Skip to content
Agentic Security

Every agent credential, traced back to who delegated it.

AI agents don't just hold credentials — they hand them to sub-agents and MCP tools. GraphDefend issues each agent a short-lived, scoped credential, signs the whole delegation chain, ensures authority only narrows as it passes down, and lets you cut off one misbehaving branch without stopping the rest.

  • Signed delegation chains
  • Just-in-time MCP credentials
  • Branch-level kill
Delegation chainIllustrative
Illustrative agent delegation chain with a branch-killA platform team delegates to an orchestrator agent, which delegates to a research sub-agent and a deploy sub-agent, each using an MCP tool. Every hop is signed and each child holds a narrower scope than its parent. The deploy branch is killed; the research branch keeps running.AUTHORITY NARROWSPlatform teamDelegates the taskOrchestrator agentrepo · deploy · ticketsResearch sub-agentrepo:readMCP · code searchDeploy sub-agentdeployMCP · CI/CDBranch killedStill running
Signed hop Scope narrows Branch-kill
Why agents break identity

Your identity model was built for accounts, not delegation

An inventory tells you which identities exist. Agents raise a different question: who handed which access to whom — and what happens when one link goes wrong.

Agents delegate — they don't just authenticate

An orchestrator hands work — and access — to sub-agents and tools nobody provisioned directly. The chain of who-gave-what is where the risk lives.

Standing secrets outlive the task

A key pasted into an agent's config keeps working long after the job it was created for has finished.

One rogue agent, fleet-wide shutdown

Without lineage, the only safe response to a compromised agent is to stop everything that might be related to it.

How it works

Discover. Scope. Trace. Sever.

One control plane for the whole life of an agent's access.

  1. 01

    Discover

    Find MCP servers, agent tooling and AI-provider keys in the environments you connect.

  2. 02

    Scope

    Issue just-in-time, least-scope credentials — and deny unknown MCP backends.

  3. 03

    Trace

    Sign every hop of delegation, so each credential carries its full chain.

  4. 04

    Sever

    Kill one branch of the chain; siblings keep running.

Capabilities

Built for how agents actually use access

Six capabilities — with their limits stated where they exist, not hidden.

Delegated authority can only narrow

When an agent delegates to a sub-agent, the child's credential is checked against its verified parent at the moment it's issued: it can't hold a scope the parent doesn't have, and it can't outlive the parent's credential. The ceiling is re-derived from the signed parent credential — never from what the request claims — and it holds on every backend GraphDefend brokers, not just MCP.

Ask any agent-security vendor: can a sub-agent ever end up with more access than the agent that created it?

Applies to credentials issued through GraphDefend.

Authority at each hop

Illustrative
ScopeLifetime
  • Orchestrator
    repodeploytickets

    sets the ceiling

  • Sub-agent
    repo:read

    ≤ parent

  • Tool call
    repo:read

    ≤ parent

Sub-agent requests secrets:write— a scope its parent doesn't hold. Denied at issuance.

Signed delegation lineage

Every credential GraphDefend issues carries a signed record of the chain that requested it — with delegation depth capped at three hops — built on the OAuth 2.0 Token Exchange standard (RFC 8693). An investigation starts from a verifiable chain, not a log search.

Just-in-time MCP credentials

Agents and MCP clients receive short-lived, least-scope credentials at the moment they need them, so an agent never inherits a standing credential from GraphDefend. MCP backends that aren't on your allowlist are denied by default.

Branch-kill with dry-run preview

Preview what a kill will cut with a dry run, then sever one delegation branch in a single action: every credential GraphDefend brokered down that branch is severed and can't be reissued. Sibling agents and the rest of your fleet keep running.

A credential created outside GraphDefend — such as a long-lived cloud key — is contained at its next use or expiry, not disabled at the provider.

MCP tool poisoning & rug-pull detection

GraphDefend enumerates the tools remote MCP servers expose and baselines their descriptions — flagging hidden instructions in a tool description, and silent changes after a tool was first seen. It also finds MCP servers configured for Claude Code, Cursor, GitHub Copilot and Windsurf on the hosts you connect, and inventories OpenAI and Anthropic organization keys, projects and service accounts.

Detection raises alerts; it does not block. Tool enumeration covers remote MCP servers (opt-in); local stdio servers are not enumerated yet. Agent-tool configs are found on hosts you point discovery at.

Provenance-gated enforcement

Enforcement only acts on identity data whose origin GraphDefend can prove. Identities reported by attested collectors are eligible for enforcement; identities found through read-only discovery are visibility-only by design — so enforcement rests on a verified source, not on whatever a scan reports.

Honest by design

We mark the edges of what we can see

Dashboards that look complete are how blind spots survive. GraphDefend states its limits in the product — and on this page.

  • MCP tool permissions

    The MCP protocol's tool listing carries no permission information, so a server's tool permissions are shown as unknown rather than guessed.

  • Local MCP servers

    Remote MCP servers can be enumerated; servers running over local stdio can't yet — and are reported as a gap, not as zero.

  • Credentials minted elsewhere

    A branch-kill stops everything GraphDefend issued. A key created directly at a cloud provider is contained at its next use or expiry.

Built on open standards

GraphDefend speaks the protocols your stack already runs on — so delegation, workload identity and policy stay verifiable outside our platform, not locked inside it.

See the full capability list
  • RFC 8693OAuth 2.0 Token Exchange — signed delegation chains
  • Model Context ProtocolTool discovery and credential brokering for MCP
  • SPIFFECryptographic workload identity between services
  • Open Policy AgentPolicy evaluated at credential issuance

See a branch-kill before you need one

Walk through signed delegation lineage, just-in-time MCP credentials and a dry-run branch-kill with our team.