Concepts
How Straza works and why it is built the way it is.
- How a tool call is decided follows an agent action from identity and policy to enforcement and audit.
- Identities and roles covers users, roles, devices and sessions, and how access follows them.
- Policies explains how rules match actions, combine decisions and require approval.
- Approvals says who can approve an action and what happens while it waits.
- Evidence and audit follows audit events from the decision to storage, verification and external delivery.
- MCP servers and the gateway shows how the gateway controls tool access and supplies upstream credentials.
- Trust model and limits states what Straza defends against, what it trusts and what it does not try to do.