# Enterprise Managed Authorization (EMA)

An MCP extension that lets a company's identity provider decide, through corporate SSO, which MCP servers an agent may connect to. It governs admission, not what the agent does once inside.

Learn more: [Enterprise Managed Authorization](/content/learn/enterprise-managed-authorization/index.html)

Part of [the Agent Control Fabric](/content/platform/index.html): Highflame's identity, policy, and enforcement substrate for AI agents.

## Keep exploring the glossary.

### Guardrails  
Inline detection and enforcement on an agent's prompts, tool calls, and responses: blocking unsafe actions in real time.[Read →](/content/glossary/guardrails/index.html)  
### ID-JAG  
Identity Assertion JWT Authorization Grant. After SSO, the identity provider evaluates policy and issues an ID-JAG, which an MCP client exchanges for a server access token: the mechanism behind Enterprise Managed Authorization.[Read →](/content/glossary/id-jag/index.html)  
### Identity provider (IdP)  
The system that issues and manages identities. Highflame extends your existing IdP to agents rather than replacing it.[Read →](/content/glossary/idp/index.html)  
### Inline enforcement  
Evaluating and deciding on an action before it executes, out-of-band, rather than detecting it after the fact. Fail posture (open or closed) is set per surface.[Read →](/content/glossary/inline-enforcement/index.html)  
### Just-in-time (JIT) access  
Issuing short-lived, task-scoped credentials on demand that expire when the work is done: eliminating standing access there's nothing to leak or over-grant.[Read →](/content/glossary/jit-access/index.html)  
### LLM firewall  
A checkpoint in front of a model that inspects prompts and responses for injection, sensitive data, and unsafe content. It guards the model's edge, not the agent's actions behind it.[Read →](/content/glossary/llm-firewall/index.html)
