Diagrid
Back to all questions
Run-Anywhere Operations

How does Diagrid Catalyst secure agent workflows with workload identity and MCP tool authorization?

Catalyst assigns a workload identity (e.g., SPIFFE-compatible) to each agent runner, authenticating to state stores and tools. MCP tool authorization enforces policies: which agent identity can call which tool, under what conditions. Policies are defined in Catalyst’s control plane and evaluated at runtime. This prevents unauthorized tool access even if an agent is compromised. Workflow state is encrypted at rest and in transit.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all