Features
Everything an agent needs to be trusted, and nothing it does not.
Identity and credentials
Per agent cryptographic identity
Every agent gets its own Ed25519 key, generated locally and never exported. No shared secrets, ever.
Short lived, sender constrained tokens
Tokens expire in minutes and only work when presented with the agent's key from the machine they were issued to.
Per request proof of possession
Each call carries a single use RFC 9421 HTTP Message Signature over that exact method, path and body, so requests cannot be replayed or altered.
Machine attestation
The local identity helper inspects the host at enrolment and binds the identity to it.
Standards based federation
Works with OIDC identity providers and SPIFFE workload identity, so agents join your existing trust domains.
Ownership and lifecycle
Named owner for every agent
Each agent is bound to a person or an organizational unit, visible on every log and decision.
Human in the loop enrolment
A person approves each agent once; nothing runs on an unapproved identity.
Tamper evident audit certificates
Every approval is signed and chained so it can be verified later.
Lifecycle controls
Suspend, rotate, transfer ownership or revoke an agent from the control plane, with effect within one token lifetime.
Orphan detection
Find agents whose owner has left, whose boundary is stale, or that have not run in a set period.
Boundaries and authorization
Operational boundaries
Define the high level envelope per agent: tenants, systems, data classes, operations and explicit exclusions.
OPA policy engine
Fine grained decisions in Rego on tenant, agent, owner, task, capability, operation and resource, evaluated on every request.
Policy as code
Version, review and test policies in Git; promote them through environments like any other code.
Fail closed by default
If identity, signature or policy cannot be verified, the request is refused.
Runtime enforcement
NVIDIA OpenShell integration
Launch agents in OpenShell sandboxes whose file, network and privilege limits are derived from the agent's OATHERA boundary.
Kernel level confinement
OpenShell uses Linux kernel controls such as Landlock to confine filesystem access to declared paths, outside the agent's reach.
Egress control
Outbound connections pass through a policy enforcing proxy, so an agent can only reach approved destinations.
Boundary to sandbox mapping
One boundary, enforced consistently at the gateway, in OPA and on the host.
Telemetry and observability
Unified agent trace
Follow one action from token issuance through gateway, policy decision and sandbox activity in a single timeline.
Decision logs
Every allow and deny with the identity, owner, boundary and policy version that produced it.
Live agent inventory
Every agent, its owner, boundary, last activity and risk signals in one view.
Anomaly signals
Flag denials spikes, boundary edge probing, unusual destinations and off hours activity.
Export anywhere
Stream events to your SIEM and observability stack through OpenTelemetry and standard log formats.