Skip to lesson
Exit
Advanced agent configuration & MCP1 / 2

1 min lesson

Maturity path: autonomy is earned

Explain your answer to "Why must a SOX pilot start at maximum restriction rather than configuring 'sensible' mid-level autonomy from the start?" Add one concrete detail from the lesson.

Step 1 of 2

Maturity path: autonomy is earned

You don't start at Cloud AgentsAgents that run in a Cursor-managed virtual machine, check out the repo, do the work and open a pull request, then shut down, with no load on your laptop. Press Enter for the full definition. auto-merging in a SOXSarbanes-Oxley Act. A US law that forces companies to keep auditable controls over any system that affects their financial reporting. Press Enter for the full definition. repo. You start at 'propose, human disposes' and graduate rungs as evidence accrues: clean review pass rates, no escaped defects, audit trail intact. Box's published numbers (85%+ daily active, 30–50% throughput, +75% usage in six weeks driven by mentorship) came from staged adoption, not a big-bang autonomy switch. Higher autonomy is conditional on evidence and controls. It is never the start.

Interview answer

When a CISOChief Information Security Officer. The executive who owns security; usually the hardest and most important person to win over. Press Enter for the full definition. asks 'how do we let agents into our SOXSarbanes-Oxley Act. A US law that forces companies to keep auditable controls over any system that affects their financial reporting. Press Enter for the full definition. repo without failing an audit?', walk the pilot: deny-by-default commands, read-only MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. allowlist, hooks for secret-scan and path-gating, sandboxed and VM-isolated execution and a hard human-review plus separate-approver merge gate that preserves segregation of duties. Then close: we widen scope only as evidence earns it, with audit logs and AI-code tracking proving the control the whole way.