Concepts
Learn how SecureAuth Agent Authority's core concepts fit together — agents, resources, policies, tags, connections, and credential modes.
SecureAuth Agent Authority's core concepts define the vocabulary the rest of these docs assume: how agents and resources meet at the gateway, and how policies, data protection, tags, connections, and credential modes decide, redact, and record what happens on every call. Start with How it works for the big picture, or jump straight to the term you need in the glossary.
How it works
How SecureAuth Agent Authority authenticates, authorizes, and audits every MCP tool call.
Agent Registry
How agents and agent instances relate, and where each is managed.
Resources
Add catalog and custom MCP servers to your gateway.
Policies
Define security policies that control which tools agents can use.
Data protection
Redact sensitive data out of tool responses before an agent ever sees it.
Tags
Organize agents, MCPs, and tools with labels you can match in policies.
Connections
How users link their accounts to third-party services.
Credential modes
How an organization chooses which OAuth app the gateway uses for a catalog resource.
Agent Topology
A live map of which agents can reach which resources, and the policies in between.
Users
One person's agents, resources, and spend in a single view.
User portal
The self-service pages your non-admin users get, and how they differ from the admin console.
Glossary
Definitions for every term Agent Authority uses, with links back to the deep guides.
Next steps
- How it works — the request-flow model behind every concept here.
- Get started — put these concepts into practice in about 30 minutes.
Sandbox an agent to one Slack channel
Scope a SecureAuth Agent Authority policy so an agent can only read and post in one designated Slack channel, not your whole workspace.
How it works
How SecureAuth Agent Authority authenticates, authorizes, and audits every MCP tool call between your AI agents and your services.