AI agents do not behave like traditional software. Securing them requires a new approach.
Standup notes posted. 2 blockers cleared.
"Q3 renewal benchmarks — mid-market SaaS"
An agent is a model with at least one tool and a goal. That combination is like a new employee who was handed your credentials, your network, and a shell, and who works at machine speed.
01
A user's permissions. A tool. The network. Each was approved on its own. Together they are a new actor most stacks have nowhere to put, so the agent inherits the widest access nearby.
02
A test tells you what the agent did once. Not what it will do with a new prompt, a new document, or a poisoned input. If you cannot predict the actions, you have to limit what they can reach. Which hosts. Which services. Which files. Which other agents.
03
An agent can chain a dozen tool calls in the time a human reads one alert. A control that arrives after the action has already lost. The boundary has to exist before the first call.
You approve an enclave once and every workload inside inherits its policies.
ACRA extends the Kubernetes you already run. Install the control plane on your cluster. You hold the keys. After handover, Valarian has no path in.
A new enclave inherits identity, policy and audit. You declare the members, the hosts, the model and the files. There is no path to another enclave unless you grant one.
It starts with the paths you named. Declare the image, the dependencies and the hostnames. A missing provider, and it does not start.
Declared paths run at full speed. The rest is refused and named. No gateway in the path. Every refusal is written down with the workload's name on it.
ACRA isn't a sandbox. It defines the world your agents can reach, then gets out of the way so you can run at full speed.
The agent lives at L4, with its tools and the work it was given. The thing that stops it lives at L1. There is no path between them, so an agent cannot rewrite an allowlist it cannot see, and it cannot climb into the control layer because the control layer is not on its plane. That is the argument of the picture.
Compliance
PrivacyControl infrastructure for high-consequence systems.
© 2026 Valarian · London
We use cookies and other technologies to personalise your experience, perform marketing, and collect analytics. Learn more in our privacy policy.