Full transcript
0:00This is a demo about personal, which is
0:02a side project that I developed as a AI
0:05harness.
0:06But unlike other harness, which is
0:08trying to make the AI more powerful and
0:11flexible, this harness is more focusing
0:13on how we can contain that power.
0:15So, I'm going to do some quick demo
0:17about some um key features in this
0:20framework.
0:21I'll start with the report itself. This
0:23is the repo uh URL. I'll I'll share that
0:25in the description attached to this
0:27video. Once you clone this repo to your
0:29local,
0:30you will be able to use a
0:32Neson um slash command
0:35is initialize app to actually initialize
0:38the local development environment. And
0:40this will bring up the necessary
0:42components like database, Keycloak, and
0:45OpenTelemetry connectors to kind of
0:47provide the infra level components in
0:49Docker.
0:50And also it will seed necessary data to
0:53uh facilitate the local development.
0:55I have already done this, so the next
0:57step is actually just to start that. You
0:59can still use like a slash command to
1:01start that, but if you want more
1:03visibility, then you can actually use
1:05the
1:07script that we have in the personal
1:09repository. So, there's a PowerShell
1:11script. In order to do that, you will
1:13need to use PowerShell.
1:16And then
1:18there's a personal.ps1,
1:20and you can start your service. You can
1:22start your back end, you can also start
1:23infra, you can also check the status. I
1:25actually have all the state uh services
1:28started, so I believe that's
1:30Yeah, so you can see all these um
1:32services are running.
1:34So, that you get application started,
1:36the next step is to um
1:38log in to the application. So, that's my
1:39first demo. It's about logging in to and
1:41then we will run one agent directly.
1:45I already have things set up there. So,
1:46first thing that's to highlight here is
1:48that we are using Keycloak. You will
1:49have to have like a external OIDC
1:51provider for the identity uh management.
1:54The personal itself don't provide any
1:55identity management building. This is
1:58intentionally to make sure that the
1:59security is brought into this
2:01application from the very beginning.
2:05Okay.
2:06After signing,
2:08you'll get a dashboard give you some
2:10high-level overview view about what is
2:12happening.
2:14And what do you have to jump to agent
2:16management?
2:20I have couple of agents predefined
2:22already for this demo.
2:27Now, because of the recording, this demo
2:29can be a little bit slow. I do have like
2:31a less powerful um MacBook here.
2:35So, agent management,
2:37I will demo this one
2:38query agent for supervised project.
2:40We'll start the demo first. Then I will
2:42explain what is set up behind of this
2:43thing.
2:45We can run agent.
2:46And you'll be required to provide a
2:47project ID. I will intentionally uh not
2:50provide that.
2:51I'll show you why.
2:55So, once you trigger the execution, then
2:57you will have these logs
2:59and some current usage information.
3:02And this is why I didn't provide that. I
3:04want to bring this human intervention,
3:06which is human in the loop. So, this is
3:07where I got in case that you didn't
3:08provide that correctly, then you can
3:10provide this right ID.
3:14And also, this is where you can put a
3:16console for like approval into the
3:18process.
3:22Okay, now I provide the project ID.
3:27And the execution will be resumed.
3:32And it's what dedicates to a agent
3:34called supervised project name agent,
3:36which is the agent that dedicated to
3:39just getting the project name by
3:41querying the by the project ID.
3:56>> Guys, still running.
4:33Okay, now I get three dots.
4:35And then I see the project name. This is
4:37the project name. Uh that's it. Let's
4:39see if choosing of this agent. And
4:41again, I'm using a very old Mac Air here
4:43for the demo. And when I start this
4:45recording, it become very slow.
4:49Look through how this is set up and how
4:51the other security
4:53um
4:54is put in place. I'll talk about
4:56architecture first, because that's the
4:57first place where all the security thing
5:00can actually start to happen.
5:04So, this is the platform architecture.
