Gabriel L. Manor - Permit.io Blog Authors
Gabriel L. Manor
Full-Stack Software Technical Leader | Security, JavaScript, DevRel, OPA | Writer and Public Speaker
Gabriel's latest articles
- Gabriel L. Manor
Jul 28 2026
Read-Only Is a Trust Level, Not a Feeling: How to Govern AI Ops Agents Before They Remediate Production
AI incident-response agents should not inherit remediation authority by default. This guide defines a practical trust-level taxonomy for MCP tool calls, shows where policy step-up approvals are required, and explains what enterprise audit trails must capture before any production mutation.
Read more](/content/blog/read-only-trust-level-ai-ops-agents/index.html) - Gabriel L. Manor
Jul 22 2026
Agent-Generated APIs Need Governance Before They Become Agent-Callable Tools
Coding agents can generate OpenAPI specs faster than most governance programs can review them. This article explains how to connect design-time API governance to runtime MCP tool authorization with policy decisions, constrained credentials, and audit receipts.
Read more](/content/blog/agent-generated-apis-governance-before-mcp-tools/index.html) - Gabriel L. Manor
Jul 08 2026
Can AI Generate Authorization Policy Safely?
LLMs can draft authorization policy, but safe policy authoring for AI agents still depends on explicit intent, verifier-guided synthesis, and runtime PDP decisions on real tool calls.
Read more](/content/blog/can-ai-generate-authorization-policy-safely/index.html) - Gabriel L. Manor
Jul 05 2026
Payment Is Not Permission: How to Authorize Paid MCP Tool Calls
Cloudflare's x402 and paid MCP tooling make agentic payments real, but payment proof is not runtime permission. This guide explains spend authorization, consent tiers, and audit requirements for paid tool calls.
Read more](/content/blog/payment-is-not-permission-authorize-paid-mcp-tool-calls/index.html) - Gabriel L. Manor
May 24 2026
What the NSA Agentic AI Advisory Actually Requires
In April 2026, the NSA published 'Careful Adoption of Agentic AI Services' — the first intelligence-community advisory specifically targeting AI agent authorization failures. Here is what it actually demands and why most engineering teams are not close to meeting it.
Read more](/content/blog/nsa-agentic-ai-authorization-2026/index.html) - Gabriel L. Manor
May 20 2026
Zero Standing Privileges: What It Is, How to Implement It, and Why AI Agents Need It
Zero Standing Privileges (ZSP) means no identity holds usable access between tasks. This article explains how ZSP differs from least privilege, how to implement it with ephemeral credentials and runtime policy enforcement, and why AI agents running on MCP make standing access a new category of operational risk.
Read more](/content/blog/zero-standing-privileges/index.html) - Gabriel L. Manor
May 14 2026
Securing Coding Agents: What You Need to Know
Coding agents execute code, run commands, and call APIs — not just generate text. This guide covers the real security risks, why authorization must happen at the tool-call level, and how Permit.io and the Permit MCP Gateway enforce least-privilege access for agentic workflows.
Read more](/content/blog/securing-coding-agents-what-you-need-to-know/index.html) - Gabriel L. Manor
Jun 05 2025
Human-in-the-Loop for AI Agents: Best Practices, Frameworks, Use Cases, and Demo
Learn how to safely integrate AI agents with human-in-the-loop (HITL) workflows. Explore best practices, frameworks, real-world use cases, and a live demo.
Read more](/content/blog/human-in-the-loop-for-ai-agents-best-practices-frameworks-use-cases-and-demo/index.html) - Gabriel L. Manor
May 29 2025
Implementing Fine-Grained Nuxt Authorization
Learn how to implement Attribute-Based Access Control (ABAC) and Relationship-Based Access Control (ReBAC) in a Nuxt application. This guide covers defining policies, syncing user data, and enforcing permissions in a scalable way.
Read more](/content/blog/implementing-fine-grained-nuxt-authorization/index.html) - Gabriel L. Manor
May 27 2025
Prisma ORM Data Filtering with ReBAC
Learn how to implement Prisma ORM data filtering using ReBAC (Relationship-Based Access Control) to control which database records each user can access, without manual filtering logic.
Read more](/content/blog/prisma-orm-data-filtering-with-rebac/index.html) - Gabriel L. Manor
May 20 2025
Delegating AI Permissions to Human Users with Permit.io’s Access Request MCP
Learn how to build secure, human-in-the-loop AI agents using Permit.io’s Access Request MCP, LangGraph, and LangChain MCP Adapters. Enable AI agents to request access and delegate sensitive permissions to human users for policy-backed decision-making.
Read more](/content/blog/delegating-ai-permissions-to-human-users-with-permitios-access-request-mcp/index.html) - Gabriel L. Manor
May 12 2025
Implementing Multi-Tenant RBAC in Nuxt.js
Learn how to integrate Role-Based Access Control (RBAC) in a multi-tenant Nuxt.js application with continuous user syncing using Permit.io. This guide walks through defining roles, enforcing permissions, and managing access dynamically.
Read more](/content/blog/implementing-multi-tenant-rbac-in-nuxtjs/index.html)