Research investigation R0912 / comparison
When an Agent-Security Gate Is Unsure: Block, Ask, or Allow-and-Log?
“Pre-execution security” is not a standardized product capability. In this bounded public-evidence review, inspection, workflow approval, runtime authorization, and execution environments are distinct controls with different documented defaults and boundaries.
Snapshot only. There is not enough history to claim a trend yet.
Version ledger
Frozen public editions
Each edition preserves the records, method, sources, and downloads available at publication time.
The matrix supports product-level comparisons, but the products address different layers: tool-call inspection, coding-workflow governance, hosted MCP authorization, CRM write approval, and agent orchestration with selectable environments. The findings should not be read as equivalent security testing or a measure of real-world effectiveness.
- Dataset ID
- spd:when-an-agent-security-gate-is-unsure-block-ask-or-allow-and-log-d7323ba8
- Stable URL
- /research/when-an-agent-security-gate-is-unsure-block-ask-or-allow-and-log-d7323ba8
- Version
- v1
- Coverage
- 2026-09-12
- Records
- 15
- Fields
- 7
- Updated
Measurement technique
How to read this report
- 01Evidence matrix plan: normalize each product’s public records into enforcement point, uncertainty default, approval unit, automation or bypass path, audit record, execution or responsibility boundary, and documented action surface.
- 02Treat non-disclosure as unspecified, not as evidence of an unsafe default.
- 03Separate policy-judgment uncertainty from approval-channel failure, workflow approval, and ordinary authorization failure.
- 04Use only the fixed five-product sample and publicly accessible vendor documentation, repositories, launch pages, and vendor-authored launch responses reviewed through September 12, 2026.
- 05No product execution was performed; recovering saved evidence was not a new collection or experiment.
Sources
Evidence
2 publishers supporting 15 records. Expand a publisher to inspect its cited pages.