5:05It's a very high-level architecture.
5:07The core part of our backend service,
5:09there are actually three isolated
5:11services. One is control center, one is
5:13communication hub, and one is agent
5:15runtime.
5:17So, the demo we did, the agent is
5:19actually running inside of the agent
5:20runtime.
5:22And agent itself has no connectivity to
5:25database
5:26uh or to be able to obtain any secrets.
5:29It can only talk to ex- external world
5:32via communication hub.
5:34And agent runtime uses its own identity.
5:37So, basically, whenever agent runtime
5:38start, it will talk to control center to
5:41obtain a certificate. And this
5:43certificate is the ID of the agent
5:45runtime itself. So, when the agent start
5:48to talk to the control center, talk to
5:50the communication hub, it bring that
5:52certificate into the communication and
5:55to prove and agent that's I'm saying
5:58that I am.
5:59So, in that way, when the agent only
6:01bring its own ID to the communication
6:03hub and communication hub then will
6:05fetch talk to control center to make
6:06sure this agent can actually do the
6:08necessary things. So, in this way
6:11even the agent somehow being compromised
6:14or the agent itself um somehow is
6:18misbehaving.
6:19It cannot really do anything that's too
6:21harmful because it has no access. It has
6:23no connection to anything that can make
6:25it somehow um obtain the sensitive data
6:28or information that is not allowed to
6:30access.
6:31So, from the architecture perspective,
6:32you can see that the agent runtime won't
6:34be able to do anything else
6:37but talk to communication hub. The
6:39communication hub is only channel that
6:41the agent agent runtime or any agent can
6:43fish to the external of the world.
6:45And in that way, any thing you want to
6:47put in place that become possible.
6:49And then the control center can talk to
6:51the backend database. And all
6:52interactions is actually interacted
6:54between um I mean the user from the
6:56browser is actually interacting with the
6:58control center or with the communication
6:59hub. And all identity are provided uh
7:02provided from an external identity
7:04provider.
7:05So, that's first thing. That is the
7:07architectural security.
7:09Now, we move back.
7:11With that architecture
7:12then how can we build further security
7:15on top of that?
7:17So, the first thing I want to talk about
7:18is uh so-called skill-based security.
7:21The skill-based security associates
7:24a skill or a SOP
7:27with a a particular agent. So, we can
7:29have a look at one of these, the one
7:31that we just executed.
7:38So, this one is using agent identity and
7:41then it's using agent role.
7:43And from here, the agent preview, you
7:45can actually see the implementation plan
7:47and you can also see this agent actually
7:50um
7:50has one role and use which SOP.
7:53And then invoke one skill
7:55to do something. This here is a
7:57delegation. That is where delegation
7:58happens because in that SOP, it's
7:59basically uh give a skill for human
8:01intervening and then it ask you to
8:03delegate the work to the Shiva base
8:05project name agent and then you get um
8:08the output.
8:11So, this is the uh like topology of the
8:14agents. Of course, when you edit that,
8:15you can see the details uh how these are
8:17defined. The key thing here is the skill
8:19or the SOP. You can either SOP is kind
8:22of like combination of skills or the
8:23step of skills, but uh in general, a
8:25skill is actually a skill. But, here we
8:27um
8:28separate this is into like a
8:30higher-level concept to where it can
8:31associate multiple skills to finish a
8:33task.
8:34So, that we call it SOP.
8:36And this agent is using this SOP.
8:38And the other things are just like how
8:40it's getting inputs, how to get outputs.
8:42We'll look at this SOP first.
8:45So, SOP define the step of the agent
8:48execution.
8:53And if you look at this SOP, it's
8:57associated with two uh steps. One is
9:00agent delegation and one is skill uh
9:02invocation. For skill, it's okay to
9:04invoke human intervene intervene and
9:06then for delegation, it can delegate to
9:08this project name agent. So, this also
9:10agent is a permission.
