Large environments already paid for routing, content safety and host telemetry. What those leave open is the agent over time: its identity, what it reached across stores and tools, who approved a risky call, and whether any of it can be proven. That is the kernel’s job.
What scales, and how far
- A tenant-scoped store: persisted entities carry a tenant. That is data-model tenancy, not a completed multi-tenant isolation certification.
- Identity federation: read-only snapshots and rules you declare. Roster connectors ingest Microsoft Entra Agent ID, AWS Bedrock AgentCore and Google agent registries as read-only snapshots. The workload-identity graph is rendered from the federation rules you declare — a view of what you stated and what those rosters report, not live-verified trust on the wire. Live-verified federation against those registries is still on the roadmap. Human SSO in the open build is single-IdP OIDC/SAML; multi-IdP and SSO enforcement belong to the Enterprise line and are not claimed as shipped here. The kernel can bind an agent to an existing non-human identity or mint a dedicated one; it does not become your IdP.
- Fidelity is tiered. Coverage is
clean,lossyoropaque; attribution isfirm,approximateorunknown. Both are shown, never guessed. See fidelity. - A managed control plane is labelled future, post-v1. Collectors stay in your infrastructure in every topology.
Related: security leaders, compare, architecture.