Concepts
The core ideas behind SecureAuth Agent Authority, and how each one shapes what happens on a tool call.
These pages define the terms the rest of the documentation uses. Together they describe how your agents reach your services through the gateway, and what decides, redacts, and records each call along the way. Start with How it works for the model behind all of it, or go straight to the term you need in the glossary.
How it works
How SecureAuth Agent Authority authenticates, authorizes, and audits every MCP tool call between your AI agents and your services.
Agent Registry
How agents and agent instances relate, and where each is managed
Resources
Add catalog and custom MCP servers to your gateway
Access Policies
Define security policies that control which tools agents can use
Data Protection
Redact sensitive data from tool responses before it reaches an agent
Rate limits
Cap how fast agents can call tools, org-wide or split further by user, agent, or tool
Inference
Choose the model your organization's DLP judge runs on
Tags
Organize agents, MCPs, and tools with labels you can match in policies
Connections
How users link their accounts to third-party services
Credential modes
How an organization chooses which OAuth app the gateway uses for a catalog resource
Authority Graph
A live map of how groups, agents, and policies reach your MCP servers
Users
One person's agents, tool calls, and spend on one page
Roles
The three built-in roles, custom roles, and how assigning one widens what a person can do
User portal
How to share the user portal link, the five pages a non-admin sees, and how the portal differs from the admin console
Glossary
Definitions for the terms Agent Authority uses: tenants, workspaces, agents, agent instances, resources, connections, policies, tags, and credential modes.
Next steps
- How it works – the request-flow model behind every concept here.
- Get started – put these concepts into practice in about 30 minutes.