9:11This means that if you are equipped with
9:14this um skill and you are your role
9:15indeed have the permission, and that's
9:17where we assign this to role. If your
9:19role have the permission to use this
9:20skill and you are as a agent, you are
9:22actually um
9:23equipped with this skill or SOP, then
9:27you can
9:28get access or you can have this um
9:30skills or um steps. And then based on
9:33your workflow, you define how you going
9:35to use them. So, here the workflow is
9:37very simple. Well, first we try to use
9:39this project name agent to find the
9:40project name, but if the project ID is
9:42not provided, then you can use human
9:44intervene skill to recreate field for
9:46human intervention.
9:48So, that is where we saw that pop up and
9:49we gave the project ID.
9:52And then if you look at the look into
9:53the skill,
9:55the one that we are using is human
9:57intervene here.
10:04Human intervene is a system skill. We do
10:06have some default system skill where you
10:08can save data and you can send
10:10notification or you can get recipient
10:12group. This is where we can talk about
10:15that integration for notification. Now,
10:17these are the skill sets where the agent
10:19can use.
10:21Then in that SOP, there's another thing
10:22that is to dedicate to another agent.
10:24So, if you look at that agent,
10:27which is this name agent,
10:31and this name agent is using um
10:35the SOP for feature and save project
10:37name.
10:40So, that is the other SOP that we were
10:41using.
10:45And that SOP, we are invoking invoking
10:48other skills like get the project name
10:50and save the data as and then
10:51notification.
10:54And these skills are defined here.
10:56Get Superbase project name and the
10:57system skills.
10:59And if you look at the
11:01Get Superbase project name,
11:03there is here is where it's um calling
11:06the tool.
11:07Where do we get this tool? This tool is
11:09MCB tool.
11:11It's from Superbase MCB.
11:14That's where we need to talk about the
11:15next one, the MCB. We probably should
11:17talk about this first. So, when you need
11:19to integrate with any of the external
11:21tools, then you have to do this via MCB
11:24hub integration.
11:25This is intentionally, we don't want the
11:27agent to use any
11:29kind of self-built APIs or otherwise to
11:33invoke the
11:34third-party tools or any of your other
11:36systems
11:37because we want to put that into
11:39container security control, right? So,
11:41this is where MCP can do the best job
11:44here.
11:45Either it's an internal one or it's an
11:47external one where you can just create
11:49you can register that server. You can
11:50put the base URL and once you have the
11:52URL then you can actually put your
11:55API settings
11:56so your API tokens to create like that
11:58session to that MCP so you can use that.
12:01I'll talk about that settings but
12:02basically we get MCP we just do her here
12:05and we can talk to that MCP. And then we
12:07have the tool repository where it
12:08fetched from all these MCPs. It's
12:10showing you what available from all
12:12these MCPs.
12:13And once you have MCP and these tools
12:16are available for you to use then you
12:17can define your skill. So, when you
12:18define the skill as what we just
12:20saw there are
12:22the list of tools that's where you can
12:24select.
12:27So, here we only choose like get
12:29project. In case you want to also say
12:30okay, I want want to actually execute
12:32SQL
12:34script query. You can also choose that
12:35tool and you can confirm it.
12:38So, then these tools will be available
12:40to be used. And it's only also be the
12:42tools that only available for the agent
12:44to use. So, even that MCP indeed have
12:46many other tools but the agent won't be
12:48able to use them. They won't be able to
12:50see them and also won't be able to use
12:51them. So, security will control the
12:53permission if they don't allow the agent
12:55to use that. But even before that the
12:57agent cannot see that. If agent cannot
12:58see that then it's another layer of
13:00security that the agent won't want
13:02somehow to
13:04to to play with that or to trying to do
13:05anything that's malicious.
13:09So, this is where skill-based security
13:12is putting in place because you have
13:16skills or SOP that's associated with
13:18tools and then you control what tools it
13:19can access. So, eventually the agent
13:22equipped with necessary skills will only
13:25have access to the necessary tools.
