Skip to main content

New: Malicious MCP server caught in the wild!

Permissions break down when an agent holds them

An agent runs with the user's identity and reaches every system that identity can. Knostic extends least privilege to the agent's actions: what it may read, run, connect to, and install.

IAM governs the user. The agent is not the user.

Role-based access is solid in your applications. But an agent acting for a developer inherits everything that developer can touch, and uses it in ways no human would in one session. Knostic applies a second layer of policy to the agent itself.

How Knostic extends IAM to agents

Consistent entitlements

Before Knostic

Each agent has its own controls for autonomy, secrets, and connectors, set differently by every user. Least privilege is a hope.

After Knostic

One policy defines what agents may do per group, applied identically across every tool, with drift flagged.

Actions, not just access

Before Knostic

The agent has write access to production, because the developer does. It uses it.

After Knostic

Destructive and sensitive operations are denied or escalated at the tool call, regardless of what the underlying identity could do.

Connector trust

Before Knostic

An MCP server the agent connected to has broad permissions and nobody reviewed it.

After Knostic

Connections are validated in real time, unapproved servers blocked, and every server, skill, and extension vetted by AgentMesh.

Key capabilities

Per-group agent policy

Map groups from your directory to agent allowances for autonomy, data, and connectors.

MCP connection control

Allow-list servers, validate every connection, and block unapproved or misconfigured ones.

Credential protection

Keys and tokens in prompts, context, and outputs are caught before they leave the agent.

Over-permission alerts

Flag agents operating with more reach than policy intends.

Decision logs

Every allowed and denied agent action, with the identity and policy behind it.

Monitor to enforce

Baseline agent behaviour before tightening the rules.

Frequently asked questions

No. IAM decides what the user can access. Knostic decides what the agent acting for that user may actually do, and in which tools.

Yes. Policies are assigned per team or group, so contractors, developers, and analysts run agents under different rules.

Kirin maintains the list of allowed servers, validates every connection, and blocks rogue or misconfigured ones. AgentMesh scans the servers themselves for malicious behaviour.

To the Kirin dashboard and your SIEM, with the user identity, the agent, the action, and the policy outcome.