Agent Authority Plane

Connection is not permission.

Okta, Auth0, and Entra already answer who may connect. A\UTH.io sits on the request path and answers the next question: what this attested instance may do, right now, on whose behalf, within what limits — and proves it.

We broker the IdP. We do not replace it. Instances and decisions are never metered.

The names already on the shelf.

A grant answers connection. It does not shrink as it is handed down, and it does not die across every region in two seconds. That gap is the product.

Issuance
Okta · Auth0 · Entra
Who may connect. We take ID-JAG and XAA as the chain root.
Action
A\UTH.io
What this instance may do on this call.
Observation
Permiso
Was it normal. We emit the trace. We do not become ITDR.
  • ≤ 1.5 msCheck, in-pod
  • ≤ 2 sKill a chain, globally
  • ≤ 30 minFirst guarded call
  • UnmeteredInstances and decisions

Four ways the call goes wrong.

Pick the job you already have. The diagram is the same path your platform team argues about — issuance, the envelope, the decision, the resource.

tools/call repo.delete · Check returns ALLOW_WITH_OBLIGATION · the call waits for a person

Case

The reviewer kept delete.

Alice connected a coding agent through Okta. The grant included repo.delete. The agent spawned a reviewer, and the reviewer kept delete. The call reached the repository. Permiso could say so the next morning. Nothing on the path had made the child smaller than the parent.

Already there
Okta answered who may connect. Permiso recorded what happened.
The gap
The child held the parent’s delete. The call did not wait.
The close
The child envelope never contained it. The repository was not called.

A short list, for the people who feel this gap.

Design partners. Tell us the job. This preview keeps your place in this browser only — nothing is sent until the site is live.