13:28And what these things are, other tools
13:29will be available. That's That's also um
13:31resolved the MCP context window issue.
13:33Because unnecessary tools, even they are
13:34available from the MCP server, won't be
13:36able to won't be loaded into that
13:37agent's context. The agent will be able
13:39to focus or pay attention to the things
13:42that he need to pay attention to. And
13:43that is where probably that's um
13:45attention saving you want or everything
13:47you need.
13:48So, this is the second one that's the
13:49skill-based security.
13:51The next one is the role-based security.
13:54So, you can see all these skills that
13:55they need to be assigned to a role.
13:58So, we we're trying to do this thing in
14:00a way where let's say you have a skill
14:01that's previously assigned to some
14:03agents and then um you probably just in
14:05order to just for your convenience, you
14:07put like multiple skills for a
14:08particular agent associated.
14:10But then there's one day that you
14:11realize, okay, um
14:12for security reason, there's certain
14:14role that's we say shouldn't be able to
14:16use that skill.
14:17So, in that way
14:19the all agents that was having this
14:20skill loaded into their context already
14:22or somehow in their memory, especially
14:24when it's external agent, so that's
14:26become kind of like an issue for you.
14:27But the role-based security is where I
14:29say, okay,
14:30you have this skill, but it's also
14:31associated with your role.
14:33You have this role and you can use this
14:35skill. Even you know how to use this
14:36skill, but if you don't have that role,
14:37you cannot use that. So, that's the
14:39role-based security. If I untick this,
14:41then this role this skill is no longer
14:43associated to this role. And then
14:44anything that defined that um named
14:46agents, which is supposed to assume this
14:48role, will fail. Because it's assumed
14:50that this role by default it cannot
14:51actually access that skill.
14:53So, in that case, that's if I uh revoke
14:56the permission to this skill, all the
14:58agents that's with that role will also
14:59be revoked to actually access that
15:01skill. Even they know that skill, even
15:02they have that skill loaded into
15:04somewhere and persist into that
15:05somewhere, but because they get access
15:07to the real tools by MCP or
15:09communication hub, and the communication
15:11hub will make sure that the security
15:12controlling is happening there. So,
15:14that's the third level that's the
15:15role-based security. Again, to put the
15:17matter of security um control into this.
15:20The fourth one um is where we already
15:22kind of talk about this human intervene
15:24intervention, where we can put the
15:27approval into the process. You know,
15:29if you want to sign up for this
15:31for for for this workflow or for this
15:33SOP, if you want to do this and at this
15:35at this stage, I want to put the
15:36approval for that. So, then you can just
15:38simply add that into your SOP and call
15:40that human intervene skill to request
15:42for an approval. And then it will
15:46request that approval during the
15:47execution.
15:48And that's another like human individual
15:50security. So, for any so anything that
15:52can be sensitive that you might want to
15:53be be able to trigger that and make sure
15:55that the human makes some
15:56decision to either approve or reject the
15:59execution of the following steps. So,
16:01that's the next one. That's the fourth
16:03security um
16:05governance there.
16:07Then the last one, it's kind of like
16:08also to me it's also security, which is
16:10the budget security. Sometimes the usage
16:13of the tokens, especially when you are
16:15defining this for operation or
16:17repetitive activities, then you kind of
16:20want to make sure that the each time the
16:22execution is within that budget.
16:25Some sometimes what can happen is that
16:27the model can somehow go go to a very
16:30wrong way and just keep trying to
16:31calling some tools. But if it didn't get
16:33that, maybe it keep repeating, then you
16:34get issue you get like nothing returned
16:37successfully, but your token usage is
16:39keep increasing and you keep wasting
16:40your money.
