The gap

Four categories touch this. None of them owns it.

Not a competitive slight — a structural fact. Each was built for a different actor, and an agent is not that actor.

CategoryWhat it governsEnforcementHuman approvalAudit
Identity providersOkta · Auth0 · EntraPeople, at loginNot their model—Login events only
Bot managementCloudflare · AkamaiBot or not, at the edgeBlock or allow—Traffic logs
Secret managersVault · AWS SMKeys, at fetchWho may read a key—Read events
Agent frameworksLangChain · CrewAINothing — they orchestrateIn-process, trustedAd hoc, in codeTraces, unsigned
authoxithe enforcement pointWhich actor, of what kind, acting for whomPer action, four outcomesSigned, non-repudiableSigned, offline-verifiable

Never a key vault

Agents never hold provider credentials. The enforcement point does — inside your own boundary if you self-host, or sealed under your KMS if you don't. A vault hands the key over and hopes; this never hands it over.

Design partners

Bring one agent.

Design partners get the gate, the signed evidence and a direct line to the people building it. One field — we will not make you fill in a form to find out what this costs.

Request access

One email. Leave in one click. We never sell it.

One field. One click to leave. Never sold.