Solution

Keep reusable credentials out of agent context on governed routes

Policy decides on the exact action. The execution boundary acquires and applies credentials so the agent receives a governed result, not standing custody.

Illustrative workflow — not a live product screenshot. Scope and coverage apply.

Keep reusable credentials out of agent context

Three lanes show where the reusable credential is held versus what the agent receives.

Agent / model context

  1. 1.Proposed action
  2. 2.Opaque credential handle (if any)
  3. 3.Governed result

Governed execution boundary

  1. 1.Policy decision
  2. 2.Permit consumption
  3. 3.Credential mediator
  4. 4.Dispatcher

Reusable credential enclosed here

Target system

  1. 1.Bound request
  2. 2.Observed outcome
No reusable secret crosses this boundary

Applies to declared governed routes and controlled credential ingress paths. Does not include interactive RDP/SSH session proxying as a substitute for this model.

An opaque handle must not be independently redeemable by the agent or usable outside the governed execution boundary.

Legend

  • Identity and context
  • Execution
  • Evidence and proof

What this diagram shows

  1. Agent lane: proposed action, optional opaque handle, governed result — no reusable secret.
  2. Execution boundary: policy, permit consumption, credential mediator, dispatcher.
  3. Target lane: bound request and observed outcome.
  4. No reusable secret crosses this boundary
  5. Applies to declared governed routes and controlled credential ingress paths. Does not include interactive RDP/SSH session proxying as a substitute for this model.

Three industry approaches

ApproachWho holds secretDurationReuseDecision pointEvidencePosture
Inject at the boundaryVault / mediator at execution boundaryAction-boundNone in agent contextPEP at governed routeConsumption + dispatch recordsEmpowerID default on governed routes
Broker short-lived, action-bound authorityBroker for narrow windowSingle action or mission turnLimited to bound scopePolicy + broker policyBroker issuance + outcome linkSupported where broker integrates with spine
Hand over and revoke laterAgent or model contextStanding until revokedHighAfter custody transferRevoke events only — not non-custody proofNot our model

Acquisition and ingress

Platform holds approved credential

  1. Policy permits action
  2. Mediator retrieves from vault
  3. Inject at dispatch
  4. Agent receives result only

User completes provider consent

  1. Request held at boundary
  2. User authorizes with provider
  3. Token captured and vaulted
  4. Later use is mediated — not pasted into model context

Secrets pasted or returned into model context require capture-and-substitute controls; output redaction alone is not equivalent.

Stronger ingress-control path: capture-and-substitute at the governed boundary (connector and deployment scope apply).

Separation of duties

Decision authority (PDP)

May: Evaluate policy and issue decision

Must not: Hold reusable credentials or dispatch directly

Execution verifier / fencer

May: Bind arguments and enforce permit consumption

Must not: Override policy or store long-lived secrets in agent context

Credential / control mediator

May: Acquire and apply credentials inside boundary

Must not: Authorize actions without policy decision

Dispatcher

May: Send bound request to target

Must not: Expand scope beyond consumed permit

Where this control holds, and where it does not

Governed

  • Actions on declared governed routes
  • Mediated credential acquisition and injection

Not governed

  • Credentials the agent already holds from another source
  • Paths that bypass the governed execution boundary

Possible bypasses

  • Direct API access with standing keys held by the agent

Exposure ledger

Illustrative exposure ledger

Identity / agentReachable credentialMediated targetPurpose / missionLast useExpiryRecert ownerCustody modeEvidence
FinanceCloseAssistantSAP service account (mediated)ERP read APIMonth-end read missionLast governed turnMission-boundFinance OpsNo standing secret in agent contextDispatch + read-back on declared path
UnregisteredCopilotExtensionUnknown — not on governed pathHTTP egressUnknownNot observed on declared pathN/AUnresolvedReview requiredGap — not on governed path

Honest boundary

  • Not a privileged-session recording product
  • No RDP/SSH proxy claim on this page
  • Non-custody applies only to governed paths
  • A credential broker alone does not prove the downstream effect
Get Started

Connect once. Govern consistently. Change safely.

See how EmpowerID Identity Fabric delivers governance, authorization, and execution for your organization.

Request Demo See the platform in action
Talk to an Expert Technical consultation
EmpowerID AI

EmpowerID AI Assistant

Online

EmpowerID AI
EmpowerID AI
Hello! How can I help you today?
11:19 PM

Suggested questions:

Powered by EmpowerID AI