Today, Lovable joined AWS, CrowdStrike, Databricks, Docker, Google Cloud, Okta, Proofpoint, Salesforce, ServiceNow, Wiz, and Zscaler as a founding member of the Blueprint Alliance, a cross-industry coalition advancing an open reference architecture for securing and governing AI agents at enterprise scale.
What is a reference architecture?
A reference architecture is a shared description of how a system should be put together.
This matters now because companies are not building or running AI from a single vendor. Identity comes from one place, a data platform comes from another, and monitoring comes from a third. Each secures its own surface area, but we need a single framework for how to secure these disparate agentic experiences across an entire organization.
This blueprint centers around four questions.
Where are my agents?
Before you can secure agents, you need to know which ones are operating across your organization. The blueprint covers three ways to classify agents:
- What your developers build: Agents created in-house on agent platforms and frameworks, running against whichever models they choose.
- Shadow AI discovery: Agents nobody registered, by looking across cloud infrastructure, the network, endpoints, and the browser.
- Agent import: Registered agents that arrived from somewhere else: agent builder tools, SaaS products, automation platforms, agents running locally on someone's machine, and agent gateways.
The blueprint calls for an agent directory where every agent is registered as a distinct identity with an accountable human owner.
What can they connect to?
Once you know an agent exists, it needs an identity and a boundary.
On top of the directory sit access policies, which the blueprint grades from coarse-grained through fine-grained to intent-based, alongside network-based controls and guardrails. The principle is that access is scoped to the task rather than granted as standing privilege, and that delegation stays traceable as agents spawn sub-agents.
What are they doing?
The blueprint puts gateways in the execution path: an agent gateway, an MCP gateway, an AI and LLM gateway, and a security gateway. Policies are enforced inline rather than checked after the fact.
Monitoring then watches the session itself, covering sandboxing, tool and data access, threat and anomaly detection, prompt injection, DLP and output filtering, tracing, cost and performance, and human-in-the-loop checkpoints.
The architecture also enumerates what an agent can actually reach, which is the part most teams underestimate: MCP servers, SaaS apps, data stores, CLI tools, other agents, privileged resources, legacy systems, payment systems, browsers, foundation models, and skills. Listing them is how you know an agent's blast radius.
How do I respond?
Responses include token revocation, universal logout, session termination, continuous authorization, process termination, network quarantine, cloud service termination, and terminating the agent platform itself. The point is to neutralize one agent without taking down everything around it, and to make reinstatement deliberate and auditable rather than a quiet re-enable.
What this means for Lovable builders
As a founding member of the Blueprint Alliance, Lovable is helping shape how the industry secures AI agents. For the people and companies building on Lovable, that means we’re contributing to the security foundations that the next generation of applications will depend on: how agents identify themselves, what they can access, and how their actions stay accountable as they work across different tools and systems.
A shared architecture gives that work a stronger foundation. It allows improvements in identity, access controls, and monitoring to benefit the wider ecosystem, with vendors building toward a common approach. Our participation is an investment in making both Lovable and the applications you build on it more secure as agents take on more responsibility. The goal is straightforward: give you more freedom to build, with confidence in the systems your applications rely on.



