An accountable identity
Every agent should have an owner, an authorised purpose and separately revocable credentials.
Planned capabilityA proposed control layer between an AI agent and its tools. Identity, scoped permissions, data boundaries and explicit approval—not a request that the model simply behave.
Designed around evidence.
Capabilities in development.
Read an invoice, request an export or attempt a payment. The demonstration checks a fixed policy before it shows a result.
Real enforcement will require every relevant call to pass through an authorised gateway. A bypassed gateway cannot protect that action.
Every agent should have an owner, an authorised purpose and separately revocable credentials.
Planned capabilityValidate the caller, exact operation, destination and resource. A tool name alone is not an access policy.
Planned capabilityHigh-impact actions require approval tied to the actual request. The model cannot grant itself more authority.
Planned capabilityNo. The planned defence is layered: source-aware context, constrained tools, permissions, data controls, monitoring and human approval. No prompt classifier is presented as a perfect guarantee.
Not on its own. Enforcement needs to be placed where the agent cannot bypass it, with direct credentials and network paths restricted accordingly.
Model independence is a design goal, not a claim of tested support today. Specific gateways, authentication methods and tool protocols will be listed as validated integrations become available.
Your organisation is already connected.
Be part of building the layer that understands it.