Learn · AI Agent Identity, Authorization & Governance · Highflame
Agent security, explained.
Evergreen reference guides on AI agent identity, authorization, and governance: what each term means, and the controls that make it real.
- [Foundations
The primitives every agent-security program is built on: who an agent is, how its access is decided, and the attacks that target it.
5 guides ↓](/content/learn/#foundations/index.html)
- [Controls
The defenses you put in front of agents: gateways, firewalls, server hardening, and how to choose them.
4 guides ↓](/content/learn/#controls/index.html)
- [Governance
Oversight and accountability: discovering agents, recording what they do, and keeping it auditable.
4 guides ↓](/content/learn/#governance/index.html)
Foundations
| Guide |
What it covers |
| Agent Identity → |
Non-human identity · Human IAM vs agent IAM · Per-session identity · Delegation & trust tiers |
| Agent Authorization → |
Authentication vs authorization · Policy-as-code · Delegation & scope ceilings · Cascade revocation |
| Enterprise Managed Authorization (EMA) → |
Admission vs runtime · ID-JAG grant · Corporate SSO · MCP servers |
| MCP Authorization → |
OAuth 2.1 roles · Server discovery · PKCE code flow · Audience-bound tokens |
| Tool Poisoning → |
What it is · Attack patterns · Detection & scanning · Runtime enforcement |
Controls
| Guide |
What it covers |
| MCP Gateway: Build vs Buy → |
The 'just a proxy' trap · What's hard to build · The maintenance burden · Build vs buy |
| LLM Security Tools → |
The category taxonomy · The 2026 landscape · Firewalls vs runtime · Choosing for agents |
| LLM Firewall → |
What it is · What it catches · What it can't see · Firewall vs runtime |
| MCP Server Security → |
The threat taxonomy · Tool poisoning & rug pulls · Credential exposure · Hardening |
Governance
| Guide |
What it covers |
| Agent Governance → |
The governance framework · Four-level maturity model · Controls at each layer · Compliance mapping |
| AI Observability → |
LLM, tool & file activity · Code agent observability · Web & custom agents · OpenTelemetry |
| Shadow AI → |
Shadow IT vs shadow AI · Why it spreads · Discovery · Governance response |
| AI Agent Audit Trails → |
What to capture · Tamper-evidence · Identity attribution · Compliance |
See the fabric against your own agents.
A 45-minute session covers your real agent footprint and what governance looks like in your environment.
Book a demo → Explore the platform