Agent Identity & Security
How does Diagrid Catalyst enforce zero-trust for autonomous agents calling internal APIs?
Catalyst assigns a workload identity to each agent runner, verified by mTLS for all internal calls. Tool authorization policies define which agents may invoke specific MCP tools or APIs, with least-privilege scoping per identity. This ensures no agent is implicitly trusted, even within the same cluster. All requests are authenticated, authorized, and audited, aligning with zero-trust principles.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Agent Identity & Security
What is a workload identity for an AI agent and why can't I just use a shared API key?
Explains workload identity for AI agents and the security limits of shared API keys in production.
- Agent Identity & Security
How does Catalyst assign a workload identity to an agent runner like LangGraph or CrewAI?
Describes how Catalyst injects workload identities into framework-agnostic agent runners.
- Agent Identity & Security
What security problems do shared API keys cause when multiple agents run in production?
Lists security problems from shared API keys in multi-agent production environments.