- Operators manage the registry through the UI or the management API. See Operator access.
- Agents act during invocations, within the capabilities you grant them.
- End users talk to agents through chat channels, within each channel’s access policy.
Identities
Operators and API keys CLOUDENTERPRISE
Operators sign in through your identity provider, and hold roles that decide what they can see and change. Automation uses management API keys, which hold roles in the same way. Agent runtimes never receive operator tokens. See Operator access.Agent capabilities
Capabilities are the fine-grained permissions of an agent. They decide what the agent can do during an invocation. The gateway enforces them on every call, so they hold even if the agent’s code or prompt is compromised. Three rules apply throughout:- Deny by default. A new agent has no capabilities. A capability you do not grant is denied.
- Signed into the token. The gateway writes the agent’s capabilities into each invocation token, and verifies them on every runtime call.
- Narrow only. Renewing a token can keep or reduce its authority, and can never add to it. In Cloud and Enterprise, an operator cannot grant more than they hold.
Capability reference
Targeted capabilities
A targeted capability takes one of three modes:- None denies the action.
- All allows it for every target.
- Selected allows it for a list of targets that you choose.
tools.invoke for sendMessage, and nothing more.
Set capabilities
- Tilde UI
- Management API
Open the agent in the Agent Registry and select Capabilities. Changes save immediately.
When a change takes effect
A capability change applies to new invocations at once, and reaches running invocations within minutes, when their tokens renew. Stop controls abort an agent’s work immediately.Permissions beyond capabilities
Some agent permissions are assignments rather than capabilities. The gateway enforces these too.End-user access
You control who can talk to an agent on each channel connection.
In private mode, allow individual identities, such as an email address or phone number. Tilde can also ask a user to verify an identity before it links that identity to them. An operator can attest an identity instead, and Tilde records who made the attestation.
Tilde enforces channel access in the database, on every message. It checks the sender before security middleware runs, and before the agent sees anything.