Gazebo
    ServicesAgentsDocsSpecWritingPricing
    Log inSign up
    Log in

    Overview

    • Introduction
    • Changelog
    • Implementations

    Identity

    • Identity declaration
    • Scope syntax

    Consent

    • The consent token
    • Verification

    Runtime

    • Overview
    • Access policy
    • Audit log
    • Credential broker
    • Compliance mappings

    Implementing AIP

    • Compatibility guide
    AIP Specification

    Overview

    • Introduction
    • Changelog
    • Implementations

    Identity

    • Identity declaration
    • Scope syntax

    Consent

    • The consent token
    • Verification

    Runtime

    • Overview
    • Access policy
    • Audit log
    • Credential broker
    • Compliance mappings

    Implementing AIP

    • Compatibility guide
    SpecRuntime

    Runtime Enforcement

    The Runtime section defines the ongoing enforcement layer — what happens on every request an agent makes after a user has consented.

    Where Identity and Consent cover the declaration and the approval event, Runtime covers moment-to-moment operation: is this agent allowed to do this specific thing right now?

    Three components

    ComponentWhat it does
    Access policyDefines the rules that determine what an agent may do
    Audit logRecords what the agent did, immutably
    Credential brokerValidates and enforces policy on every credential request

    For compliance requirements, see compliance mappings — SOC 2 CC6/7/9 and HIPAA §164.312 reference mappings.

    Enforcement model

    Runtime enforcement happens at the broker layer, on every request:

    1. Agent presents its consent token
    2. Broker validates the token against the active policy
    3. Broker evaluates any applicable approval rules
    4. If approved: credential is returned  ·  If denied: error returned  ·  If pending approval: request is held

    Policy is evaluated at request time, not at install time. A policy change — reduced scope, new approval rule, or revocation — takes effect immediately on the next request.

    VerificationAccess policy
    Gazebo

    IAM for AI agents. Scoped credentials, access policies, and audit trails — without rotating keys.

    Product

    • Pricing
    • Status

    Explore

    • Services
    • Agents
    • Workflows
    • Integrations

    Content

    • Writing
    • Topics
    • Blog
    • Docs

    Free Tools

    • Scanner

    Company

    • About
    • [email protected]
    • [email protected]

    © 2026 Gazebo. All rights reserved.

    PrivacyTermsSecurity