Agent boundaries
Who may invoke the agent, which tools it may call, what it can read or change, and where human approval is required.
Storrow Labs · Labs · Updated July 2026
We prototype new agent frameworks, models, and deployment patterns against real operating requirements: data access, permission boundaries, tool execution, evaluation, observability, human review, and recovery.
OpenClaw · Hermes Agent · Thinking Machines · Open models · Sandboxed agents · Evaluation
Systems under evaluation include OpenClaw, Hermes Agent, and models and tooling from Thinking Machines. A Labs prototype is not automatically a production recommendation. Technologies move into client environments only when their operating and security characteristics fit the approved use case.
Who may invoke the agent, which tools it may call, what it can read or change, and where human approval is required.
Identity, secrets, network access, sandboxing, tenant boundaries, logging, rollback, and the difference between a prototype and a production environment.
Test representative work for quality, failure modes, prompt injection, data exposure, operating cost, latency, and recoverability.
We will define the operating boundary before selecting the technology.