Hacker Newsnew | past | comments | ask | show | jobs | submit | fpierfed's commentslogin

Nice project! Quick question: how do you handle LLM access control in practice? For example, can different steps in a workflow run under different credentials or provider accounts, and is that enforced centrally by AxonFlow or delegated to the underlying orchestrator? Thanks!

Thanks. In practice, access control is enforced centrally by AxonFlow, not delegated to the orchestrator.

Each LLM or tool call is evaluated at execution time against the active policy context, which includes the user, workflow, step, and tenant. That allows different steps in the same workflow to run under different credentials, providers, or cost and permission constraints if needed.

In gateway mode, the orchestrator still issues the call, but AxonFlow pre-authorizes it and records the decision so the policy is enforced consistently. In proxy mode, AxonFlow holds and applies the credentials itself and routes the call to the appropriate provider.

The key point is that credentials and access rules are defined once and enforced centrally, while orchestration logic remains separate.


What kind of latency does this generate? I guess for LLM operations the extra latency might not bet that important. Is that correct?

Good question. The overhead is designed to be low enough for inline enforcement. For the fast, rule based checks we typically see single digit millisecond evaluation time, and in gateway mode the end to end pre check usually adds around 10 to 15 ms.

You’re right that relative to an LLM call this is usually negligible, but we still treat it seriously because policy checks also sit in front of tool calls and other non LLM operations where latency matters more. That’s why the static checks are compiled and cached and the gateway path is kept tight.

If you want more detail, I have a longer architecture walkthrough that goes into the execution path and performance model: https://youtu.be/hvJMs3oJOEc


Understood. Pretty cool, good luck with the project!

Here’s why you should be scared: CEO of health care company pardoned by Trump



+1 as well: 2M LOC codebase with little to no tests and a lot of lost knowledge due to disbanded teams, people moving on etc. In my experience very common state of affairs honestly.


Indeed and fiber cables are used to sense distant earthquakes as well. They are a very good sensor network.


Promotions are an employee retention tool. In a hot market, they come by easily. In a cool market, they are harder to get. Outside of your company they might mean very little. If you get a higher salary, good for you :-)


For my wife the wait period was 8 days and the bill was 300 Euro (cancer). We live in the Netherlands.


Amsterdam, Ziggo cable 300 Mbps down 30 mbps up for 26 Eur/mo for 12 months, then 53 Eur/mo


Is that on a business contract or private / consumer one?


These are the places where the person sitting next to you and doing pretty much the same job as you could be making half of what you are making simply because you have a CERN contract and they work for a contractor.


I tried in Italian. Speech to text is impressive: kudos. The conversation was definitely weird and very repetitive. It needs more work I think. In any case, great idea and I am sure that you will soon enough get a fantastic product out.


sei italiano? pensato che la conversazione era buona ma io ho solo studiato l'italiano da 6 mesi.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: