# Agent security, explained.

Evergreen reference guides on AI agent identity, authorization, and governance: what each term means, and the controls that make it real.

- [Foundations\
The primitives every agent-security program is built on: who an agent is, how its access is decided, and the attacks that target it.\
5 guides ↓](/content/learn/#foundations/index.html)
- [Controls\
The defenses you put in front of agents: gateways, firewalls, server hardening, and how to choose them.\
4 guides ↓](/content/learn/#controls/index.html)
- [Governance\
Oversight and accountability: discovering agents, recording what they do, and keeping it auditable.\
4 guides ↓](/content/learn/#governance/index.html)

## Foundations

| Guide | What it covers |
| --- | --- |
| [Agent Identity](/content/learn/ai-agent-identity/index.html) → | Non-human identity · Human IAM vs agent IAM · Per-session identity · Delegation & trust tiers |
| [Agent Authorization](/content/learn/ai-agent-authorization/index.html) → | Authentication vs authorization · Policy-as-code · Delegation & scope ceilings · Cascade revocation |
| [Enterprise Managed Authorization (EMA)](/content/learn/enterprise-managed-authorization/index.html) → | Admission vs runtime · ID-JAG grant · Corporate SSO · MCP servers |
| [MCP Authorization](/content/learn/mcp-authorization/index.html) → | OAuth 2.1 roles · Server discovery · PKCE code flow · Audience-bound tokens |
| [Tool Poisoning](/content/learn/mcp-tool-poisoning/index.html) → | What it is · Attack patterns · Detection & scanning · Runtime enforcement |

## Controls

| Guide | What it covers |
| --- | --- |
| [MCP Gateway: Build vs Buy](/content/learn/mcp-gateway-build-vs-buy/index.html) → | The 'just a proxy' trap · What's hard to build · The maintenance burden · Build vs buy |
| [LLM Security Tools](/content/learn/llm-security-tools/index.html) → | The category taxonomy · The 2026 landscape · Firewalls vs runtime · Choosing for agents |
| [LLM Firewall](/content/learn/llm-firewall/index.html) → | What it is · What it catches · What it can't see · Firewall vs runtime |
| [MCP Server Security](/content/learn/mcp-server-security/index.html) → | The threat taxonomy · Tool poisoning & rug pulls · Credential exposure · Hardening |

## Governance

| Guide | What it covers |
| --- | --- |
| [Agent Governance](/content/learn/ai-agent-governance/index.html) → | The governance framework · Four-level maturity model · Controls at each layer · Compliance mapping |
| [AI Observability](/content/learn/ai-observability/index.html) → | LLM, tool & file activity · Code agent observability · Web & custom agents · OpenTelemetry |
| [Shadow AI](/content/learn/shadow-ai/index.html) → | Shadow IT vs shadow AI · Why it spreads · Discovery · Governance response |
| [AI Agent Audit Trails](/content/learn/ai-agent-audit-trails/index.html) → | What to capture · Tamper-evidence · Identity attribution · Compliance |

## See the fabric against your own agents.

A 45-minute session covers your real agent footprint and what governance looks like in your environment.

[Book a demo →](/content/contact/index.html) [Explore the platform](/content/platform/index.html)
