Every agent credential, traced back to who delegated it.
AI agents don't just hold credentials — they hand them to sub-agents and MCP tools. GraphDefend issues each agent a short-lived, scoped credential, signs the whole delegation chain, ensures authority only narrows as it passes down, and lets you cut off one misbehaving branch without stopping the rest.
- Signed delegation chains
- Just-in-time MCP credentials
- Branch-level kill
Your identity model was built for accounts, not delegation
An inventory tells you which identities exist. Agents raise a different question: who handed which access to whom — and what happens when one link goes wrong.
Agents delegate — they don't just authenticate
An orchestrator hands work — and access — to sub-agents and tools nobody provisioned directly. The chain of who-gave-what is where the risk lives.
Standing secrets outlive the task
A key pasted into an agent's config keeps working long after the job it was created for has finished.
One rogue agent, fleet-wide shutdown
Without lineage, the only safe response to a compromised agent is to stop everything that might be related to it.
Discover. Scope. Trace. Sever.
One control plane for the whole life of an agent's access.
- 01
Discover
Find MCP servers, agent tooling and AI-provider keys in the environments you connect.
- 02
Scope
Issue just-in-time, least-scope credentials — and deny unknown MCP backends.
- 03
Trace
Sign every hop of delegation, so each credential carries its full chain.
- 04
Sever
Kill one branch of the chain; siblings keep running.
Built for how agents actually use access
Six capabilities — with their limits stated where they exist, not hidden.
Delegated authority can only narrow
When an agent delegates to a sub-agent, the child's credential is checked against its verified parent at the moment it's issued: it can't hold a scope the parent doesn't have, and it can't outlive the parent's credential. The ceiling is re-derived from the signed parent credential — never from what the request claims — and it holds on every backend GraphDefend brokers, not just MCP.
Ask any agent-security vendor: can a sub-agent ever end up with more access than the agent that created it?
Applies to credentials issued through GraphDefend.
Authority at each hop
Illustrative- Orchestratorrepodeploytickets
sets the ceiling
- Sub-agentrepo:read
≤ parent
- Tool callrepo:read
≤ parent
Sub-agent requests secrets:write— a scope its parent doesn't hold. Denied at issuance.
Signed delegation lineage
Every credential GraphDefend issues carries a signed record of the chain that requested it — with delegation depth capped at three hops — built on the OAuth 2.0 Token Exchange standard (RFC 8693). An investigation starts from a verifiable chain, not a log search.
Just-in-time MCP credentials
Agents and MCP clients receive short-lived, least-scope credentials at the moment they need them, so an agent never inherits a standing credential from GraphDefend. MCP backends that aren't on your allowlist are denied by default.
Branch-kill with dry-run preview
Preview what a kill will cut with a dry run, then sever one delegation branch in a single action: every credential GraphDefend brokered down that branch is severed and can't be reissued. Sibling agents and the rest of your fleet keep running.
A credential created outside GraphDefend — such as a long-lived cloud key — is contained at its next use or expiry, not disabled at the provider.
MCP tool poisoning & rug-pull detection
GraphDefend enumerates the tools remote MCP servers expose and baselines their descriptions — flagging hidden instructions in a tool description, and silent changes after a tool was first seen. It also finds MCP servers configured for Claude Code, Cursor, GitHub Copilot and Windsurf on the hosts you connect, and inventories OpenAI and Anthropic organization keys, projects and service accounts.
Detection raises alerts; it does not block. Tool enumeration covers remote MCP servers (opt-in); local stdio servers are not enumerated yet. Agent-tool configs are found on hosts you point discovery at.
Provenance-gated enforcement
Enforcement only acts on identity data whose origin GraphDefend can prove. Identities reported by attested collectors are eligible for enforcement; identities found through read-only discovery are visibility-only by design — so enforcement rests on a verified source, not on whatever a scan reports.
We mark the edges of what we can see
Dashboards that look complete are how blind spots survive. GraphDefend states its limits in the product — and on this page.
MCP tool permissions
The MCP protocol's tool listing carries no permission information, so a server's tool permissions are shown as unknown rather than guessed.
Local MCP servers
Remote MCP servers can be enumerated; servers running over local stdio can't yet — and are reported as a gap, not as zero.
Credentials minted elsewhere
A branch-kill stops everything GraphDefend issued. A key created directly at a cloud provider is contained at its next use or expiry.
Built on open standards
GraphDefend speaks the protocols your stack already runs on — so delegation, workload identity and policy stay verifiable outside our platform, not locked inside it.
- RFC 8693OAuth 2.0 Token Exchange — signed delegation chains
- Model Context ProtocolTool discovery and credential brokering for MCP
- SPIFFECryptographic workload identity between services
- Open Policy AgentPolicy evaluated at credential issuance
See a branch-kill before you need one
Walk through signed delegation lineage, just-in-time MCP credentials and a dry-run branch-kill with our team.