STRAZAdocs

Straza docs

Open source runtime governance for AI agents.

Straza is the control plane between your IdM/IGA and your agents. Your identity manager (IdM) or identity governance and administration system (IGA) says who people and agents are and which roles they hold. Straza turns those roles into a decision on each tool call that passes through it, on the agent’s machine and at the gateway in front of your MCP servers. It records every decision.

Your identity manager sends people and roles to Straza. Straza sends signed policy to agents' machines and holds the credentials for MCP servers. Every decision comes back to Straza as an audit record. Your identity manager midPoint, Okta, or any SCIM 2.0 client Straza (strazad) Who may do what Signs the policy Routes approvals to people Keeps the audit chain Agents' machines Claude Code, Codex, Gemini MCP servers behind the gateway people and roles change feed signed policy audit records tool calls
Your identity manager stays the source of people and roles. Straza decides, and every decision comes back to it as an audit record. Solid lines carry policy and calls, and dashed lines carry records.

Start from what you came to do

Already running Straza

Search documentation

Search page titles, commands, and article text.

↑ ↓ Choose resultEnter OpenEsc Close