Constrain what the agent can attempt
Identity, tenant, role, data classification, risk, region, and workflow policy determine the available path before a model can call a tool.
- SSO, RBAC/ABAC, and tenant isolation
- Approved tools and schema-constrained inputs
- PII, secrets, and regional data boundaries
- Risk-based approval and deny rules
