Diagrid
Back to all questions
Agent Identity & Security

How does Diagrid Catalyst enforce zero-trust for autonomous agents calling internal APIs?

Catalyst assigns a workload identity to each agent runner, verified by mTLS for all internal calls. Tool authorization policies define which agents may invoke specific MCP tools or APIs, with least-privilege scoping per identity. This ensures no agent is implicitly trusted, even within the same cluster. All requests are authenticated, authorized, and audited, aligning with zero-trust principles.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all