Skip to main content
Tilde has three kinds of principal, and each is governed differently:
  • Operators manage the registry through the UI or the management API. See Operator access.
  • Agents act during invocations, within the capabilities you grant them.
  • End users talk to agents through chat channels, within each channel’s access policy.

Identities

Operators and API keys CLOUDENTERPRISE

Operators sign in through your identity provider, and hold roles that decide what they can see and change. Automation uses management API keys, which hold roles in the same way. Agent runtimes never receive operator tokens. See Operator access.

Agent capabilities

Capabilities are the fine-grained permissions of an agent. They decide what the agent can do during an invocation. The gateway enforces them on every call, so they hold even if the agent’s code or prompt is compromised. Three rules apply throughout:
  • Deny by default. A new agent has no capabilities. A capability you do not grant is denied.
  • Signed into the token. The gateway writes the agent’s capabilities into each invocation token, and verifies them on every runtime call.
  • Narrow only. Renewing a token can keep or reduce its authority, and can never add to it. In Cloud and Enterprise, an operator cannot grant more than they hold.

Capability reference

Targeted capabilities

A targeted capability takes one of three modes:
  • None denies the action.
  • All allows it for every target.
  • Selected allows it for a list of targets that you choose.
Prefer Selected. An agent that only replies to users needs tools.invoke for sendMessage, and nothing more.

Set capabilities

Open the agent in the Agent Registry and select Capabilities. Changes save immediately.

When a change takes effect

A capability change applies to new invocations at once, and reaches running invocations within minutes, when their tokens renew. Stop controls abort an agent’s work immediately.

Permissions beyond capabilities

Some agent permissions are assignments rather than capabilities. The gateway enforces these too.

End-user access

You control who can talk to an agent on each channel connection. In private mode, allow individual identities, such as an email address or phone number. Tilde can also ask a user to verify an identity before it links that identity to them. An operator can attest an identity instead, and Tilde records who made the attestation. Tilde enforces channel access in the database, on every message. It checks the sender before security middleware runs, and before the agent sees anything.

Token lifetimes

Every credential in Tilde is either short-lived or revocable.