Agent identity
Identify agents through authenticated, server-bound principals rather than self-reported names.
View in the catalogConnect every action to an identity, a scope and a current policy. Keep personal access and company authority separate.
Discuss your use caseIdentify agents through authenticated, server-bound principals rather than self-reported names.
View in the catalogKeep the authenticated human authorizer distinct from the client and executing agent.
View in the catalogScope organization-owned identities for unattended workloads without permanent employee impersonation.
View in the catalogLimit operations and resources within the applicable tenant, project, application and environment.
View in the catalogEvaluate shared, versioned rules using trusted inputs. Distinguish observation, warnings, approval and enforcement.
View in the catalogIntersect policy, consent, delegated authority, resource permissions and plan eligibility.
View in the catalogProtect independently selected accounts and credentials, with scoped reauthorization and disconnection.
View in the catalogGrant bounded, expiring task or child-agent authority without widening the parent’s scope.
View in the catalogPreserve tenant and personal/business boundaries across reads, writes, sessions, caches and exports.
View in the catalogApply organization-defined requirements through supported controls. Rules alone do not establish certification.
View in the catalogAn agent can request a sensitive action, but approval is only one part of the decision. Re-evaluate the requester, resource and current authority before the protected effect.
A connected account, a paid plan or a model-supplied agent name is not authorization.