Diagrid
Back to all questions
Agent Identity & Security

How does Catalyst handle tool authorization for agents running in air-gapped environments where external identity providers are unavailable?

Catalyst supports offline identity provisioning via pre-configured workload identity certificates and local policy files. In air-gapped setups, you define tool authorization policies as YAML or JSON files that are loaded into Catalyst’s local policy engine. These policies are immutable once deployed, preventing tampering. Catalyst still enforces identity-based authorization and logs all tool calls locally, which can be exported for audit when connectivity is restored.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all