Diagrid
Back to all questions
Agent Identity & Security

Can I use workload identities to authorize which tools an AI agent can call via MCP?

Yes. Catalyst ties workload identities to MCP tool authorization policies, so each agent can only invoke tools its identity is permitted to use. You define policies that specify which agent identities may call which MCP tools, under what conditions (e.g., rate limits, required claims). This prevents an agent from accidentally or maliciously calling unauthorized tools, even if the agent framework supports them. Policies are evaluated at runtime before each tool invocation.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all