Research investigation R0912 / comparison

When an Agent-Security Gate Is Unsure: Block, Ask, or Allow-and-Log?

“Pre-execution security” is not a standardized product capability. In this bounded public-evidence review, inspection, workflow approval, runtime authorization, and execution environments are distinct controls with different documented defaults and boundaries.

Archived snapshotv1Sep 18, 2026
Verified observations
15

12 measured fields

Supported claims
12

12 material findings

Cited sources
10

10 primary or authoritative

Research score
87

Automated topic and evidence score

Interactive figureWhen an Agent-Security Gate Is Unsure: Block,...
CSV JSON
Data status0.6 verified records across 1 period

Snapshot only. There is not enough history to claim a trend yet.

Verified observationHover or focus any mark for exact valuesLast updated Sep 18, 2026

Version ledger

Frozen public editions

Each edition preserves the records, method, sources, and downloads available at publication time.

  1. v1 / latestSep 18, 202615 records / 10 sources

    Initial public snapshot with 15 records and 10 cited sources.

Coverage note

The matrix supports product-level comparisons, but the products address different layers: tool-call inspection, coding-workflow governance, hosted MCP authorization, CRM write approval, and agent orchestration with selectable environments. The findings should not be read as equivalent security testing or a measure of real-world effectiveness.

Dataset ID
spd:when-an-agent-security-gate-is-unsure-block-ask-or-allow-and-log-d7323ba8
Stable URL
/research/when-an-agent-security-gate-is-unsure-block-ask-or-allow-and-log-d7323ba8
Version
v1
Coverage
2026-09-12
Records
15
Fields
7
Updated

Read the data

The records behind the figure

CSV JSON
When an Agent-Security Gate Is Unsure: Block, Ask, or Allow-and-Log? data records
EntityMetricValueUnitObservedSourceTransform
Noodle Seedapproval_channel_failure_defaultFail closed with interaction_unavailable when elicitation is unavailable and trusted host fallback is not configured.2026-09-12https://docs.noodleseed.dev/docs/guides/customer-auth
Noodle Seedapproval_defaultDirect execution unless confirm:true is explicitly configured.2026-09-12https://docs.noodleseed.dev/docs/guides/embedded-assistant
Mastra Factoryapproval_semanticsRecorded task acceptance, plan approval, separate stage-transition approval, and normal repository merge approval.2026-09-12https://factory.mastra.ai/using/work-and-approvals
Noodle Seedapproval_semanticsOne exact server-held connector operation, reverified before one execution; accept releases it, decline/cancel stops it.2026-09-12https://docs.noodleseed.dev/docs/guides/embedded-assistant
Mastra Factoryaudit_recordSession conversation, decisions, commands, tool output, files, changes, errors, checks, and linked PR output; retention/export unspecified.2026-09-12https://factory.mastra.ai/using/sessions
Noodle Seedaudit_recordScalar request metadata, per-request stream, chronological session replay, governance-event query, and JSON output; no raw bodies or arguments/results.2026-09-12https://docs.noodleseed.dev/docs/guides/analytics
Mastra Factoryautomation_or_bypass_pathAuto-start eligible runs and auto-approve submit_plan requests; custom boards and rules can change workflow.2026-09-12https://factory.mastra.ai/using/work-and-approvals
Noodle Seedbypass_or_override_pathExplicit confirmationFallback:'host' trusts the MCP host to have collected approval; omitted confirm also permits direct execution.2026-09-12https://docs.noodleseed.dev/docs/guides/customer-auth
Mastra Factoryenforcement_pointTask acceptance, plan requests, board transitions, and repository merge workflow.2026-09-12https://factory.mastra.ai/using/work-and-approvals
Noodle Seedenforcement_pointAuthentication and per-tool authorization occur before arguments or fulfilment; confirmation occurs before the exact connector operation.2026-09-12https://docs.noodleseed.dev/docs/guides/customer-auth
Mastra Factoryexecution_boundaryCloud providers can supply VM isolation; LocalSandbox runs commands on the Factory server machine.2026-09-12https://factory.mastra.ai/configure/sandboxes
Bounded sampleproducts_documenting_approval_granularity3 of 5: Mastra Factory, Noodle Seed, Relaticleshare2026-09-12https://factory.mastra.ai/using/work-and-approvalsCounted products specifying what exact unit an approval authorizes and divided by the fixed five-product sample.
Bounded sampleproducts_with_programmatically_retrievable_action_or_request_record2 of 5: Noodle Seed and OpenAI Agents APIshare2026-09-12https://docs.noodleseed.dev/docs/guides/analyticsCounted products documenting JSON/API retrieval of action or request records and divided by the fixed five-product sample; this does not assert that either record is a complete compliance audit log.
Noodle Seedresponsibility_boundaryApp developer owns authorization server and token issuance; Noodle verifies tokens and runs tools; client owns discovery, sign-in, refresh, and calls.2026-09-12https://docs.noodleseed.dev/docs/guides/customer-auth
Mastra Factoryuncertainty_defaultUnspecified; sessions may ask questions when context is missing.2026-09-12https://factory.mastra.ai/using/sessions

Measurement technique

How to read this report

  1. 01Evidence matrix plan: normalize each product’s public records into enforcement point, uncertainty default, approval unit, automation or bypass path, audit record, execution or responsibility boundary, and documented action surface.
  2. 02Treat non-disclosure as unspecified, not as evidence of an unsafe default.
  3. 03Separate policy-judgment uncertainty from approval-channel failure, workflow approval, and ordinary authorization failure.
  4. 04Use only the fixed five-product sample and publicly accessible vendor documentation, repositories, launch pages, and vendor-authored launch responses reviewed through September 12, 2026.
  5. 05No product execution was performed; recovering saved evidence was not a new collection or experiment.
Next report / 01AI Model Economics Index All research reports