Key Concepts
- Multi-user AI agent architecture
- Data isolation and security
- N8N chat embed widget
- WordPress proxy
- JSON Web Tokens (JWT)
- Superbase row-level security (RLS)
- Principle of least privilege
- Multi-factor authentication (MFA) / Step-up authentication
- Data anonymization
- Data residency
- N8N licensing (Sustainable Use vs. Enterprise)
1. Demo of Multi-User AI Agent
- The video demonstrates a multi-user AI agent embedded in a dummy WooCommerce e-commerce store dashboard.
- Example: Frank Grimes logs in and asks about an order placed on July 28th. The agent identifies the order, provides a proof-of-delivery image from Superbase storage, and offers to escalate the issue to support.
- Example: Hank Scorpio logs in and asks the same question. The agent correctly states that there is no order for that date and offers information about orders around that time.
- The agent can generate secure links to invoices using Superbase signed URLs with configurable expiration.
- The agent uses a calculator tool to accurately calculate order totals for a specific month (July 2024).
- The agent correctly identifies items in the user's last order.
2. Under the Hood: N8N Workflow
- The AI agent uses N8N's native chat embed widget with embedded chat mode enabled, public accessibility with basic authentication, memory from previous sessions, and streaming mode.
- The agent is configured to use GPT-5, short-term memory using Postgres with Superbase, and tools to fetch customer records, fetch orders and order details, generate signed URLs, and escalate queries.
- Security is paramount: The video emphasizes that securing the agent and ensuring data isolation is more challenging than building the agent itself.
- Prompt Injection Protection: The "fetch customer record" tool hardcodes the customer ID from the webhook to prevent prompt injection attacks. All database queries are filtered by customer ID.
3. Superbase Data Structure
- Superbase tables include:
customers: Test customer data for login.orders: Order statuses, total amounts, tracking numbers, and links to documents.order_items: Items linked to orders.n8n_chat_histories: Agent memory.
- Superbase storage includes buckets for "PODs" (proof of delivery) and "invoices," with folders organized by customer ID.
4. Multi-User vs. Multi-Tenant Architectures
- Multi-user: A single organization (e.g., e-commerce store) with multiple customers who can access their private information.
- Multi-tenant: A single app with multiple organizations (tenants), each with its own users and data. Requires strict data separation logic.
- Example (Multi-user): Netflix, where individual users have accounts.
- Example (Multi-tenant): Shopify, where businesses create online shops and manage their users.
- The choice between these architectures impacts the N8N license required.
5. Seven Strategies for Data Isolation and Security
- Strategy 1: Proxying the N8N Chat Embed
- The standard N8N chat embed exposes the webhook URL, basic authentication credentials, and customer ID in the browser, creating a security risk.
- Solution: Create a proxy on the website backend (e.g., WordPress) to handle communication with N8N. The front end only communicates with the secure backend.
- The WordPress plugin "N8 Secure Chat" exposes a proxy endpoint that requires user authentication, passes basic authentication and a JWT token to N8N, and injects the customer ID from the user profile.
- Strategy 2: JSON Web Tokens (JWT) for Request Verification
- Even with a proxy, an attacker could potentially gain access to the webhook URL and basic authentication credentials.
- Solution: Use a JWT to verify that the request originated from the WordPress backend.
- A JWT is generated on the WordPress side, verified on the N8N side using a shared secret key, and has a short expiration time (60 seconds) to prevent replay attacks.
- Strategy 3: Superbase Row-Level Security (RLS)
- Even if authentication is handled in WordPress, enable RLS on all Superbase tables and storage buckets.
- Disabling RLS exposes data publicly via the API, even with the anonymous API key.
- N8N typically integrates with Superbase using the service role key, which bypasses RLS.
- Strategy 4: Multi-Factor Authentication (MFA) / Step-Up Authentication
- If WordPress is compromised, an attacker could access passwords and secret keys.
- Solution: Implement MFA within the AI agent chat for sensitive actions.
- Example: Send a one-time SMS code to the user's phone and require them to enter it into the AI agent interface.
- This limits the "blast radius" of a hack.
- Strategy 5: Keep Software Up-to-Date
- Ensure that both N8N and the server software are up-to-date to patch security vulnerabilities.
- Failing to do so can lead to privilege escalation, unauthorized access, and access to backend systems.
- Strategy 6: Principle of Least Privilege
- Grant only the minimum required level of access to backend systems.
- Instead of using the Superbase service role key, create a specific database user with restricted permissions (e.g., read access to orders and customers tables, write access to chat histories).
- Strategy 7: Database-Enforced Security with Identity Providers
- Use a secure identity provider (e.g., Superbase Auth) to authenticate users and return a secure access token.
- Pass the access token with each request to the N8N workflow.
- Enforce security at the database level using RLS policies that control what the user can see and do based on the access token.
- Example: The Insights LM project uses Superbase Auth to authenticate users and grant access to the dashboard. Requests to the Superbase vector store include the access token, and RLS policies ensure that users can only view documents from their own notebooks.
6. Additional Security Measures
- Use Cloudflare for anti-bot protection, DDoS protection, and as a web application firewall.
- Ensure all communications are over HTTPS/TLS.
- Validate and sanitize user inputs to prevent SQL injection attacks.
- Implement rate limiting to slow down attackers.
- Rotate basic authentication keys and JWT secret keys regularly.
- Implement logging and monitoring across the architecture.
- Use firewalls and a DMZ to protect internal traffic.
- Ensure custom code is sound and free of bugs.
7. Compliance Considerations
- Relationship with Customers: Obtain explicit consent for AI data processing, update terms of service and privacy policies.
- Relationship with LLM Provider: Have a data processing agreement with zero data retention and data residency within the EU (if required by GDPR).
- Data Anonymization: Anonymize data before sending it to an LLM by tokenizing personally identifiable information (PII).
- Avoid Sending Sensitive Information: Never send payment card information, health information, social security numbers, or financial information to an LLM.
8. N8N Licensing
- N8N has a Sustainable Use License and an Enterprise License.
- The Sustainable Use License allows for internal business purposes.
- The Enterprise License is required for selling a product or service that derives value from N8N functionality.
- The video raises questions about whether the e-commerce store use case falls under the Sustainable Use License or the Enterprise License.
- The N8N licensing team has not provided clarification on this issue.
9. Synthesis/Conclusion
Building a secure multi-user AI agent requires a layered approach that addresses potential vulnerabilities at every level of the architecture. This includes proxying the chat embed, using JWTs for request verification, implementing Superbase RLS, employing MFA, keeping software up-to-date, adhering to the principle of least privilege, and enforcing database-level security with identity providers. Compliance considerations, such as data anonymization and data residency, are also crucial. The N8N licensing model can be ambiguous, requiring careful consideration of the specific use case.
AI summaries can miss context or contain errors. Check important details against the original video.





