Skip to main content

AI Access & MCP

AI Access separates authentication from authorization.
A display name alone is never authentication.

AI Identity

Interactive AI uses OAuth Authorization Code verification where supported. Automation/custom AI can use OAuth Client Credentials where supported.

Permission Objects

Examples include host-info, process-read, file-read, command-exec, file-write, file-upload, and file-download. A true read-only permission set does not include command execution.

AI Access Rule

AI Access Rules are not ordered and have no per-rule action. AI authentication remains mandatory even when policy enforcement is disabled. The v2.4 target uses a server-side MCP Bridge over authenticated HTTPS. MCP does not bypass Agent identity, AI Access policy, or target OS permissions. Remote Services and SSH are not prerequisites for approved AI operations.
Last modified on September 22, 2026