AI Control Layer Architecture
Visual explanation of the 4 interception channels, hybrid defense pipeline (sub-15ms deterministic fast-path + internal organization AI guard), and fail-closed tool governance.
1. End-to-End Architecture & 4 Interception Channels
Mermaid Diagram
flowchart TD
classDef client fill:#FFFFFF,stroke:#ACC5A6,stroke-width:1.5px;
classDef ch fill:#EFF6FF,stroke:#1A73E8,stroke-width:1.5px,color:#1E40AF;
classDef t1 fill:#F0FDF4,stroke:#10B981,stroke-width:1.5px,color:#065F46;
classDef t2 fill:#FAF5FF,stroke:#9333EA,stroke-width:1.5px,color:#581C87;
classDef block fill:#FEE2E2,stroke:#EF4444,stroke-width:1.5px,color:#991B1B;
classDef core fill:#E8EFE7,stroke:#5C7057,stroke-width:1.5px,color:#3C4043;
classDef db fill:#FEF3C7,stroke:#F59E0B,stroke-width:1.5px,color:#92400E;
User["π» Client / App
(Prompt + Files + Role)"]:::client Ch1["π‘οΈ Channel 1: App-to-Agent
Pre-Flight DLP & Budget Cap"]:::ch subgraph Defense ["Hybrid Defense Pipeline (src/defense/mod.rs)"] T1["β‘ Tier 1: Fast Deterministic
Regex Secrets + FastEmbed Vectors
(<15ms | $0 AI Spend)"]:::t1 T2["π§ Tier 2: Semantic AI Guard
Internal Organization AI Model
(Contextual Evaluation)"]:::t2 end BlockT1["π Fast-Path Short-Circuit
0 AI Tokens ($0 Cost) | <15ms"]:::block BlockT2["β Blocked by Internal AI Guard
Aborts Downstream Agent Loop"]:::block AuditSink["π¨ SecOps Audit Trail
(tasks / tool_calls in SQLite)"]:::block Catalog["βοΈ SQLite Catalog (catalog.db)
Hot-Reloads Live Every Request"]:::db AgentCore["π€ Agent Runtime & Loop Mitigator
Max 6 Rounds | Persistent State"]:::core Ch2["π Channel 2: Agent-to-Agent
Sub-Agent Privilege Boundaries"]:::ch ToolGate["π‘οΈ Channel 3: Agent-to-MCP Tool Gate
Path Norm → Blacklist → DLP → Whitelist → HITL"]:::ch MCPServers["ποΈ MCP Tools (SQLite confidential.db)
+ Tool Output Redaction"]:::core ModelGW["π Channel 4: Agent-to-Model Gateway
Internal vs External Isolation & Metering"]:::ch LLMs["βοΈ Models (Internal Org Models / External Cloud)"]:::core User --> Ch1 Ch1 --> T1 T1 -- "Violation (<15ms)" --> BlockT1 BlockT1 --> AuditSink T1 -- "Pass (<15ms)" --> T2 T2 -- "Malicious" --> BlockT2 BlockT2 --> AuditSink T2 -- "Cleared" --> AgentCore Catalog -. "Hot-Reload Rules" .-> Ch1 Catalog -. "Patterns" .-> T1 Catalog -. "Prompts" .-> T2 Catalog -. "Tool Rules" .-> ToolGate AgentCore <--> Ch2 AgentCore --> ToolGate ToolGate --> MCPServers MCPServers --> AgentCore AgentCore --> ModelGW ModelGW --> LLMs
(Prompt + Files + Role)"]:::client Ch1["π‘οΈ Channel 1: App-to-Agent
Pre-Flight DLP & Budget Cap"]:::ch subgraph Defense ["Hybrid Defense Pipeline (src/defense/mod.rs)"] T1["β‘ Tier 1: Fast Deterministic
Regex Secrets + FastEmbed Vectors
(<15ms | $0 AI Spend)"]:::t1 T2["π§ Tier 2: Semantic AI Guard
Internal Organization AI Model
(Contextual Evaluation)"]:::t2 end BlockT1["π Fast-Path Short-Circuit
0 AI Tokens ($0 Cost) | <15ms"]:::block BlockT2["β Blocked by Internal AI Guard
Aborts Downstream Agent Loop"]:::block AuditSink["π¨ SecOps Audit Trail
(tasks / tool_calls in SQLite)"]:::block Catalog["βοΈ SQLite Catalog (catalog.db)
Hot-Reloads Live Every Request"]:::db AgentCore["π€ Agent Runtime & Loop Mitigator
Max 6 Rounds | Persistent State"]:::core Ch2["π Channel 2: Agent-to-Agent
Sub-Agent Privilege Boundaries"]:::ch ToolGate["π‘οΈ Channel 3: Agent-to-MCP Tool Gate
Path Norm → Blacklist → DLP → Whitelist → HITL"]:::ch MCPServers["ποΈ MCP Tools (SQLite confidential.db)
+ Tool Output Redaction"]:::core ModelGW["π Channel 4: Agent-to-Model Gateway
Internal vs External Isolation & Metering"]:::ch LLMs["βοΈ Models (Internal Org Models / External Cloud)"]:::core User --> Ch1 Ch1 --> T1 T1 -- "Violation (<15ms)" --> BlockT1 BlockT1 --> AuditSink T1 -- "Pass (<15ms)" --> T2 T2 -- "Malicious" --> BlockT2 BlockT2 --> AuditSink T2 -- "Cleared" --> AgentCore Catalog -. "Hot-Reload Rules" .-> Ch1 Catalog -. "Patterns" .-> T1 Catalog -. "Prompts" .-> T2 Catalog -. "Tool Rules" .-> ToolGate AgentCore <--> Ch2 AgentCore --> ToolGate ToolGate --> MCPServers MCPServers --> AgentCore AgentCore --> ModelGW ModelGW --> LLMs
How it Works
The gateway acts as an inline proxy intercepting traffic across 4 distinct AI interaction channels:
- Channel 1 (App-to-Agent): Evaluates user budget balance, scans attachment text for DLP leaks, and runs the hybrid defense pipeline before execution.
- Channel 2 (Agent-to-Agent): Bounds agent-to-agent recursion with
MAX_TOOL_ROUNDS = 6to eliminate runaway execution loops. - Channel 3 (Agent-to-MCP): Inspects every tool call before running, blocking traversal and blacklisted tools, escalating gray-zone calls to human review.
- Channel 4 (Agent-to-Model): Enforces strict data perimeter isolation (confidential data only sent to internal organization AI models, never to external cloud APIs).
Challenge Criteria Covered
- Section 1 & 2 (Interception Architecture): Lightweight proxy covering App-to-Agent, Agent-to-Agent, Agent-to-MCP, Agent-to-Model.
- Section 4.1 (Centralized Policy Engine): Single source of truth in SQLite (
catalog.db) with dynamic hot-reloading (0s restart). - Code References:
src/policy.rs,src/executor.rs,src/defense/tool_gate.rs.