The six layers
Identity
People, service accounts, and agents are all first-class principals in an account. Nothing acts
anonymously.
Permissions
Roles and grants decide which capabilities an identity holds, and on which resources. Default
deny, additive grants.
Standards
Every agent is created against your organization’s standards — ownership, budget, judges,
guardrails — with waivers shown rather than hidden.
Runtime gates
Configured gateways can inspect model and tool traffic, then allow, refuse, or redact it before
it continues.
Approvals
A consequential action can wait for a person, with the evidence needed to decide.
The record
Governed changes and selected sensitive reads are written to the audit log with their actor and
outcome.
The principle underneath
An agent is governed the same way a person is, and by the same machinery. An agent has its own identity, holds its own roles, and is refused by the same enforcement that refuses a human — which is what makes “what can this agent do?” a question with an answer rather than an assumption. Two properties follow from that, and they are worth stating because they are what makes the model trustworthy:- Authorization is enforced where the request lands. An agent cannot grant itself a capability by changing its own code. Runtime guardrails separately apply to traffic sent through configured KAOP gateways.
- The identity is the credential. A worker’s token resolves the agent and its account on its own. An agent cannot present someone else’s name and be believed.
What each layer stops
Reading order
Start with Signing in and Roles & permissions — they establish the vocabulary every other page uses. Then read Standards & Guardrails for the controls that act at runtime, and the Architecture considerations section for how accounts, secrets, data, and network traffic are isolated underneath.Next steps
Agent identity
How an agent authenticates and what it is permitted to do.
Access explorer
Check what an identity can actually do, before you change anything.
Agent isolation & tenancy
The account boundary, and how it is kept.
Secrets & credential handling
How a secret reaches a run without being exposed.