Hover or tab a component to light its data paths and read a fact. Toggle a plane (top right) to filter edges: identity, policy, approval, audit, MCP. Dashed arrows are asynchronous.
What this shows
Agent harnesses funnel through straza, the client PEP kit: its local PDP decides
every tool call against an ed25519-signed snapshot, no server and no database on the path. Its mcp mode
proxies to the strazad MCP gateway, where a two-tier catalog (a shared
role catalog refined by a per-session policy overlay) hides tools the subject could never call and the
built-in native straza app serves approval_request / status / await for tickets. The
inline classifier scans classify-gated calls. The approval
service drives mode:approve across console, Slack, and the mobile approver API
(/v1/approver/*), which sends each request to the approver's phone as a content-free
push notification (the hosted relay, FCM, APNs, WebPush or UnifiedPush). Identity arrives over SCIM 2.0 and an OIDC IdP; changes flow back to the IGA over
the cursored changes feed. Every decision is audited asynchronously into a SHA-256 hash chain; the
sentinel judges whole sessions off the same stream, failing open with an
alarm. Kill-switch revocations push in under 2 seconds; credentials inject upstream, never reaching the
agent.