The gap
Four categories touch this. None of them owns it.
Not a competitive slight — a structural fact. Each was built for a different actor, and an agent is not that actor.
| Category | What it governs | Enforcement | Human approval | Audit |
|---|---|---|---|---|
| Identity providersOkta · Auth0 · Entra | People, at login | Not their model | — | Login events only |
| Bot managementCloudflare · Akamai | Bot or not, at the edge | Block or allow | — | Traffic logs |
| Secret managersVault · AWS SM | Keys, at fetch | Who may read a key | — | Read events |
| Agent frameworksLangChain · CrewAI | Nothing — they orchestrate | In-process, trusted | Ad hoc, in code | Traces, unsigned |
| authoxithe enforcement point | Which actor, of what kind, acting for whom | Per action, four outcomes | Signed, non-repudiable | Signed, offline-verifiable |
Never a key vault
Agents never hold provider credentials. The enforcement point does — inside your own boundary if you self-host, or sealed under your KMS if you don't. A vault hands the key over and hopes; this never hands it over.
Design partners
Bring one agent.
Design partners get the gate, the signed evidence and a direct line to the people building it. One field — we will not make you fill in a form to find out what this costs.
Request access
One email. Leave in one click. We never sell it.