AI Engineer

Your company brain will leak secrets: how we stopped it for big banks — Tanmai Gopal, PromptQL

Published 2026-09-03 · Duration 26:25

Summary

The talk addresses the critical security challenge of 'Company Brains'—shared knowledge systems that risk leaking sensitive corporate secrets. The speaker proposes a secure architectural model centered on using a single companywide wiki (linked markdown files) for context storage. Key security measures include scoping read/write access per file, preventing agents from auto-writing memory, and ensuring every change is attributed to a human owner. For multi-user operations, credentials must be injected at the HTTP and SQL layers rather than stored in a sandbox.

Download summary

Key takeaways

  1. Healthy Company Brain Growth 5:41

    A healthy company brain should show a continuously increasing trend in daily updates, indicating that users are not only consuming knowledge but also teaching the system new skills (e.g., querying data $\rightarrow$ interpreting results $\rightarrow$ taking action).

  2. Secure Knowledge Contribution Model 20:33

    To prevent leakage, context must be stored in a single shared wiki (linked markdown files), and the agent should only *suggest* changes with defined scopes; a human user must accept or reject the change to assign ownership.

  3. Multi-User Security Architecture 25:00

    For collaborative tasks (e.g., incident management), credentials should never be stored in a sandbox. Instead, they must be injected per user at the HTTP and SQL layers to allow the AI agent to behave as the authenticated human.

Technical details

  • Company Brain Definition 950s

    A company brain is defined as shared context stored in a set of markdown files, coupled with granular access control rules for the data and tools available to a coding agent. It focuses on enabling agents to solve general-purpose problems, not just pulling knowledge into an LLM.

  • Data Storage Model 1233s

    The recommended model is a single companywide wiki using linked markdown files. This structure allows for granular scoping of read/write access per file, mitigating the risk of siloed data.

  • Security Principles (Rules) 1300s

    1) All context must reside in one companywide wiki. 2) Every change must be backed by a human's name/ownership to ensure accountability and traceability.

  • Credential Handling 1485s

    To maintain security during shared AI use, credentials must be injected at the HTTP layer and the SQL layer, rather than being stored in a sandbox environment.

Mentioned resources

  • PromptQL (Company/Product)
  • Hasura GraphQL engine (Open Source Project)

Channel & topics

Watch on YouTube · Back to latest

This independent, AI-assisted summary is provided for commentary and informational purposes. It may contain errors or omit important context. Please watch the original video for the creator's complete presentation. Video, thumbnail, and related copyrights belong to their respective owners.