How BlueBear handles the work
Goal hijacking and tool misuse
Constrain agents with workflow definitions, assigned MCP capabilities, action policy, approval gates, budgets, and denial tests. Prompt filtering alone is not the boundary.
Evidence: Platform control: tool/action scope and policy result · Customer-owned: approved workflow and risk tier
Identity and privilege abuse
Carry authenticated actor, tenant, workspace, agent, credential, and resource context into authorization. Avoid token passthrough and implicit authority from prompt content.
Evidence: Platform control: scoped execution context · Deployment-specific: IdP, MFA, token lifetime, and key ownership
Supply chain and unexpected code execution
Inventory servers, tools, versions, packages, artifacts, and runtime permissions. Restrict execution environments and require review for new or changed capabilities.
Evidence: Shared responsibility: platform assignment and logs; customer approval, scanning, network, and runtime policy
Incident response and accountability
Correlate plans, policy decisions, model routes, tool calls, approvals, retries, failures, costs, and outcomes so responders can contain and reconstruct an incident.
Evidence: Platform control where enabled: session evidence · Customer-owned: retention, response plan, and accountable owners