16:41If you know, okay, this task normally I
16:43know that it won't be able to actually
16:45consume more than 10K tokens, then I can
16:48set a budget for that. So, this is a
16:51last security thing that we put in
16:52place, which is the
16:54guardrail. We call it guardrail here,
16:55probably should be called budget. It can
16:57be put on two different levels. First,
17:00it can be put on model level.
17:02So, in our system where we
17:04integrate with the models.
17:08So, this is where we can add we can put
17:10your API key to Digger to Open AI, and
17:13then you can get it integrated. And once
17:15you integrate that,
17:16you can actually uh
17:19choose what models you want to use.
17:26Somehow these buttons aren't working.
17:29So, when you fit models
17:31and then you can choose which model you
17:32want to use and which model you don't
17:34want to post to anyone. Then only
17:35available only to choose the one can be
17:37used. But then further than that, you
17:39can uh based on the one you choose, then
17:41you can add some budgets or gario for
17:43the usage for that model. So, you can
17:45say, "Okay, for this one per day, I want
17:47to set that you should not exceed 100k
17:50tokens." Or you can add another gario
17:52and say, "Okay, um even if met that, but
17:54um hourly basis that I want you to
17:56control that in a certain uh limit
17:58limit."
18:00So, this is on the model level.
18:02You can also do this on the agent level.
18:15So, on this agent
18:17there's execution garios where you can
18:19define
18:20like how many operations maximally you
18:21can do and how many tokens you can
18:23consume. And if you exceed that, then
18:26you will be either uh terminated. We can
18:28enforce the budget and we say it stop um
18:31and terminate that.
18:32So, that's where
18:34um another level of security for budget
18:36is putting in place and that makes sure
18:37that each of the execution won't bring
18:39you a surprise.
18:41And once it exceeding that, um we can
18:43look at that
18:45execution logs.
19:02And this is our gario and you can see
19:04the token uh is not uh because it's not
19:07configured, then it's not used uh not
19:09limited. Uh the iteration good, all
19:11these things good. And if it's exceeding
19:13the uh budget, then it will get
19:14terminated.
19:16Okay, so this is a budget control.
19:18And that's all about the first demo, the
19:20agent execution, and also the security
19:23being put under the hood. The next one I
19:25want to put is another thing, it's also
19:27about security. It's the identities.
19:29Because we also have like one concern
19:31about the security is where agent uh
19:33sometimes kind like as a delegate of the
19:35human, what kind of permission we should
19:36give to this agent? Are we treating that
19:38as like just a normal identity, or we
19:41should treat that as that user's
19:42delegate, so that user's permission will
19:44be allowed to do for the agent to do
19:47anything that the user can do.
19:49This situation can get tricky. Uh in
19:51Personal, the solution for that is that
19:53we do have dual identities system
19:55building into this. I'll show you a case
19:57here. We have like a conversational
20:00agents, we have two agents, one is agent
20:01one and one is agent two. They're pretty
20:03much same, they're using the same kind
20:05of skill or SOP. The only thing
20:06different is that the agent identity
20:08they are using
20:09are different.
20:10This one is using this test agent, and
20:12this one is using test agent two.
20:14So, let's see let's let's see let's do a
20:16demo.
20:18Let's say hello. Very simple demo, just
20:20hello world.
20:25So, you can actually see that it's using
20:26tool to say hello to the user.
20:29And it's actually also using the tool to
20:31say hello to the agent.
20:33So, the response is that to the agent is
20:35now the agent called Tom, and to the
20:36user is now the agent called admin. So,
20:39basically this is a response from MCP,
20:40and this MCP is a demo MCP, it's inside
20:43of the Personal, and you can you can
20:45find
20:46out from the
20:48MCP demo app. So, there's a folder for
20:52MCP demo app where there's
20:54initialization script where you can just
20:56sitting some testing data, so that it
20:58can create that test agent one and test
21:00agent two. And there's start
21:03um
21:06start script to start it at MCP. So,
21:08once you start that, then you can also
21:09integrate that uh in the MCP hub.
