralizing enterprise workflows into a single cloud-hosted personalization graph is an aggressive bet on context over compartmentalization.

I rely on Gemini models for production workloads like summarization and ranking, where their handling of deep context holds up well. But turning that foundation into an autonomous coworker that spawns sub-agents across external tools shifts the engineering focus toward permissions and state management. When an agent creates specialized sub-agents to touch production systems, the primary challenge moves past cost-efficient model routing. Fine-grained access control inside that shared memory layer determines whether autonomous execution is viable.

A universal agent sounds tidy on a stage, but enterprise systems of record remain fragmented for structural reasons, not for a lack of shared text boxes. If persistent execution cannot rigorously isolate user credentials from the actions a sub-agent executes against an API, a unified context graph quickly becomes a governance risk.

Source: x.com/sundarpichai/status/2108257472553386059

← all posts