- First-party authorization — What can the agent do inside your own application? One common pattern is to model agents as first-class principals in your authorization model so they participate in the same permission hierarchy as users. For example, an agent with project membership can read all issues in that project. See Modeling Agents as Principals.
- Third-party authorization — What can the agent do in external systems (Slack, Jira, GitHub, etc.)? Because you do not control those systems, you model permissions around the tools and resources the agent can access, and narrow the scope beyond what the external credential allows. See Authorization for MCP Servers and RAG Authorization — both patterns also apply to first-party resources.
When to useThe content in this section is useful if you are building AI agents or automated systems that need fine-grained, scoped permissions to perform actions on behalf of users.
Task-Based Authorization
Grant agents access to perform specific actions only when necessary, without granting permanent permissions.
RAG Authorization
Ensure AI agents only retrieve documents users are authorized to access.
Authorization for MCP Servers
Control which tools each user can access on an MCP server based on roles, group membership, and temporal grants.
Modeling Agents as Principals
Model agents as first-class principals in a user-centric authorization model so they inherit access through the same permission hierarchy as users.