21:12But, basically, what that that MCP demo
21:14app
21:15uh do is that it's going to say hello.
21:17It's going to check the user, check the
21:18agent, and then see the agent's
21:20permission and user's permission. Say,
21:21"Okay, use Agent, do you have the
21:23permission to say hello?" And User, do
21:24you have permission to say hello?
21:26And to demonstrate that, we can trigger
21:28this one to see the difference. This one
21:30basically the same user, but different
21:32agent.
21:33So,
21:34the response will be different.
21:42Okay, you can see that to the agent, the
21:44access denied. Because that agent
21:46identity don't have necessary role, so
21:48the agent cannot be completed. I mean,
21:49that that that greeting cannot be
21:50completed. So, this is where the far end
21:53security will be put in place. So, when
21:56all the request coming to the far end
21:58system, MCP servers, then the far end
22:00implementation can make a decision to
22:02say, "Okay, always request, I know there
22:04will have two identities. One is the
22:06primary identity, which is agent
22:07identity. And another one is the user's
22:09identity, which is like secondary
22:10identity.
22:11What should I do?" It depends on the use
22:13case. Like, if the agent is doing some
22:15query on behalf of the user to call
22:17something like get my profile, or get
22:19user's profile, then I will check if
22:21that user have the permission to do
22:22that. And also, I will return only that
22:24profile for that user, because I do have
22:26that second identity in the request.
22:29But, if it's more about agent itself, do
22:31I need to do the same kind of do the
22:33same from this agent? Then, I will just
22:34check only check the agent's identity.
22:35Or, sometimes, maybe I need to combine
22:37them together. But, it will be the
22:38decision of the remote system to put
22:42that control in place.
22:43So, you can see that actually there are
22:44two layers. From our side, it's more
22:46like outbound or incoming request. Where
22:49we put control? We put enough security
22:50there to make sure that it can only send
22:52the necessary allowed request out. But,
22:55then the far end there's another
22:56security there. The MCP implementation
22:58will make sure that it validate the
22:59identity either from the user or the
23:01agent or both to complete that security
23:03check. So, that's another round. But,
23:06with the couple of that, so that's the
23:07different team and focus on what we want
23:10to do and then the remote team can focus
23:12on what you're allowed to do. And that's
23:13similar happen has since happened in
23:15your current human
23:17users, right? We can request or we think
23:19that we can do that, we can try that,
23:21but eventually it's a remote system
23:23where they configure the permission for
23:25us and to allow us to certain things.
23:26And sometimes we think that we are I
23:28mean maybe we are I mean we should do
23:29this, but we should not be the one that
23:31decide if that's the case or not. It's a
23:34far end in the remote systems I mean
23:35make a decision. You as a
23:37let's say super user or perfect power
23:39user, this is your permission. That make
23:42that more secure because they know their
23:44system, they know their security better
23:45than the local end or near end. So,
23:48okay. So, this is the two identity demo.
23:50I'll quickly talk about this agent
23:52identity. So, user is the one that you
23:54log in,
23:55but agent identity they also came from
23:57Keycloak. It can be from different
23:59identity provider, but it can be from
24:00the same identity provider. But,
24:01basically agent identities are also came
24:03from identity provider. And then you can
24:05create agent by signing to that agent.
24:08So, you will still need to
24:13go to the Keycloak. All right, but this
24:15is agent realm. So, even the same
24:16Keycloak but it's different realm. So,
24:18this part is where agent is manned. Then
24:20you can if you use of agent three, you
24:21can log in to the agent three and then
24:22that token will be then saved here and
24:26then whenever it killed it will refresh
24:27that token, but when it expired you need
24:29to re-login back again. So, this makes
24:30sure that the agent is also like a
24:32short-term short-life
24:35agents for in terms of the identity. And
24:38whenever that if you are not keep
24:39repeating the work or if somehow
24:41this this this identity has been
24:42revoked, then this agent will no longer
24:44be able to do the work.
