Skip to main content

Topic index

Agentic Access

Learn how to control agent identities, delegated authority, tools, and autonomous workflows.

Topic index

Understand this domain

Pomerium coverage

Pomerium can protect Streamable HTTP MCP server routes, bridge documented upstream OAuth flows, keep upstream connections separate by user, issue External Tokens for delegated application flows, and apply identity and mcp_tool policy. Operators can add selected MCP fields to authorization logs.

Limits

  • Gateway policy does not secure model reasoning, prompt handling, tool code, or the model runtime.
  • Pomerium protects Streamable HTTP MCP routes. It does not mediate a local stdio connection.
  • The mcp_tool criterion applies to tools/call. Tools still need their own data and action authorization.

Primary sources

1 learning path

Paths for this topic

7 related guides

Guides in this topic

30 related terms

Concepts in this topic

Agentic Access

Agent

An agent is a software loop that uses model output and context to select steps or tools toward a goal.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent and Tool Inventory

Inventory agent identities, hosts, models, tools, servers, credentials, owners, versions, targets, and provenance.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Blast Radius

Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Cascading Failure

Stop one false result, repeated action, or unavailable dependency from propagating through agents and tools with growing impact.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Credential Custody

Keep agent credentials isolated by user, task, audience, and tool and control storage, use, rotation, and revocation.

Learn this term
Agentic Access

Agent Goal Hijack

Prevent untrusted instructions from changing an agent's objective, authority use, tool sequence, or target resource.

Learn this term
Agentic AccessAuthorization and Policy

Agentic Access Management (AAM)

Agentic Access Management controls agent actions with originating identity, explicit delegation, per-request policy, enforcement, and audit evidence.

Learn this term
Agentic AccessSecurity Operations and Risk

Agentic Supply Chain

Verify the origin, version, integrity, permissions, and change process for agent code, models, prompts, tools, and metadata.

Learn this term
Authorization and PolicyAgentic Access

Confused Deputy

Prevent a service or agent from using its own authority for a caller that did not have permission to request the action.

Learn this term
Agentic AccessAuthorization and Policy

Delegation

Delegation gives an actor limited authority to act for another principal, called the subject.

Learn this term
Agentic AccessAuthorization and Policy

Delegation Chain

Preserve the human actor, agent, service, tool, target, authority, and constraints through every delegated access step.

Learn this term
Agentic AccessAuthorization and Policy

Explicit Delegation

Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.

Learn this term
Agentic AccessSecurity Operations and Risk

Hidden Trust Boundary

A hidden trust boundary exists when one component accepts another component's identity, authority, data, or result without an explicit enforced rule.

Learn this term
Identity and AuthenticationAgentic Access

Identity Collapse

Identity collapse occurs when a downstream service sees a common agent or service identity and loses the originating user or actor relationship.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term
Agentic AccessAuthorization and Policy

MCP Authorization

Learn how MCP authorization uses OAuth metadata, resource indicators, token audience checks, route policy, and tool authorization.

Learn this term
Agentic AccessAuthorization and Policy

MCP Security

Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term
Agentic AccessAuthorization and Policy

Prompt Injection

Learn how direct and indirect prompt injection can drive unsafe agent actions, and how least privilege and authorization reduce impact.

Learn this term
Agentic Access

Rogue Agent

A rogue agent acts outside its declared goal, approved policy, expected identity chain, or authorized operating boundary.

Learn this term
Agentic Access

Tool

In Model Context Protocol, a tool is a callable capability that a server exposes with a name, description, and input schema.

Learn this term
Agentic AccessAuthorization and Policy

Tool Misuse

Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.

Learn this term
Agentic AccessSecurity Operations and Risk

Tool Surface Area

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.

Learn this term
Agentic AccessApplication and Service Access

Workload Identity

Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo