# ID-JAG

Identity Assertion JWT Authorization Grant. After SSO, the identity provider evaluates policy and issues an ID-JAG, which an MCP client exchanges for a server access token: the mechanism behind Enterprise Managed Authorization.

Learn more: [Enterprise Managed Authorization](/content/learn/enterprise-managed-authorization/index.html)

Part of [the Agent Control Fabric](/content/platform/index.html): Highflame's identity, policy, and enforcement substrate for AI agents.

## Keep exploring the glossary.

### Identity provider (IdP)
The system that issues and manages identities. Highflame extends your existing IdP to agents rather than replacing it.\
Read → [Identity provider](/content/glossary/idp/index.html)

### Inline enforcement
Evaluating and deciding on an action before it executes, out-of-band, rather than detecting it after the fact. Fail posture (open or closed) is set per surface.\
Read → [Inline enforcement](/content/glossary/inline-enforcement/index.html)

### Just-in-time (JIT) access
Issuing short-lived, task-scoped credentials on demand that expire when the work is done: eliminating standing access there's nothing to leak or over-grant.\
Read → [Just-in-time access](/content/glossary/jit-access/index.html)

### LLM firewall
A checkpoint in front of a model that inspects prompts and responses for injection, sensitive data, and unsafe content. It guards the model's edge, not the agent's actions behind it.\
Read → [LLM firewall](/content/glossary/llm-firewall/index.html)

### LLM security tools
The stack that protects LLM applications: input/output filters, firewalls and gateways, runtime enforcement, red teaming, and observability. No single tool covers all five.\
Read → [LLM security tools](/content/glossary/llm-security-tools/index.html)

### MCP (Model Context Protocol)
An open protocol that connects agents to external tools and data. Powerful for capability. But every connection is a new access path that has to be governed.\
Read → [MCP](/content/glossary/mcp/index.html)