24:47Okay, that's second demo.
24:48The last one is
24:50it it's like extension to this two
24:52identity demo, but this is where I want
24:54to show this capability to integrate
24:56with external agent. As I said, the
24:58communication hub is actually a MCP hub.
25:01So, whatever that you integrate here,
25:03then our communication hub can make this
25:06as a MCP proxy. But, the difference from
25:08compared to other MCP proxies that this
25:11MCP proxy is scale-based. It's also
25:14role-based. So, basically all the
25:15security we we put into the control will
25:17be applied here as well for the external
25:18agent. So, how the external agent can
25:20connect to this MCP hub? They need to
25:22create API keys.
25:24And the API keys
25:26are associated to the agent identity and
25:28also the agent role. So, that means that
25:30that agent and that agent role have
25:32permission to only certain skills or SOP
25:34and tools, then only these necessary
25:37associated allowed tools will be
25:39available and available for the external
25:42agent to access.
25:43I'll show you quickly
25:45in
25:46VS code. So, in VS code we have
25:48configured this
25:52API key.
25:53And when we say we restart that, you can
25:56see there are seven tools that's
25:57discovered. And if you open these
26:02and then you can see those are the ones
26:03that's been
26:05added. So, this basically are the ones
26:08that is allowed for this agent. So, this
26:11agent role. And that agent role indeed
26:13have the permission to this few of this
26:16tools based on the skill.
26:18And especially like the skill-based Git
26:19project. We know that skill-based have a
26:20lot of the tools available, but the
26:23skill only will will work one of them.
26:24So, that when you connect to this MCP,
26:26it will only get that project. It will
26:28only get that Git project tool.
26:30So, this is the what the agent can see.
26:31But, then also by the permission,
26:33there's a demo. I'm not going to demo
26:34that to that again. I'll just show you
26:36the screens the history here. So, this
26:39is the like a two times of the hello
26:40agent. And because the VS code don't
26:42really have like the dual identity
26:44mechanism that's in place. So, it will
26:46only send like the API key, which is the
26:47agent identity. So, the test is about to
26:50say hello to the agent. And then when I
26:52say hello to the agent, it will call
26:54that demo MCP to say hello agent. And
26:56for
26:57this test, it's successful. It says
26:59hello agent. And this one is failed. It
27:01say you don't have the permission to do
27:02that. This is because I used two
27:04different key two different API key. So
27:06back to the application. There's one key
27:08that I configured for the AI agent the
27:10test agent. And there's another key that
27:12I configured that for demo agents. So
27:14demo agents API key will use this
27:16identity. But this identity don't have
27:17permission. So it's get failed. But this
27:19one get successful. So this is where
27:21again this MCP hub even you don't define
27:24or sometimes you want some your own
27:26developed or
27:28self-implemented agents doing the
27:30complex job. But you want that to be
27:32also in a secure way where it talk to
27:34external worlds by control the secured
27:37hub. This is where you can use this MCP
27:40hub. You can use this identity. You can
27:41use all these kind of security
27:43infrastructure in this framework even
27:45you don't want to use the agent inside
27:46of here. Or you are just doing the
27:49more featured agents or more complex
27:51agents to integrate with this framework.
27:54So that's how you can use them as a MCP
27:56server.
27:57All right. That's all the demo I wanted
27:59to try. It's still a little bit long. I
28:01hope that this focus on the security
28:04demo can bring something interesting for
28:06the for discussion. And also there are
28:08quite some other features here which you
28:09can try to explore by yourself. Or you
28:11can look into the documents and there's
28:13another full demo that I did a while ago
28:16which is a little bit unprepared. It's
28:18not that well structured. But still here
28:20you can find some information there.
28:22All right. So thank you all for watching
28:23this demo. I wish you have a nice one.