NoticiasNews

JetStream Clearance autoriza cada acción del agente antes de ejecutarla: el log deja de ser el control y pasa a ser el reciboJetStream Clearance Authorizes Each Agent Action Before It Runs: The Log Stops Being the Control and Becomes the Receipt

2026-09-04

JetStream Security anunció esta semana JetStream Clearance, descrito como un motor de razonamiento de confianza cero para IA. Su función es sencilla de enunciar y difícil de implementar: examinar cada solicitud que pasa por el AI Gateway de JetStream y decidir, en vuelo y antes de la ejecución, si esa acción está autorizada.

Qué evalúa exactamente

Según la compañía, Clearance mapea cada solicitud contra cuatro elementos: el agente o usuario que la origina, el diseño aprobado que autoriza esa solicitud, la herramienta o herramientas que se invocan, y qué va a hacer concretamente esa llamada. El razonamiento ocurre en el momento del tráfico, no después en un registro.

El punto técnico más relevante es que evalúa secuencias de acciones y no llamadas aisladas. Una consulta a una base de datos es inofensiva. Adjuntar el resultado a un archivo es inofensivo. Enviarlo a una dirección externa es inofensivo. Las tres en ese orden son un patrón de exfiltración, y ningún control que mire llamada por llamada lo va a ver.

Por qué esto importa más allá del vendedor

La industria pasó dos años construyendo observabilidad para agentes: trazas, registros, paneles. Todo eso responde la pregunta de qué pasó. Ninguna de esas herramientas responde la pregunta de si debía pasar. Cuando un agente tiene credenciales para tocar sistemas de producción, la distancia entre esas dos preguntas se mide en minutos y en datos filtrados.

  • Auditoría posterior: sirve para explicar el incidente y para cumplir con el regulador. No lo evita.
  • Autorización previa: puede detener una secuencia a mitad de camino, sea maliciosa o simplemente un agente mal configurado.
  • Costo del enfoque: hay que medir cuántos trabajos legítimos y de larga duración quedan pausados por el control, porque romper acuerdos de nivel de servicio por exceso de celo también es un fallo.

JetStream está mostrando Clearance en Fal.Con y aparece en la nueva Especialización de Socios de IA que CrowdStrike lanzó en ese mismo evento, lo que indica que el control por acción está dejando de ser una idea de nicho para volverse parte del catálogo de seguridad empresarial.

Qué revisar si usted opera agentes hoy

  • Mapear los flujos de varios pasos con mayor riesgo: consulta, adjunto, envío. Ahí es donde una compuerta por acción cambia el resultado.
  • Verificar si sus agentes corren con credenciales de un usuario humano. Si es así, no hay forma de distinguir en el registro qué hizo la persona y qué hizo el agente.
  • Definir qué pasa cuando el control bloquea: si no hay una ruta de excepción con aprobación humana, el equipo va a desactivar el control.

La conexión con el cumplimiento

Para una entidad regulada, esto no es solo seguridad informática. Un supervisor que pregunta por qué un sistema automatizado accedió a determinado expediente no se conforma con un registro: quiere saber bajo qué autorización ocurrió. La autorización previa produce esa respuesta por diseño; la auditoría posterior la produce por reconstrucción.

En TEKFENIX trabajamos ese principio en CumplimientoControl, donde el monitoreo de medios adversos y la trazabilidad regulatoria se construyen sobre la premisa de que cada consulta y cada acción automatizada deben tener un permiso explícito y verificable detrás. Y en Servigo365, cuando un agente de IA resuelve un caso de soporte, la acción queda acotada a lo que ese agente tenía autorizado hacer, no a lo que el modelo consideró razonable en el momento. Para empresas del Caribe y Latinoamérica que empiezan a dar herramientas reales a sus agentes, esa distinción va a definir cuáles proyectos sobreviven a la primera auditoría.

JetStream Security this week announced JetStream Clearance, described as an AI zero trust reasoning engine. Its function is simple to state and hard to implement: examine every request passing through the JetStream AI Gateway and decide, in flight and ahead of execution, whether that action is authorized.

What it actually evaluates

According to the company, Clearance maps each request against four elements: the agent or user making it, the approved design that authorizes the request, the tool or tools being invoked, and what that specific call is about to do. The reasoning happens at traffic time, not afterward in a log.

The most relevant technical point is that it evaluates action sequences rather than isolated calls. A database query is harmless. Attaching the result to a file is harmless. Sending it to an external address is harmless. All three in that order form an exfiltration pattern, and no control that looks call by call will catch it.

Why this matters beyond the vendor

The industry spent two years building observability for agents: traces, logs, dashboards. All of that answers the question of what happened. None of it answers whether it should have happened. When an agent holds credentials to touch production systems, the distance between those two questions is measured in minutes and in leaked data.

  • Post-hoc auditing: useful to explain the incident and satisfy the regulator. It does not prevent it.
  • Pre-execution authorization: can stop a sequence mid-way, whether malicious or simply a misconfigured agent.
  • Cost of the approach: you must measure how many legitimate long-running jobs get paused by the control, because breaking service level agreements through excess caution is also a failure.

JetStream is demonstrating Clearance at Fal.Con and is named in the new AI Partner Specialization CrowdStrike launched at that same event, signaling that per-action control is moving from niche idea to part of the enterprise security catalog.

What to review if you run agents today

  • Map the highest-risk multi-step flows: query, attachment, send. That is where a per-action gate changes the outcome.
  • Check whether your agents run under a human user’s credentials. If so, there is no way to distinguish in the log what the person did from what the agent did.
  • Define what happens when the control blocks: without an exception path with human approval, the team will disable the control.

The compliance connection

For a regulated entity, this is not just information security. A supervisor asking why an automated system accessed a particular file will not settle for a log: they want to know under what authorization it happened. Pre-execution authorization produces that answer by design; post-hoc auditing produces it by reconstruction.

At TEKFENIX we apply that principle in CumplimientoControl, where adverse media monitoring and regulatory traceability are built on the premise that every query and every automated action must have an explicit, verifiable permission behind it. And in Servigo365, when an AI agent resolves a support case, the action stays bounded by what that agent was authorized to do, not by what the model deemed reasonable at the time. For companies across the Caribbean and Latin America starting to give their agents real tools, that distinction will decide which projects survive the first audit.

← Volver al blog← Back to blog