Agent Identity & Security
What happens if an agent's workload identity is compromised—can I revoke it without downtime?
Yes. Catalyst supports immediate revocation of a specific agent's workload identity via its control plane. The revocation takes effect on the next token refresh or tool invocation, blocking that agent from making further calls. Other agents with different identities continue running unaffected. You can then investigate the compromised agent's audit trail, rotate any leaked credentials, and redeploy the agent with a new identity—all without restarting your entire agent fleet.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Agent Identity & Security
What is a workload identity for an AI agent and why can't I just use a shared API key?
Explains workload identity for AI agents and the security limits of shared API keys in production.
- Agent Identity & Security
How does Catalyst assign a workload identity to an agent runner like LangGraph or CrewAI?
Describes how Catalyst injects workload identities into framework-agnostic agent runners.
- Agent Identity & Security
What security problems do shared API keys cause when multiple agents run in production?
Lists security problems from shared API keys in multi-agent production environments.