Skip to main content
In the Komodor Agentic Operation Platform (KAOP), every agent is a governed principal alongside people and service accounts. It belongs to one account, acts under its own identity, and receives only the roles and credentials assigned to it.

An agent is the actor

Runs and evidence are attributed to the agent that performed the work, even when a person, schedule, or workflow initiated the run. When a person starts a run manually, the audit log also records the invocation under that person’s identity. This preserves both the agent’s operating history and the human action that initiated it. Agents receive a built-in Agent role by default. An authorized administrator can change an agent’s role assignments to match its job. Use Roles & permissions to define the capabilities and resource scopes, then verify the result in Access explorer.

Agent ID and display name

An agent has an Agent ID and a display name. The Agent ID is a normalized slug, such as payments-triage, used in URLs, configuration, and by the agent itself. It is unique within the account. The display name is the more readable label shown in the console.

How a self-deployed worker authenticates

A self-deployed worker uses a worker token bound to one agent. KAOP resolves the agent and account from the token, then verifies that the agent identifier presented by the worker matches the token. The SDK attaches the token to registration, heartbeat, run-claim, and evidence requests. Configure the worker with environment variables or an equivalent secret-injection mechanism: Keep the token out of source control, container images, and logs.

Manage worker tokens

Open Settings → Agents → Worker tokens to see each token’s status, creation time, expiration, and associated agent. A token value is shown only when it is issued or rotated.
1

Issue or copy the token

Store the value in your deployment’s secret manager before leaving the screen.
2

Rotate the token

KAOP issues a replacement and invalidates the previous value. Update the deployed secret before expecting the worker to authenticate with the new token.
3

Revoke the token

Prevent the token from authenticating again. Revocation does not terminate the worker process.
Worker-token creation, rotation, and revocation are security-relevant changes and appear in the audit log.

Next steps

Access explorer

Inspect an agent’s effective access before it runs.

Agent isolation & tenancy

Understand account and agent boundaries.

Standards & Guardrails

Add runtime checks to governed model and tool traffic.

Credentials & secrets

Bind credentials to only the agents that need them.