In this briefing
  1. 01Putting judgement and execution into defined workflows
  2. 02Checking model and business API requests at the entry point
  3. 03Data actions remain subject to requester permissions and human approval
  4. What to watch next
  5. Sources and verification
Key points
  1. LittleHorse announced that Saddle Command Center 1.3 is available, adding Agent creation, prebuilt task workers and a JavaScript SDK. The company described to a media outlet an approach in which the workflow executes actions while the Agent makes judgements.
  2. Fastly announced the availability of AI Runtime Control, AI Firewall and new API Security capabilities. They cover the entry point for model calls, prompt-injection protection and checks on the API contracts for requests made by Agents.
  3. BigID introduced AgentIQ, saying that Agents can investigate and act on data through API and MCP under the requesting user’s permissions. Human approval can be configured for actions such as revoking access, quarantining data and deleting records.
Signal 01

Putting judgement and execution into defined workflows

On 21 September, LittleHorse announced that Saddle Command Center 1.3 was available. Its release lists Agent creation, prebuilt task workers, a JavaScript SDK and a free serverless trial. The product is positioned to bring Agents, microservices and events into business workflows that span systems. This is product-launch information. The customer-outcome statements in the release have no supporting independent test data.

After interviewing the company on the same day, SiliconANGLE added a more specific account of how execution is divided. Under what LittleHorse calls the decision worker model, an Agent uses read-only tools for steps that require judgement. Deterministic workflow code then validates the Agent’s output and executes the action. The report also describes records of tool calls and debugging stack information. Business errors are handled by workflow rules, while technical errors such as network failures can be retried according to policy. These details come from the company’s account; they are not independent media measurements of reliability.

What this may mean for enterprise adoption

For an enterprise connecting several existing business systems, separating uncertain judgement from the final write action may make workflow versions, error handling and lines of responsibility easier to inspect. That assessment depends on the workflow actually covering the target systems and approval points. The available sources provide no cross-industry comparison of failure rates, recovery times or costs.

Signal 02

Checking model and business API requests at the entry point

On 21 September, Fastly announced that AI Runtime Control, AI Firewall and new API Security capabilities were available. Its announcement says AI Runtime Control can route calls to public or self-hosted models through a common entry point, protect the underlying model providers’ credentials with virtual keys, and give visibility into or control over token spending, rate limits, budgets and failover. These are Fastly product descriptions and cannot establish that every model provider will show the same behaviour in a particular deployment.

The same announcement positions AI Firewall to detect and block prompt injection on the request path. It positions API Security to check, service by service, whether an Agent’s requests to enterprise APIs conform to defined API contracts, with observe or block modes. The announcement provides no independent test across every form of attack. It also does not establish that a structurally valid API request carries the right business authorisation.

What this may mean for enterprise adoption

When an Agent operates an existing system through an API, the routing policy for model requests and the rules for calls to a business interface can serve as two distinct checkpoints. An API contract can constrain the form of a request, but existing identity controls, data permissions and business approvals still determine whether the action is allowed. The vendor’s published feature scope cannot replace checks of false blocking and performance in a specific environment.

Signal 03

Data actions remain subject to requester permissions and human approval

On 21 September, BigID introduced AgentIQ, saying it can be used within BigID or through Claude, Copilot, ChatGPT, Gemini and enterprises’ own Agents. Its official blog describes data discovery, access investigation, risk prioritisation, reporting and remediation as work that can be linked together. Agents call existing data-security capabilities through API, MCP and tools. The blog describes the vendor’s product capabilities; it provides no published cross-platform comparison from field deployments.

BigID further says that an Agent inherits the initiating user’s permissions. Those permissions are enforced at the API and MCP layers, and actions are recorded and attributable. Revoking access, quarantining data and deleting records can require human approval. The word “can” depends on workflow configuration: it does not mean that every high-risk action passes through human review by default.

What this may mean for enterprise adoption

For enterprise processes involving sensitive data, the ability to carry the requester’s identity, data context and approval record through to execution affects how an Agent action can be audited. BigID, Fastly and LittleHorse each describe controls at the data, interface and workflow layers respectively. The public material does not say that these three products already interoperate, and it offers no shared measurement from a production environment.

Verification

Sources and verification

  1. Meet AgentIQ: Run Your Entire Data & AI Program From a PromptBigID / Sarah Hospelhorn · 2026-09-21 · Official announcement

Golden Data has edited this briefing from the public materials listed above. The original sources govern facts and figures. The enterprise relevance sections are Golden Data editorial analysis and do not constitute an endorsement of any third-party product.

← Back to AI Daily Briefing