Endram field guides
AI agent security solutions
Runtime controls for authorization, MCP, governance, identity, guardrails, and human approval.
Model Context Protocol
MCP gateway for secure tool access
MCP gateway for secure tool access with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →02 · mcp securityMCP security controls
MCP security controls with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →03 · mcp proxyMCP proxy with policy enforcement
MCP proxy with policy enforcement with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →04 · mcp authenticationMCP authentication for production agents
MCP authentication for production agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →05 · mcp authorizationMCP authorization server
MCP authorization server with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →06 · mcp server securityMCP server security
MCP server security with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →07 · mcp governanceMCP governance and control
MCP governance and control with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →08 · mcp observabilityMCP observability with enforcement context
MCP observability with enforcement context with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →09 · mcp access controlMCP access control
MCP access control with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →10 · mcp permission managementMCP permission management
MCP permission management with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →11 · mcp tool inventoryMCP tool inventory
MCP tool inventory with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →12 · mcp security platformMCP security platform
MCP security platform with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →13 · github mcp serverGitHub MCP server security
GitHub MCP server security with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →14 · mcp oauthMCP OAuth authorization controls
MCP OAuth authorization controls with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →15 · mcp toolsMCP tools security and access control
MCP tools security and access control with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →16 · mcp security toolsMCP security tools buyer guide
MCP security tools buyer guide with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →17 · a2a protocolA2A protocol authentication and the Agent Card
A2A lets agents from different vendors call each other. The Agent Card declares what an agent can do and how to authenticate to it, and that declaration is the trust decision.
Open guide →18 · claude connectorsReviewing Claude and ChatGPT connectors before enabling them
A connector is an MCP server someone else runs, with your data and your credentials. This is the review to run before enabling one for a workspace rather than for yourself.
Open guide →Identity and credentials
Non-human identity management for AI agents
Non-human identity management for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →02 · ai agent identity platformAI agent identity platform
AI agent identity platform with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →03 · machine identity for ai agentsMachine identity for AI agents
Machine identity for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →04 · workload identity for ai agentsWorkload identity for AI agents
Workload identity for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →05 · ai agent authenticationAI agent authentication
AI agent authentication with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →06 · oauth for ai agentsOAuth for AI agents
OAuth for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →07 · task scoped credentialsTask-scoped credentials for AI agents
Task-scoped credentials for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →08 · ephemeral credentials for ai agentsEphemeral credentials for AI agents
Ephemeral credentials for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →09 · agent credential brokerAI agent credential broker
AI agent credential broker with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →10 · spiffeSPIFFE workload identity for AI agents
SPIFFE gives an agent a verifiable workload identity without a shared secret. What it does not carry is which human the agent is acting for, and that gap is where agent authorization begins.
Open guide →Platform and governance
AI agent security platform
AI agent security platform with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →02 · ai security toolsAI agent security tools
AI agent security tools with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →03 · ai agent governance platformAI agent governance platform
AI agent governance platform with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →04 · ai agent management platformAI agent management platform security
AI agent management platform security with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →05 · secure ai agentsSecure AI agents in production
Secure AI agents in production with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →06 · ai agent audit logsAI agent audit logs
AI agent audit logs with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →07 · ai agent security posture managementAI agent security posture management
AI agent security posture management with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →08 · ai agent capability inventoryAI agent capability inventory
AI agent capability inventory with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →09 · agentic ai coding toolsAgentic AI coding tools security
Agentic AI coding tools security with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →10 · ai agent gatewayAI agent gateway for governed tool access
AI agent gateway for governed tool access with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →11 · ai agent firewallAI agent firewall for external actions
AI agent firewall for external actions with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.
Open guide →