Development teams are building AI-powered applications faster than ever, but they're stuck waiting for access to the operational data those applications need to function, according to a report published by The New Stack. The report highlights how manual access provisioning has become the primary bottleneck in software development, forcing teams to file tickets with individual system owners and rebuild connections by hand for every new project. When direct access is denied, developers must work with stale copies of data that can't write back to source systems.

The access problem compounds as organizations scale, the report finds. Each application requires custom connections to APIs, databases, and cloud services, with different permission levels and data subsets for each one. Teams create tickets with system owners and wait through lengthy approval processes, sometimes defending their need for access through multiple email exchanges. Three years after a tool is built, no one can identify every system connected to a PostgreSQL database being migrated, risking outages when connections are missed. When employees leave, organizations can't guarantee that access has been revoked from every tool. With AI agents entering production environments, tracking who connects them to live systems and for what purpose has become nearly impossible.

The report presents unified API layers as a centralized access solution that sits between applications and data sources containing business-critical information. Rather than requesting permission from individual database or API owners, teams request access in one location with consistent rules and a single record of every change. James White, VP of Product at Monospace, explains the depth of control: "A gateway covers the connection. We go deeper, because we know the schema, we know who's asking, and we understand the response. So two agents may make the same request, but get a different response, depending on what each one is allowed to see." The layer uses role-based access control with least-privilege principles, assigning identities not just to team members but to applications and AI agents, each scoped to exactly the data they require.

The rise of AI agents has exposed a fundamental identity problem, according to the report. Agents typically inherit whatever credentials developers hand them—often personal API keys that tie the agent's identity to an individual developer. When that developer rotates keys or leaves the organization, the agent's access breaks or persists inappropriately. Field-level permissions enforced at the data layer provide stronger guardrails than relying on prompt instructions, the report notes. An example rule might allow an agent to update shipping addresses on orders but not payment methods, and only on orders that haven't shipped yet—combining field-level permissions that permit writes to shippingAddress but not paymentMethod with record-level filters restricting access to unshipped orders. The report describes Monospace as one implementation of this model, connecting databases and SaaS platforms once and introspecting existing schemas without migrating underlying systems, keeping data in place while maintaining a metadata layer on top.

The unified API layer model requires federating data across systems where it lives rather than copying or consolidating it, the report states. Every consumer needs scoped access controls, and a single record must track all connections and requests across systems, eliminating the need to piece together logs from multiple servers. Developers receive a typed SDK generated from the schema with IDE autocomplete, while agents connect through Model Context Protocol endpoints with unique identities whose roles and policies determine accessible data. The report positions access control—not application development itself—as the challenge enterprises have deferred, knowing they'll eventually need to solve identity and permissions for agents at scale. For organizations adopting AI at speed, the tension between developer velocity and governance will only sharpen as agents proliferate beyond the direct oversight of security teams. Centralizing that control may prove less a technical convenience than an operational necessity when the alternative is auditing permissions across dozens of systems for hundreds of autonomous agents.