Diagrid
Back to all questions
Agent Identity & Security

What is the architecture for least-privilege agent identity in Catalyst?

Catalyst binds each agent runner to a unique workload identity, separate from human or service identities. Tool authorization policies map identities to specific MCP tools or API endpoints, with granular permissions like read-only or write-scoped. The architecture uses Dapr’s service invocation with mTLS, so every call carries the agent’s identity for policy enforcement.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all