OATHERA logo OATHERA
Platform Features Integrations Use cases Developers Security Contact Request access

Features

Everything an agent needs to be trusted, and nothing it does not.

On this page

  1. Identity and credentials
  2. Ownership and lifecycle
  3. Boundaries and authorization
  4. Runtime enforcement
  5. Telemetry and observability

Identity and credentials

Per agent cryptographic identity

Every agent gets its own Ed25519 key, generated locally and never exported. No shared secrets, ever.

Short lived, sender constrained tokens

Tokens expire in minutes and only work when presented with the agent's key from the machine they were issued to.

Per request proof of possession

Each call carries a single use RFC 9421 HTTP Message Signature over that exact method, path and body, so requests cannot be replayed or altered.

Machine attestation

The local identity helper inspects the host at enrolment and binds the identity to it.

Standards based federation

Works with OIDC identity providers and SPIFFE workload identity, so agents join your existing trust domains.

Ownership and lifecycle

Named owner for every agent

Each agent is bound to a person or an organizational unit, visible on every log and decision.

Human in the loop enrolment

A person approves each agent once; nothing runs on an unapproved identity.

Tamper evident audit certificates

Every approval is signed and chained so it can be verified later.

Lifecycle controls

Suspend, rotate, transfer ownership or revoke an agent from the control plane, with effect within one token lifetime.

Orphan detection

Find agents whose owner has left, whose boundary is stale, or that have not run in a set period.

Boundaries and authorization

Operational boundaries

Define the high level envelope per agent: tenants, systems, data classes, operations and explicit exclusions.

OPA policy engine

Fine grained decisions in Rego on tenant, agent, owner, task, capability, operation and resource, evaluated on every request.

Policy as code

Version, review and test policies in Git; promote them through environments like any other code.

Fail closed by default

If identity, signature or policy cannot be verified, the request is refused.

Runtime enforcement

NVIDIA OpenShell integration

Launch agents in OpenShell sandboxes whose file, network and privilege limits are derived from the agent's OATHERA boundary.

Kernel level confinement

OpenShell uses Linux kernel controls such as Landlock to confine filesystem access to declared paths, outside the agent's reach.

Egress control

Outbound connections pass through a policy enforcing proxy, so an agent can only reach approved destinations.

Boundary to sandbox mapping

One boundary, enforced consistently at the gateway, in OPA and on the host.

Telemetry and observability

Unified agent trace

Follow one action from token issuance through gateway, policy decision and sandbox activity in a single timeline.

Decision logs

Every allow and deny with the identity, owner, boundary and policy version that produced it.

Live agent inventory

Every agent, its owner, boundary, last activity and risk signals in one view.

Anomaly signals

Flag denials spikes, boundary edge probing, unusual destinations and off hours activity.

Export anywhere

Stream events to your SIEM and observability stack through OpenTelemetry and standard log formats.

← Back to OATHERA
OATHERA logo OATHERA

The agentic identity platform. Verifiable, human-approved, short-lived identity for every AI agent.

Product

  • Platform
  • Features
  • Integrations
  • Use cases

Developers

  • Docs
  • GitHub
  • Demo

Company

  • Security
  • Contact
  • Careers soon

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
© 2026 OATHERA · Agentic Identity Platform

Cookie preferences

We use cookies to run this site and, with your consent, to understand usage and improve OATHERA. Strictly necessary cookies are always on; you can choose whether to allow analytics and marketing cookies below.

  • Strictly necessaryAlways on

    Required for the site to work — security, load balancing, and remembering your cookie choices. These cannot be switched off.

  • Help us measure traffic and see how the site is used, so we can improve it. No personal profiles are built.

  • Used to make messages about OATHERA more relevant across other sites. Off unless you turn it on.