Secure your AI agents
Secure your AI agents with security policies and agent passports that establish trusted identities, define permitted capabilities, and enforce security controls throughout the agent lifecycle.
Use policies to control agent behavior, access, and interactions, while agent passports provide verifiable identity and trusted context for each agent. Together, they help maintain consistent governance, reduce security risks, and ensure agents operate within approved boundaries.
Policies
Define policies that govern agent behavior, access, and interactions. Policies can specify permitted capabilities, namespaces, network destinations, protocols, resource access, and other operational constraints. Use authorization, constraint, and audit policies to establish what agents can and cannot do.
Passport profiles
Create reusable identity templates that define the capabilities, constraints, and security requirements for AI agents. Passport profiles provide a consistent foundation for issuing trusted identities and ensure that agents are configured according to organizational requirements.
Agent passports
Issue a verifiable digital identity to an AI agent based on its passport profile. A passport binds the agent to its trusted identity and defined attributes. This provides cryptographic evidence that can be used to establish trust before allowing the agent to interact with protected resources.
Policy Enforcement Points (PEPs)
Deploy PEPs at critical points in the agent runtime environment to enforce policies in real time. PEPs evaluate agent requests and actions against applicable policies and can allow, deny, restrict, or record activity based on the policy decision.