Diagrid
Back to all questions
Agent Identity & Security

How does Catalyst ensure agent identity is tied to every action in audit logs?

Catalyst binds workload identity—such as OIDC tokens or SPIFFE IDs—to each workflow and tool invocation. Every log entry includes the agent’s identity, timestamp, and action hash. This creates a non-repudiable chain: you can trace which agent called which MCP tool under which policy. No identity spoofing is possible because the runtime enforces authentication before execution.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all