# Agent access, earned the way a person earns it.

> Agent access control in ColossalX makes an agent earn access the way a person does. It is enrolled at the gate, placed in a trust zone with limits you set, and promoted from sandbox to production only by clearing gates you define. Extra tool access is requested, approved by a second person, and ends on a date.

An agent gets access the way a person does: an owner, evidence, a trust zone and grants that expire.

Canonical page: https://colossalx.tech/platform/agent-access · Last reviewed: 7 Oct 2026

*Illustration:* One agent · gate, zone, grant: refunds-agent to ColossalX (enrolled); unknown caller found calling ColossalX (not enrolled); ColossalX to provider A (in zone); ColossalX to crm.lookup (granted to Friday); ColossalX held for a person before payments.refund (request pending).

## The threat and the control

- **The threat:** An agent that worked in a sandbox keeps broad access in production, and nobody remembers approving it.
- **The control:** ColossalX promotes an agent only through your gates, and grants extra access to one tool, for a time.

## How it works: From a new agent to earned production access.

One agent enrolled at the gate, placed in a zone, promoted through two gates and given one tool for a few days, each step decided by a person or a rule you wrote.

### Workflow: an agent earning production access (illustrative)

1. **Enrolled.** The agent is enrolled at the gate, with an expiry.
   Agent: refunds-agent; Gate entry: enrolled, with expiry; Zone: sandbox | Enrolled · Revocable
2. **Gates cleared.** Promotion waits for the conditions you defined.
   Guardrail profile assigned (done); No critical findings (done); Approval to reach production (waiting: required) | Staging
3. **Grant requested.** One tool is requested for a few days, with a reason.
   crm.lookup · requested, with a reason · Pending | The person who asks cannot approve.
4. **Second person decides.** Someone other than the requester approves, with an end date.
   Security lead: Approved crm.lookup until Friday | Expires · Revocable | x, held

## What you see: The gates an agent clears, and the grant beside them.

A promotion pipeline in three zones, each gate with its conditions. Where a gate needs approval, a person decides; extra tool access sits beside it and ends on a date.

1. **Enrol at the gate.** An enrolment is an allow-list entry with an expiry. Enrol the agents that qualify in one step; quarantined, suspended and retired agents are never enrolled. Each row shows its expiry and can be revoked, and a revoked row shows why. The gate refuses an unenrolled agent only once you switch it to enforce.
2. **Place in a zone.** Each trust zone sets limits you choose, measured on every request. Limits cover call rate, session length, tokens, blocked tools, allowed model hosts, acting for another agent and whether a person approves each request. Every limit keeps a change history, and the last week's breaches are listed by agent.
3. **Clear the gates.** Promotion from sandbox to production waits for conditions you define. A gate names a source zone, a target zone and conditions: an assessment score, a guardrail assigned, time in the zone, no anomalies, no critical findings, a kill switch configured. It auto-promotes or only notifies, and any agent can be evaluated against all of them.
4. **Ask for a grant.** One agent, one tool, until a date, decided by a second person. The person who raises a request cannot approve it. An approval carries an end time, and a grant can be revoked early with a reason. The access graph then lists grants past their expiry, and grants still held by an agent that was retired.

*Illustration:* An illustrative promotion pipeline: an agent climbs from sandbox to staging to production, each step waiting on the gates the workspace defined, with an approval where one is required and an expiring tool grant, approved by a second person, beside it. Notes: 1. A gate that promotes by rule 2. A gate that waits for a person 3. One tool, until a date, second approver

## How we know

- The person who raises a request can never approve it.
- A grant ends on its date, when revoked, or when its agent is retired.
- A written deny rule, a failed argument check or a poisoned tool description still wins over a grant.
- Quarantined, suspended and retired agents are never enrolled at the gate.

## Where earned access goes next.

Access is read by the controls around it, and refused or expired access leaves a record.

- **ColossalX MCP Firewall.** The firewall honours an approved grant where default deny would refuse the tool, on live traffic.
- **The agent's credential.** Its credential carries the agent's zone and its latest test results.
- **Containment.** A quarantined agent is refused whatever it holds, and retiring one ends its grants.

Where an x ends up: x, held.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## Frameworks

- Assessed per agent against OWASP Top 10 for Agentic Applications: Privilege abuse (ASI03) limited by zones and grants.

## What it does not do

- The gate refuses an unenrolled agent only in enforce mode; in monitor mode it records.
- An enrolment is an allow-list entry with an expiry, not a certificate.
- Trust-zone breaches are recorded by default; refusing them is a setting you switch on.
- The access graph reviews granted tool access; it is not a map of everything an agent can reach.

*Illustration:* Access graph · what it shows: Granted access Listed per agent; Past its expiry Flagged for review; Retired agent Live grant flagged; Full topology Not drawn. Review, not a map.

## Questions

### What is least privilege for AI agents?

Least privilege means an agent holds only the access its job needs, for as long as it needs it. That is hard for AI agents, which pick up tools and act on their own. ColossalX uses trust zones for baseline limits and expiring, tool-by-tool grants for anything extra, so access shrinks back instead of piling up.

### How does an AI agent get promoted to production?

It moves through trust zones, from sandbox to staging to production, only when it clears the gates you define: for example a guardrail assigned, no critical findings and a kill switch configured. A gate either promotes the agent automatically or notifies a person, and any agent can be evaluated against all of your gates.

### What is a trust zone for an AI agent?

A trust zone is a tier with limits you set: call rate, session length, tokens, blocked tools, allowed model hosts and whether a person approves each request. Agents move between zones as they earn trust. ColossalX measures every request against the agent's zone; by default a breach is recorded, and refusing it is a setting you switch on.

### How do you catch agent access that outlived its approval?

The access graph lists each approved grant by agent and flags two cases: a grant that passed its expiry and was never removed, and a grant still held by an agent that was retired or quarantined. It reviews granted tool access; it is not a map of everything an agent can reach.

### Is an enrolled agent the same as an approved agent?

No. Enrolment puts an agent on the gate's allow-list with an expiry. Approval means someone is accountable: an owner, a second approver and a guardrail profile. The agent's own credential, not its enrolment, proves which agent is calling, and the gate refuses unenrolled agents only in enforce mode.

## Related

- [Agent identity](https://colossalx.tech/platform/agent-identity)
- [ColossalX MCP Firewall](https://colossalx.tech/platform/mcp-firewall)
- [Detection and response](https://colossalx.tech/platform/detection-response)

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
