NOIR
Guides

Security model

Protect credentials, authorize exact effects, isolate tenants, verify providers, and treat every model-facing value as untrusted.

Noir provides enforcement points; your application defines authority. Self-hosting removes a third-party control plane but does not remove the need for least privilege and isolation.

Trust boundaries

Treat all of these as untrusted:

  • webhook bodies before signature verification
  • user messages, files, and URLs
  • model arguments and final text
  • MCP and OpenAPI responses
  • repository files and web research
  • sandbox stdout, generated files, and status claims

Validate at the boundary where a value becomes executable or user-visible.

Credentials

Use provider-native clients and environment or secret-manager injection. Prefer restricted API keys. Do not put keys in prompts, model tools, memory facts, logs, repository files, or sandbox environments by default. Rotate any credential pasted into chat or committed to source.

Authorization

Verify exact stable IDs: installation, actor, connection, repository, account, operation, and resource. Prompt text can describe policy but cannot enforce it. Use connector callbacks and capability hooks to reject unauthorized work before the external call.

Tool safety

Declare effect, approval, and retry separately. Require requester approval for consequential writes and external messages. Keep destructive actions narrower than broad provider SDK methods. Use stable idempotency keys for retried writes.

Network and files

Use safe HTTP utilities for URL parsing, DNS/IP restrictions, redirect limits, timeouts, byte caps, and content-type checks. Attachment resolvers should only fetch signed provider references from the current message. Sandbox paths must stay inside the scoped root and must not follow an escape through symlinks.

Data isolation

Namespace memory, sandbox, connections, secrets, schedules, and tasks by verified owner identity. Test cross-tenant denial. Project tool results before giving them to the model, removing raw provider IDs, storage pointers, secrets, internal hashes, and fields whose names can be misread.

Incident readiness

Record authorization denials, repeated tool failures, approval outcomes, delivery failures, and unusual usage without storing sensitive payloads. Keep an operator path to pause schedules, cancel tasks, revoke connections, rotate keys, and roll back an agent version.

On this page