Control human-to-agent-to-tool access
Preserve identity, delegation, consent, policy, credential custody, approval, evidence, and revocation through agent actions.
Topic index
Learn how to control agent identities, delegated authority, tools, and autonomous workflows.
Topic index
Pomerium can protect Streamable HTTP MCP server routes, bridge documented upstream OAuth flows, keep upstream connections separate by user, issue External Tokens for delegated application flows, and apply identity and mcp_tool policy. Operators can add selected MCP fields to authorization logs.
1 learning path
Preserve identity, delegation, consent, policy, credential custody, approval, evidence, and revocation through agent actions.
7 related guides
Trace one agent action through identity, delegation, policy, approval, credential, tool, target, result, and future revocation.
Preserve subject, actor, audience, action, and authority limits when a service or agent acts for another principal.
Give people, services, workloads, devices, and agents distinct identity, delegation, credential, and revocation models.
Present the real target, arguments, authority, effect, and uncertainty so human approval gates a concrete agent action.
Reject tokens issued for another resource and exchange or broker credentials instead of forwarding bearer authority through agents.
Separate remote Streamable HTTP authorization from local stdio process, executable, environment, and operating-system security.
Trace one agent action from human intent through agent, client, server, tool, credential, target resource, and evidence.
30 related terms
An agent is a software loop that uses model output and context to select steps or tools toward a goal.
Inventory agent identities, hosts, models, tools, servers, credentials, owners, versions, targets, and provenance.
Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions.
Stop one false result, repeated action, or unavailable dependency from propagating through agents and tools with growing impact.
Keep agent credentials isolated by user, task, audience, and tool and control storage, use, rotation, and revocation.
Prevent untrusted instructions from changing an agent's objective, authority use, tool sequence, or target resource.
Prevent an agent from using a shared, wrong-user, stale, or excessive identity to act beyond the current delegated task.
Agentic Access Management controls agent actions with originating identity, explicit delegation, per-request policy, enforcement, and audit evidence.
Verify the origin, version, integrity, permissions, and change process for agent code, models, prompts, tools, and metadata.
Prevent a service or agent from using its own authority for a caller that did not have permission to request the action.
Delegation gives an actor limited authority to act for another principal, called the subject.
Preserve the human actor, agent, service, tool, target, authority, and constraints through every delegated access step.
Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.
A hidden trust boundary exists when one component accepts another component's identity, authority, data, or result without an explicit enforced rule.
Identity collapse occurs when a downstream service sees a common agent or service identity and loses the originating user or actor relationship.
Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.
Authenticate agent messages, bind them to one task and audience, validate content, and preserve actor and delegation evidence.
Learn how MCP authorization uses OAuth metadata, resource indicators, token audience checks, route policy, and tool authorization.
Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.
Stop untrusted content from becoming durable or cross-user agent state that changes later identity, policy, or tool actions.
Model Context Protocol is a client-server protocol for context exchange between AI applications and external systems.
Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.
Learn how direct and indirect prompt injection can drive unsafe agent actions, and how least privilege and authorization reduce impact.
A rogue agent acts outside its declared goal, approved policy, expected identity chain, or authorized operating boundary.
In Model Context Protocol, a tool is a callable capability that a server exposes with a name, description, and input schema.
Treat tool names, descriptions, schemas, annotations, outputs, and discovery changes as untrusted supply-chain input.
Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.
Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.
Keep model output, tool arguments, generated code, interpreters, and sandboxes from becoming uncontrolled host execution.
Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.