Agent transaction capabilities shift to IT administrators
AWS, GitHub, and Cloudflare are tightening the capabilities of agentic AI tools. The focus shifts from what models can generate to who can authorize connections to existing infrastructure.
Artificial Intelligence··Morning
AgentCore Payments moves from preview to general availability
AWS moved Amazon Bedrock AgentCore Payments, which had been in preview since May, to general availability. The new service lets agents pay for APIs, Model Context Protocol endpoints, and paid web content using managed wallets and spending caps set by enterprise administrators. Credentials are centrally managed, and every agent has a predefined transaction limit and expiration time.[1]
Copilot hands plugin and MCP control to administrators
GitHub handed plugin and MCP control in its Copilot for JetBrains version from individual developers over to enterprise administrators. Enterprise administrators now determine exactly which MCP servers a developer can connect to inside the network through centralized allowlists. This prevents an agent from spontaneously connecting to an unapproved internal server or external service.[2]
Cloudflare filters agent calls that carry write permission
On the same day, Cloudflare announced that WriteGuard, a tool that filters agent calls carrying write permission at the edge before they reach the server, has entered private beta. The tool evaluates every incoming request and allows, blocks, or audits critical actions such as production deployments or bulk deletions according to policy. This approach requires no server modifications and moves authorization to the network layer rather than relying on individual developer tools.[3]