Run-Anywhere Operations
How does Diagrid Catalyst secure agent workflows with workload identity and MCP tool authorization?
Catalyst assigns a workload identity (e.g., SPIFFE-compatible) to each agent runner, authenticating to state stores and tools. MCP tool authorization enforces policies: which agent identity can call which tool, under what conditions. Policies are defined in Catalyst’s control plane and evaluated at runtime. This prevents unauthorized tool access even if an agent is compromised. Workflow state is encrypted at rest and in transit.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Run-Anywhere Operations
What does 'run anywhere' mean for agent workloads in Diagrid Catalyst?
Understand how Diagrid Catalyst enables agent workloads to run across cloud, hybrid, and air-gapped environments consistently.
- Run-Anywhere Operations
How does Catalyst handle durable execution for agents in a hybrid cloud setup?
Learn how Catalyst ensures durable execution for agents across hybrid cloud environments with state persistence and replay.
- Run-Anywhere Operations
Can I migrate an existing agent workflow from managed cloud to an air-gapped environment without rewriting?
Migrate agent workflows from cloud to air-gapped environments with Catalyst without code rewrites, just configuration changes.