OATHERA logo OATHERA
Platform Features Integrations Use cases Developers Security Contact Request access

Platform

One identity model for every agent you run.

OATHERA treats an AI agent as a first class principal. Before it can touch anything, it must have an identity it can prove, an owner who answers for it, and a boundary that limits it. The control plane issues, enforces, observes and revokes all three.

On this page

  1. Agent identity
  2. Accountable ownership
  3. Operational boundary
  4. Control plane
  5. Defense in depth

1. Agent identity

A credential that cannot be borrowed.

Each agent generates its own Ed25519 key pair inside your environment. OATHERA issues short lived identity tokens bound to that key and to the attested machine, and requires a fresh RFC 9421 signature over every request. Steal the token and it fails: the thief has neither the key nor the machine. Identities interoperate with OIDC and SPIFFE, so agents fit the workload identity fabric you already run.

2. Accountable ownership

No orphan agents.

Every agent is enrolled against a named human or organizational owner. The owner approves the agent once, and that approval is sealed into a tamper evident audit certificate. Ownership travels with the identity, so every log line, policy decision and alert answers the question "whose agent is this?" When an owner leaves or a team changes, OATHERA flags the agents that need a new owner or a shutdown.

3. Operational boundary

A perimeter drawn around each agent.

The operational boundary is the high level envelope of what an agent may do: which tenants, systems, data classes and operations are in scope, and which are never in scope. It is set at approval and travels inside the agent's identity. Two layers enforce it:

  • Fine grained authorization with OPA. Open Policy Agent evaluates every request against the boundary and your Rego policies, down to the tenant, agent, task, capability, operation and resource.
  • Runtime confinement with NVIDIA OpenShell. OpenShell sandboxes confine what the agent's process can reach on the host: files, network destinations and privileges, enforced outside the agent where it cannot override them.

4. Control plane

The system of record for your agents.

The OATHERA control plane is where agents are enrolled, approved, scoped, monitored and revoked. It holds the inventory of every agent, its owner and its boundary, distributes policy to gateways and sandboxes, and collects telemetry from every enforcement point into one trace.

Defense in depth

LayerQuestion it answersEnforced by
RequestIs this really the agent it claims to be, on the machine it was issued for?OATHERA gateway, sender constrained tokens, RFC 9421 signatures
PolicyIs this exact action allowed for this agent, owner and task?Open Policy Agent
RuntimeCan the agent's process physically reach this file, host or privilege?NVIDIA OpenShell
RecordCan we prove what happened afterward?OATHERA control plane, audit certificates
← Back to OATHERA
OATHERA logo OATHERA

The agentic identity platform. Verifiable, human-approved, short-lived identity for every AI agent.

Product

  • Platform
  • Features
  • Integrations
  • Use cases

Developers

  • Docs
  • GitHub
  • Demo

Company

  • Security
  • Contact
  • Careers soon

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
© 2026 OATHERA · Agentic Identity Platform

Cookie preferences

We use cookies to run this site and, with your consent, to understand usage and improve OATHERA. Strictly necessary cookies are always on; you can choose whether to allow analytics and marketing cookies below.

  • Strictly necessaryAlways on

    Required for the site to work — security, load balancing, and remembering your cookie choices. These cannot be switched off.

  • Help us measure traffic and see how the site is used, so we can improve it. No personal profiles are built.

  • Used to make messages about OATHERA more relevant across other sites. Off unless you turn it on.