Diagrid
Back to all questions
Agent Identity & Security

How do I troubleshoot an agent failing to call an internal API due to identity policy in Catalyst?

Check Catalyst’s audit logs for denied authorization events, which show the agent identity, target tool, and policy rule that blocked the call. Verify the agent’s workload identity matches the policy’s allowed identities. Ensure the MCP tool is registered with the correct endpoint and method. Use Catalyst’s policy dry-run mode to test changes without affecting production.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all