Agent security, explained.
Evergreen reference guides on AI agent identity, authorization, and governance: what each term means, and the controls that make it real.
- 01 ▸ Reference guide
Agent Identity
Agent identity is a verifiable, cryptographic credential issued to an autonomous agent that carries agent-shaped claims: who owns it, how far it can delegate, and how much it should be trusted. It exists so every action an agent takes traces back to a named human, which the user accounts and API keys built for people and services cannot do.
- Non-human identity
- Human IAM vs agent IAM
- Per-session identity
- Delegation & trust tiers
- 02 ▸ Reference guide
Agent Authorization
Agent authorization is the control that decides, for every action an agent tries to take, whether it is allowed, based on the agent's identity, its scopes, and the authority delegated to it. Authentication proves who an agent is; authorization decides what it may do, and for an agent that decision has to be made at every action, not once at login.
- Authentication vs authorization
- Policy-as-code
- Delegation & scope ceilings
- Cascade revocation
- 03 ▸ Reference guide
Agent Governance
Agent governance is the practice of controlling what the autonomous agents in an organization are allowed to do, and proving after the fact what they did. It spans discovering every agent, authorizing each action against policy, and producing audit evidence. It is distinct from AI governance in the broad sense, which is mostly about model risk: bias, safety, and the model supply chain.
- The governance framework
- Four-level maturity model
- Controls at each layer
- Compliance mapping
More guides
| Guide | What it covers |
|---|---|
| AI Observability | LLM, tool & file activity · Code agent observability · Web & custom agents · OpenTelemetry |
| Shadow AI | Shadow IT vs shadow AI · Why it spreads · Discovery · Governance response |
| AI Agent Audit Trails | What to capture · Tamper-evidence · Identity attribution · Compliance |
| Enterprise Managed Authorization (EMA) | Admission vs runtime · ID-JAG grant · Corporate SSO · MCP servers |
| MCP Gateway: Build vs Buy | The 'just a proxy' trap · What's hard to build · The maintenance burden · Build vs buy |
| LLM Security Tools | The category taxonomy · The 2026 landscape · Firewalls vs runtime · Choosing for agents |
| LLM Firewall | What it is · What it catches · What it can't see · Firewall vs runtime |
See the fabric against your own agents.
A 45-minute session covers your real agent footprint and what governance looks like in your environment.