Endram field guides

AI agent security solutions

Runtime controls for authorization, MCP, governance, identity, guardrails, and human approval.

49 implementation pages4 sectionsUpdated September 2026

Model Context Protocol

01 · mcp gateway

MCP gateway for secure tool access

MCP gateway for secure tool access with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
02 · mcp security

MCP security controls

MCP security controls with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
03 · mcp proxy

MCP proxy with policy enforcement

MCP proxy with policy enforcement with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
04 · mcp authentication

MCP authentication for production agents

MCP authentication for production agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
05 · mcp authorization

MCP authorization server

MCP authorization server with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
06 · mcp server security

MCP server security

MCP server security with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
07 · mcp governance

MCP governance and control

MCP governance and control with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
08 · mcp observability

MCP observability with enforcement context

MCP observability with enforcement context with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
09 · mcp access control

MCP access control

MCP access control with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
10 · mcp permission management

MCP permission management

MCP permission management with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
11 · mcp tool inventory

MCP tool inventory

MCP tool inventory with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
12 · mcp security platform

MCP security platform

MCP security platform with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
13 · github mcp server

GitHub MCP server security

GitHub MCP server security with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
14 · mcp oauth

MCP OAuth authorization controls

MCP OAuth authorization controls with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
15 · mcp tools

MCP tools security and access control

MCP tools security and access control with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
16 · mcp security tools

MCP security tools buyer guide

MCP security tools buyer guide with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
17 · a2a protocol

A2A protocol authentication and the Agent Card

A2A lets agents from different vendors call each other. The Agent Card declares what an agent can do and how to authenticate to it, and that declaration is the trust decision.

Open guide →
18 · claude connectors

Reviewing Claude and ChatGPT connectors before enabling them

A connector is an MCP server someone else runs, with your data and your credentials. This is the review to run before enabling one for a workspace rather than for yourself.

Open guide →

Authorization and policy

01 · ai agent authorization

AI agent authorization

AI agent authorization with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
02 · ai agent access control

AI agent access control

AI agent access control with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
03 · ai agent guardrails

AI agent guardrails for tool use

AI agent guardrails for tool use with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
04 · human in the loop ai agent

Human-in-the-loop AI agent approvals

Human-in-the-loop AI agent approvals with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
05 · ai agent permission management

AI agent permission management

AI agent permission management with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
06 · ai agent policy engine

AI agent policy engine

AI agent policy engine with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
07 · least privilege for ai agents

Least privilege for AI agents

Least privilege for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
08 · authzen

AuthZEN: a standard request shape for authorization decisions

AuthZEN defines how an enforcement point asks a decision point whether an action is allowed. Endram implements it, so an existing PEP can consult it without a proprietary client.

Open guide →
09 · fine grained authorization

Fine-grained authorization for agent actions

Fine-grained usually means per-object. For agents the decisive granularity is per-call: the same tool, the same object, and a different answer because of the arguments.

Open guide →
10 · authorization as a service

Authorization as a service for agent tool calls

Externalising authorization means someone else's availability is now in your request path. This covers what that buys, what it costs, and the questions to settle before it is load-bearing.

Open guide →

Identity and credentials

01 · non human identity management

Non-human identity management for AI agents

Non-human identity management for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
02 · ai agent identity platform

AI agent identity platform

AI agent identity platform with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
03 · machine identity for ai agents

Machine identity for AI agents

Machine identity for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
04 · workload identity for ai agents

Workload identity for AI agents

Workload identity for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
05 · ai agent authentication

AI agent authentication

AI agent authentication with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
06 · oauth for ai agents

OAuth for AI agents

OAuth for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
07 · task scoped credentials

Task-scoped credentials for AI agents

Task-scoped credentials for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
08 · ephemeral credentials for ai agents

Ephemeral credentials for AI agents

Ephemeral credentials for AI agents with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
09 · agent credential broker

AI agent credential broker

AI agent credential broker with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
10 · spiffe

SPIFFE workload identity for AI agents

SPIFFE gives an agent a verifiable workload identity without a shared secret. What it does not carry is which human the agent is acting for, and that gap is where agent authorization begins.

Open guide →

Platform and governance

01 · ai security platform

AI agent security platform

AI agent security platform with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
02 · ai security tools

AI agent security tools

AI agent security tools with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
03 · ai agent governance platform

AI agent governance platform

AI agent governance platform with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
04 · ai agent management platform

AI agent management platform security

AI agent management platform security with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
05 · secure ai agents

Secure AI agents in production

Secure AI agents in production with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
06 · ai agent audit logs

AI agent audit logs

AI agent audit logs with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
07 · ai agent security posture management

AI agent security posture management

AI agent security posture management with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
08 · ai agent capability inventory

AI agent capability inventory

AI agent capability inventory with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
09 · agentic ai coding tools

Agentic AI coding tools security

Agentic AI coding tools security with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
10 · ai agent gateway

AI agent gateway for governed tool access

AI agent gateway for governed tool access with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →
11 · ai agent firewall

AI agent firewall for external actions

AI agent firewall for external actions with identity-aware policy, human approval, and a verifiable decision record for every sensitive tool call.

Open guide →