Capability 13 / 14 · Prove and integrate

Give applications and AI agents governed access to the same knowledge layer.

Governed foundationAvailable nowStage: Prove

Create tenant-bound machine identities with expiring, revocable tokens, then access supported EKOS capabilities through REST or authenticated MCP.

MACHINE ACCESS / SVC-0042Token active

svc-audit-assistant

active

ekos_sa_9f31… shown once · stored as hash only

expires in 90 daysrevocable per tokentenant bound

Your agent, over authenticated MCP

› search_knowledge("data retention schedule")

‹ 5 source passages, visibility-scoped, with citations

# tenant derived from the connection, tool arguments cannot change it

The same governed layer answers your assistants: bring your own agents over MCP, keep EKOS as the source of cited truth.

Illustrative product view · a scoped machine identity and one MCP call

The problem

Scripts, integrations, and customer-owned agents need non-human access without sharing personal credentials or trusting identity supplied inside model-generated tool arguments.

What EKOS does

Administrators create a service account, assign role context, issue tokens whose cleartext is shown once, and revoke individual tokens or deactivate the account when access should end.

  • Tenant-bound non-human identities
  • One-time token display with hash-only storage
  • Expiration, revocation, and account deactivation
  • REST and authenticated MCP access
  • Transport-derived identity with audited use

How it works

  1. An administrator creates a tenant-bound service account, assigns its role context, and issues one or more tokens with recorded expirations.

  2. The cleartext token is displayed exactly once; EKOS stores only its hash.

  3. The same bearer credential authenticates the REST API and the authenticated streamable-HTTP MCP transport.

  4. MCP identity is established on the connection before a tool runs; a tenant assertion inside a tool argument cannot override it, and a mismatch is recorded for audit.

  5. Individual tokens can be revoked at any time, and deactivating the account invalidates all of them at once.

Business outcome

Organizations can embed governed EKOS knowledge into existing workflows and assistants while retaining tenant context, revocation, provenance, and audit behavior.

Proof and human control

EKOS stores token hashes, derives tenant and role context from the authenticated transport, and audits supported REST and MCP activity against the machine identity.

Example in practice

A customer issues a dedicated 90-day token to an internal assistant. The assistant can request cited policy answers, while its authenticated tenant context cannot be replaced by a different tenant identifier in a tool call.

Scope today

Service accounts provide authenticated tenant and role context across supported REST and MCP surfaces. Authorization behavior is specific to each supported surface.

Next step

See your own documents become a trail of proof.

A working session with the EKOS team: bring a policy set, a framework, and a hard question. We will walk the loop end to end.