Security architecture
For security and enterprise architects: how Authesta makes an agent’s consequential actions bounded, enforced and provable.
On this page
Deterministic policy enforcement
Decisions come from explicit rules in the agent’s authority profile, evaluated against the exact request. The same request under the same authority always gets the same decision, and every decision records which rule produced it.
No LLM in the allow or deny path
No language model takes part in deciding whether an action is allowed, needs authorization or is denied. Agents may be built on models; the authority decision about them is not.
Agent authentication
Every protected call carries the agent’s own credential. The agent and its organization are taken from the verified credential, never from identifiers in the request body. An integration key only routes a call; it is never accepted as proof of identity.
Calls with a missing, wrong, revoked or expired credential, or with another agent’s credential, are refused.
Exact grant binding
An authorization is bound to the exact action and parameters that were decided or approved, to the agent, and to the organization. A grant for one purchase order cannot be used for a different amount, vendor or agent.
Single use
Each grant can be consumed once. Consumption is atomic, so two concurrent attempts cannot both succeed.
Anti-replay
Used, expired and unknown grants are refused. Approvals expire if they aren’t used within their window.
Tenant isolation
Agents, authority profiles, credentials, approvals and evidence are scoped to one organization. Cross-organization references are rejected, including in the database itself for gateway assignments.
Suspension and revocation
Agents, credentials, organizations and Private Gateways can each be suspended or revoked. Authesta Cloud applies this immediately; Private Gateways apply it with their next signed update.
Signed policy state
Private Gateways enforce only policy, agent identity and entitlements signed by Authesta, and refuse to roll back to an older policy version.
Bounded offline operation
A Private Gateway that loses contact with Authesta Cloud trusts its signed identity for a bounded window only. After that it stops serving protected actions. Actions that need human authorization fail closed while Cloud is unreachable.
Private Gateway
Target-system credentials and the execution connection stay inside your environment. Evidence is synchronized to Authesta Cloud; the credentials are not. More about Private Gateway.
Fail-closed behavior
When Authesta cannot establish authority — an unknown agent, a missing profile, an invalid signature, stale state or an unreachable dependency the decision needs — the action does not run.
Execution provenance
Each executed value is recorded with where it came from: the target system’s response, an independent observation, an echo of the request, or the agent’s own report. Only the first two can establish a match.
Verification
MATCH requires every authorized field to be observed and to match. Anything that can’t be independently confirmed is recorded as NOT VERIFIABLE, and a conflict as DEVIATION.
Evidence
Each protected action has one record: request, agent, rule, decision, approver, execution and verification. Evidence never contains credentials or secrets.
Certifications
Authesta is an early-stage company and does not yet hold third-party certifications such as SOC 2 or ISO 27001. During a pilot we walk your security team through the architecture and answer your questionnaire.