Diagrid
Back to all questions
Agent Identity & Security

What is the architecture for MCP tool authorization in Catalyst?

Catalyst inserts a policy enforcement point between the agent runner and MCP tools. Each agent has a workload identity from the platform. When the agent calls a tool, Catalyst intercepts the request, evaluates the policy (which agent can call which tool), and either allows or denies it. The policy is defined declaratively and stored in Catalyst's control plane.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all