Platform holds approved credential
- Policy permits action
- Mediator retrieves from vault
- Inject at dispatch
- Agent receives result only
Solution
Policy decides on the exact action. The execution boundary acquires and applies credentials so the agent receives a governed result, not standing custody.
Illustrative workflow — not a live product screenshot. Scope and coverage apply.
Three lanes show where the reusable credential is held versus what the agent receives.
Reusable credential enclosed here
Applies to declared governed routes and controlled credential ingress paths. Does not include interactive RDP/SSH session proxying as a substitute for this model.
An opaque handle must not be independently redeemable by the agent or usable outside the governed execution boundary.
| Approach | Who holds secret | Duration | Reuse | Decision point | Evidence | Posture |
|---|---|---|---|---|---|---|
| Inject at the boundary | Vault / mediator at execution boundary | Action-bound | None in agent context | PEP at governed route | Consumption + dispatch records | EmpowerID default on governed routes |
| Broker short-lived, action-bound authority | Broker for narrow window | Single action or mission turn | Limited to bound scope | Policy + broker policy | Broker issuance + outcome link | Supported where broker integrates with spine |
| Hand over and revoke later | Agent or model context | Standing until revoked | High | After custody transfer | Revoke events only — not non-custody proof | Not our model |
Secrets pasted or returned into model context require capture-and-substitute controls; output redaction alone is not equivalent.
Stronger ingress-control path: capture-and-substitute at the governed boundary (connector and deployment scope apply).
May: Evaluate policy and issue decision
Must not: Hold reusable credentials or dispatch directly
May: Bind arguments and enforce permit consumption
Must not: Override policy or store long-lived secrets in agent context
May: Acquire and apply credentials inside boundary
Must not: Authorize actions without policy decision
May: Send bound request to target
Must not: Expand scope beyond consumed permit
Illustrative exposure ledger
| Identity / agent | Reachable credential | Mediated target | Purpose / mission | Last use | Expiry | Recert owner | Custody mode | Evidence |
|---|---|---|---|---|---|---|---|---|
| FinanceCloseAssistant | SAP service account (mediated) | ERP read API | Month-end read mission | Last governed turn | Mission-bound | Finance Ops | No standing secret in agent context | Dispatch + read-back on declared path |
| UnregisteredCopilotExtension | Unknown — not on governed path | HTTP egress | Unknown | Not observed on declared path | N/A | Unresolved | Review required | Gap — not on governed path |
Online
Powered by EmpowerID AI