Skip to content

Identity primitives for AI agents

The controls a CISO asks about first, against the vendors in the identity spine and MCP gateways. A claim links to the vendor's own documentation. "No public claim found" means the docs were read and did not say so; "Not checked" means nobody has looked yet.

Agent as a first-class identity

The agent is registered in the directory with its own identity, owner, and lifecycle, instead of borrowing a service account or a person's session.

Reference: Microsoft Entra Agent ID, Okta Agent SSO

1PasswordNot checked
AcuvityNot checked
AembitNo public claim found
Arcade.devNot checked
Astrix SecurityClaimed
AurascapeNo public claim found
Auth0Not checked
CiscoNo public claim found
CrowdStrikeNo public claim found
DescopeNo public claim found
Entro SecurityNo public claim found
Harmonic SecurityNot checked
KeycardNo public claim found
Lasso SecurityNot checked
MicrosoftClaimed
NatomaNot checked
Nightfall AINot checked
Noma SecurityNo public claim found
Oasis SecurityClaimed
OktaClaimed
Operant AINo public claim found
Palo Alto NetworksNo public claim found
Permiso SecurityNot checked
PortkeyNo public claim found
RunlayerClaimed
SailPointClaimed
SGNLNot checked
StytchNot checked
TeleportNot checked
Token SecurityClaimed
VezaNo public claim found
ZscalerNo public claim found

On-behalf-of token exchange

The agent trades a user's token for a narrower token that records both the user and the agent, so every downstream call carries the delegation chain.

Reference: RFC 8693

1PasswordNot checked
AcuvityNot checked
AembitClaimed
Arcade.devNot checked
Astrix SecurityNot checked
AurascapeNot checked
Auth0Claimed
CiscoNot checked
CrowdStrikeNot checked
DescopeClaimed
Entro SecurityNot checked
Harmonic SecurityNot checked
KeycardClaimed
Lasso SecurityNot checked
MicrosoftClaimed
NatomaNot checked
Nightfall AINot checked
Noma SecurityNot checked
Oasis SecurityNot checked
OktaNot checked
Operant AINot checked
Palo Alto NetworksNot checked
Permiso SecurityNot checked
PortkeyNot checked
RunlayerClaimed
SailPointNot checked
SGNLNot checked
StytchNot checked
TeleportClaimed
Token SecurityNot checked
VezaNot checked
ZscalerNot checked

Cross App Access (ID-JAG)

The identity provider brokers agent access between enterprise apps, so admins approve app-to-app agent connections centrally instead of users clicking consent screens.

Reference: MCP authorization extension

1PasswordNot checked
AcuvityNot checked
AembitClaimed
Arcade.devNot checked
Astrix SecurityNot checked
AurascapeNot checked
Auth0Not checked
CiscoNot checked
CrowdStrikeNot checked
DescopeClaimed
Entro SecurityNot checked
Harmonic SecurityNot checked
KeycardNo public claim found
Lasso SecurityNot checked
MicrosoftNo public claim found
NatomaNot checked
Nightfall AINot checked
Noma SecurityNot checked
Oasis SecurityNot checked
OktaClaimed
Operant AINot checked
Palo Alto NetworksNot checked
Permiso SecurityNot checked
PortkeyNot checked
RunlayerNot checked
SailPointNot checked
SGNLNot checked
StytchClaimed
TeleportNo public claim found
Token SecurityNot checked
VezaNot checked
ZscalerNot checked

Asynchronous human approval (CIBA)

The agent pauses and asks a person to approve a sensitive action on a separate device before it gets the token to proceed.

Reference: OpenID Connect CIBA

1PasswordNo public claim found
AcuvityNot checked
AembitNo public claim found
Arcade.devNot checked
Astrix SecurityNot checked
AurascapeNot checked
Auth0Claimed
CiscoNot checked
CrowdStrikeNot checked
DescopeClaimed
Entro SecurityNot checked
Harmonic SecurityNot checked
KeycardNo public claim found
Lasso SecurityNot checked
MicrosoftNo public claim found
NatomaNot checked
Nightfall AINot checked
Noma SecurityNot checked
Oasis SecurityNot checked
OktaNot checked
Operant AINot checked
Palo Alto NetworksNot checked
Permiso SecurityNot checked
PortkeyNot checked
RunlayerNo public claim found
SailPointNot checked
SGNLNot checked
StytchNot checked
TeleportNot checked
Token SecurityNot checked
VezaNot checked
ZscalerNot checked

MCP authorization conformance

MCP servers act as OAuth 2.1 resource servers: protected resource metadata (RFC 9728), PKCE, resource indicators (RFC 8707), client ID metadata documents before dynamic registration, and no token passthrough.

Reference: MCP specification 2025-11-25

1PasswordNot checked
AcuvityNot checked
AembitClaimed
Arcade.devClaimed
Astrix SecurityNot checked
AurascapeNot checked
Auth0Claimed
CiscoNot checked
CrowdStrikeNot checked
DescopeClaimed
Entro SecurityNot checked
Harmonic SecurityNot checked
KeycardClaimed
Lasso SecurityNot checked
MicrosoftClaimed
NatomaNot checked
Nightfall AINot checked
Noma SecurityNot checked
Oasis SecurityNot checked
OktaNot checked
Operant AINot checked
Palo Alto NetworksNot checked
Permiso SecurityNot checked
PortkeyNo public claim found
RunlayerClaimed
SailPointNot checked
SGNLNot checked
StytchClaimed
TeleportNo public claim found
Token SecurityNot checked
VezaNot checked
ZscalerNot checked

Fine-grained authorization

Per-resource, per-action decisions, including permission-aware retrieval so an agent only reads documents the requesting user may see.

