The employee left. The agent did not.
Credentials and delegations survive offboarding.
The authority plane for AI agents
Your agent's identity, connection and token are all valid. None of that proves your organisation still authorises the exact action it is about to take.
How it works
Delegrity sits between your agents and the systems they change. It consults the controls you already run, decides on the exact action, and returns signed evidence of what happened.
What Delegrity checks
For developers
An agent submits a proposal to POST /runtime/tool-requests. What comes back is an authority decision; execution stays NOT_DISPATCHED.
REST, MCP, A2A and agent framework SDK wrapper request forms are registered and reach one governed endpoint, POST /runtime/tool-requests, for governed tools such as update_supplier_bank_account. Registered is not connected: there is no standalone MCP or A2A listener, and no live framework or provider connectivity is claimed.
RequestsubmitPublicAgentToolRequest
POST /runtime/tool-requests
Authorization: Bearer <workload token>
Idempotency-Key: req-7f2a91c4
Content-Type: application/json
{
"request_id": "req-7f2a91c4",
"agent": {
"agent_id": "00000000-0000-4000-8000-00000000a9e7",
"session_id": "00000000-0000-4000-8000-0000000051c2"
},
"tool": {
"name": "update_supplier_bank_account",
"arguments": {
"supplier_id": "sup-00482",
"account_number": "0000 0000 9930",
"country_code": "GB",
"routing_code": "00-00-00",
"beneficiary_name": "Example Supplies Ltd",
"reason": "Supplier emailed new bank details"
}
},
"context": {
"instruction": "Update the supplier's bank account from the latest email",
"timestamp": "2026-09-29T10:15:00Z"
}
}Response201 · publicToolResponse
{
"request_id": "req-7f2a91c4",
"decision": "AWAITING_APPROVAL",
"reason": {
"code": "APPROVAL_REQUIRED",
"message": "Beneficiary change needs a human decision on this digest."
},
"execution": {
"status": "NOT_DISPATCHED",
"connector_invoked": false
},
"correlation_id": "corr-3c9d0e12",
"replayed": false
}AWAITING_APPROVAL is a decision, not a result: nothing is dispatched until a person approves this exact digest and the recheck passes.
For your security review
Each capability declares its mode: Observed, Assisted, Enforced or Hybrid. We say Enforced only where a non-bypassable enforcement point is proven.
Questions
We start as a design partner on one consequential workflow, at no platform commitment. A pilot then runs one protected capability in your environment, scoped and priced with you. There is no self-serve tier or per-seat menu yet.
No. It works beside them. Delegrity consults your policy engine through AuthZEN-compatible policy consultation, binds your approvals to the exact action, and keeps your identity provider as the source of who an agent is.
REST, MCP, A2A and agent framework SDK wrapper request forms are registered and reach one governed endpoint, POST /runtime/tool-requests, for governed tools such as update_supplier_bank_account. Registered is not connected: there is no standalone MCP or A2A listener, and no live framework or provider connectivity is claimed.
Hosting and credential custody are agreed per deployment. A customer-hosted enforcement bridge is part of the enterprise scope, so execution credentials can stay in your environment.
An evidence chain hashed with SHA-256 and a receipt with an Ed25519 detached signature, checkable by an independent verifier. Completeness is shown explicitly, and an unsigned receipt is labelled unsigned.
Not yet claimed. Delegrity is at design-partner stage, with no production customer evidence and no independent certification so far. We would rather say so than overclaim.
Request a demo