Learn · AI Agent Identity, Authorization & Governance · Highflame
Highflame Identity is now open source: agent identity on open standards. Read the launch
Learn

Agent security, explained.

Evergreen reference guides on AI agent identity, authorization, and governance: what each term means, and the controls that make it real.

Foundations

GuideWhat it covers
Agent Identity Non-human identity · Human IAM vs agent IAM · Per-session identity · Delegation & trust tiers
Agent Authorization Authentication vs authorization · Policy-as-code · Delegation & scope ceilings · Cascade revocation
Enterprise Managed Authorization (EMA) Admission vs runtime · ID-JAG grant · Corporate SSO · MCP servers
MCP Authorization OAuth 2.1 roles · Server discovery · PKCE code flow · Audience-bound tokens
Tool Poisoning What it is · Attack patterns · Detection & scanning · Runtime enforcement

Controls

GuideWhat it covers
MCP Gateway: Build vs Buy The 'just a proxy' trap · What's hard to build · The maintenance burden · Build vs buy
LLM Security Tools The category taxonomy · The 2026 landscape · Firewalls vs runtime · Choosing for agents
LLM Firewall What it is · What it catches · What it can't see · Firewall vs runtime
MCP Server Security The threat taxonomy · Tool poisoning & rug pulls · Credential exposure · Hardening

Governance

GuideWhat it covers
Agent Governance The governance framework · Four-level maturity model · Controls at each layer · Compliance mapping
AI Observability LLM, tool & file activity · Code agent observability · Web & custom agents · OpenTelemetry
Shadow AI Shadow IT vs shadow AI · Why it spreads · Discovery · Governance response
AI Agent Audit Trails What to capture · Tamper-evidence · Identity attribution · Compliance

See the fabric against your own agents.

A 45-minute session covers your real agent footprint and what governance looks like in your environment.