Reference: OpenFGA, Zanzibar-style ReBAC

1PasswordNot checked
AcuvityNot checked
AembitClaimed
Arcade.devClaimed
Astrix SecurityNot checked
AurascapeClaimed
Auth0Claimed
CiscoNo public claim found
CrowdStrikeNot checked
DescopeClaimed
Entro SecurityNot checked
Harmonic SecurityClaimed
KeycardClaimed
Lasso SecurityNot checked
MicrosoftNot checked
NatomaClaimed
Nightfall AIClaimed
Noma SecurityClaimed
Oasis SecurityNot checked
OktaNot checked
Operant AIClaimed
Palo Alto NetworksNo public claim found
Permiso SecurityNot checked
PortkeyNo public claim found
RunlayerClaimed
SailPointNo public claim found
SGNLClaimed
StytchNot checked
TeleportClaimed
Token SecurityNot checked
VezaNot checked
ZscalerNo public claim found

Short-lived, secretless credentials

Credentials are minted just in time and expire in minutes, so there is no standing secret to steal.

Reference: SPIFFE, workload identity federation

1PasswordNot checked
AcuvityNot checked
AembitClaimed
Arcade.devNot checked
Astrix SecurityClaimed
AurascapeNot checked
Auth0Not checked
CiscoNo public claim found
CrowdStrikeNo public claim found
DescopeClaimed
Entro SecurityNot checked
Harmonic SecurityNot checked
KeycardClaimed
Lasso SecurityNot checked
MicrosoftClaimed
NatomaNot checked
Nightfall AINot checked
Noma SecurityNot checked
Oasis SecurityClaimed
OktaClaimed
Operant AINot checked
Palo Alto NetworksNot checked
Permiso SecurityNot checked
PortkeyNot checked
RunlayerNo public claim found
SailPointNo public claim found
SGNLNot checked
StytchNot checked
TeleportClaimed
Token SecurityNot checked
VezaNot checked
ZscalerNot checked

Token vault

Third-party tokens are held by a broker and never reach the model or the prompt context.

Reference: Brokered credentials

1PasswordClaimed
AcuvityNot checked
AembitClaimed
Arcade.devClaimed
Astrix SecurityNot checked
AurascapeNot checked
Auth0Claimed
CiscoNot checked
CrowdStrikeNot checked
DescopeClaimed
Entro SecurityNot checked
Harmonic SecurityNot checked
KeycardClaimed
Lasso SecurityNot checked
MicrosoftNot checked
NatomaNot checked
Nightfall AINot checked
Noma SecurityNot checked
Oasis SecurityNot checked
OktaNo public claim found
Operant AINot checked
Palo Alto NetworksNot checked
Permiso SecurityNot checked
PortkeyClaimed
RunlayerClaimed
SailPointNot checked
SGNLNot checked
StytchNot checked
TeleportNot checked
Token SecurityNot checked
VezaNot checked
ZscalerNot checked

Kill switch

An operator can revoke one agent, one tool, or every token an agent holds, in seconds, across systems.

Reference: Operational control

1PasswordNot checked
AcuvityNo public claim found
AembitClaimed
Arcade.devNot checked
Astrix SecurityClaimed
AurascapeNo public claim found
Auth0Not checked
CiscoNo public claim found
CrowdStrikeNo public claim found
DescopeClaimed
Entro SecurityNot checked
Harmonic SecurityNo public claim found
KeycardClaimed
Lasso SecurityNo public claim found
MicrosoftClaimed
NatomaNot checked
Nightfall AIClaimed
Noma SecurityNo public claim found
Oasis SecurityNot checked
OktaClaimed
Operant AINo public claim found
Palo Alto NetworksNo public claim found
Permiso SecurityNot checked
PortkeyClaimed
RunlayerClaimed
SailPointClaimed
SGNLNo public claim found
StytchNot checked
TeleportNot checked
Token SecurityNot checked
VezaNot checked
ZscalerNo public claim found

Per-action audit chain

Every tool call is logged with the human, the agent, the tool, the data touched, and the decision, and can be exported to a SIEM.

Reference: Operational control

1PasswordNo public claim found
AcuvityNo public claim found
AembitClaimed
Arcade.devNot checked
Astrix SecurityNot checked
AurascapeNo public claim found
Auth0Not checked
CiscoNo public claim found
CrowdStrikeClaimed
DescopeNot checked
Entro SecurityNot checked
Harmonic SecurityNo public claim found
KeycardClaimed
Lasso SecurityNo public claim found
MicrosoftNo public claim found
NatomaNo public claim found
Nightfall AINo public claim found
Noma SecurityNo public claim found
Oasis SecurityNo public claim found
OktaClaimed
Operant AINot checked
Palo Alto NetworksNo public claim found
Permiso SecurityNo public claim found
PortkeyNo public claim found
RunlayerClaimed
SailPointNo public claim found
SGNLNot checked
StytchNot checked
TeleportClaimed
Token SecurityNo public claim found
VezaNot checked
ZscalerNo public claim found