Engineering brief

How Two Sigma Tames Cloud Agents by Running Them as You

AI Engineer1 min read · saves 20 min

At a glance

Relevance
Practical value
Warnings
None

Two Sigma runs cloud agents as the user's own identity, solving permission sync but creating attribution challenges. Their solution: a header for traceability and Google's enterprise web index to avoid internet egress.

Enables secure agentic workflows in regulated enterprises without separate identity provisioning or external egress.

Summary

Two Sigma lets agents act as the user's own identity, not a separate machine identity. This avoids permission sync issues but introduces attribution challenges. Their solution: a header that propagates through every action, enabling full traceability.

To mitigate web access risks, they use Google's web grounding for enterprise, a cached index within their VPC. This eliminates egress vulnerabilities but introduces data freshness lag (24 hours, 6 for frequent sites). They block standard web tools and redirect through MCP.

The tradeoff is clear: security for freshness. For most internal use cases, the lag is acceptable. They claim no loss in expected value, but this assumes the cached index is sufficient for all agentic tasks.

The key takeaway for engineering leaders: enterprise-grade guardrails—existing namespaces, observability, and curated web indexes—can make agentic workflows safe. This approach reduces security team friction and avoids separate identity provisioning.

Watch the video

This video is blocked due to your privacy settings. To watch this video, please accept YouTube marketing cookies.

Related breakdowns

Get TL;DW

Too Long; Didn't Watch.

A concise breakdowns of the AI and devtools videos that actually matter for engineering leaders.

Free. Weekly. No hype.

Video and thumbnails remain the property of their respective creators. tldw.news provides editorial analysis, commentary, and discovery links to original content.