TOLAP: Closing the data-object security gap in AI agent architectures
Public Sector Blog
This article introduces TOLAP (Tool-Object Level Access Protocol), an open standard that closes the data-object security gap in AI agent architectures by enforcing access control at the tool boundary.
- Traditional access models (RBAC, ABAC, database RLS) cannot prevent agents from accessing unauthorized data through tools and plugins
- TOLAP enforces security at the tool layer with three principles: source-point enforcement, object granularity, and agent transparency
- Five components execute on every tool call: Security Profiles, Policy Resolution Engine, Security Context, Secure Tool Wrappers, and Secure Tool Factory
- Policies operate on individual data objects including columns, rows, fields, tags, endpoints, and result limits with built-in masking and filtering
- Unified schema covers databases, APIs, knowledge bases, and object storage across AWS, Azure, and Google Cloud
- Reference SDK available in .NET, Python, and TypeScript with zero external dependencies and pluggable policy storage
- Provides non-bypassable enforcement, tamper resistance, replay resistance, and mandatory audit trails for compliance
TOLAP enables public sector organizations to deploy AI agents against sensitive data with consistent, enforceable access controls that survive prompt injection attacks.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2025
2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.