Authority / Security & access

Identity is the beginning.
Authority is the boundary.

Operator sessions, agent identities and connector credentials serve different purposes. Keep them separate throughout execution.

01 / People

Organization sign-in.

The OIDC gateway supports organization sign-in with PKCE and nonce validation. Browser sessions are held on the server, with provisioned roles for requesters, approvers, operators and administrators.

Identity-provider setup and account provisioning are required. The prototype does not provide public self-registration or a local password-reset service.

02 / Agents

Authenticated workload identities.

Workload tokens are checked for their signature, expiry, audience, tenant and agent binding. An agent identity does not grant access to operator data.

03 / Connectors

Credentials outside the agent.

Connector secrets belong to the worker’s protected configuration. Provider tokens and connector secrets are not exposed through the agent’s workflow state.

Credential lifetime and rotation depend on the deployed connector and identity provider. The ServiceNow PDI evaluation currently uses a limited development authentication flow.

04 / Readiness

Scoped tests. Clear limits.

Authority remains a development prototype. Local tests do not establish production certification, universal exactly-once execution or complete coverage of partitions and restored history.

Validate live connector access, tenancy, secret rotation, reconciliation and restore procedures in the intended deployment before production use.

Get started →Read the guide →