Agent governance
Extend identity governance to AI agents and MCPs
Bring the same ownership and access discipline to your agent ecosystem. Define who owns an agent, what it can do, and who can use it.
- 01
Register MCP servers and establish ownership
Register your Model Context Protocol servers and map ownership during registration, making accountability explicit from the start.
- 02
Create agents and connect the right MCPs
Create agents with ownership mapped at registration. Connect each agent to one or more registered MCP servers.
- 03
Authorise specific tool sets
Map each agent to the tool sets it needs from each MCP. Authorisation is defined at the tool level, rather than granting every tool on a connected server.
- 04
Control who can use each agent
An OAuth layer restricts agent usage to people in your organisation. An additional allowlist can narrow access to selected organisation members.
- 05
Share a people configuration
Give your people the configuration to connect to an agent. They sign in with their organisational identity, with usage governed by your access rules.
Identity → Agent → Tools
Illustrative access model
Organisation members
Organisational identity
Research agent
Owner: Knowledge team
Knowledge MCP
- Search documents
- Read documents
- Delete documents· not assigned
Projects MCP
- List projects
- Read project status
- Update projects· not assigned
One agent · Multiple MCPs · Explicit tool permissions