One product. Three connected surfaces.

Give AI agents authority without giving them standing access.

PaloNexus connects the developer SDK, the enforcement Control Plane, and the security Command Center so every agent action is identity-aware, policy-checked, and attributable to the human authority behind it.

  • Integrate — SDK for developers and agent owners to register agents, provision identity, and request scoped actions.
  • Enforce — Control Plane for platform operations to verify identity, evaluate policy, and issue short-lived authority.
  • Observe — Command Center for security teams and leaders to review approvals, posture, and the verifiable audit trail.
Architecture diagram: agents in any runtime or sandbox — LangGraph, LangChain, Deep Agents, OpenAI Agents SDK, kagent, or your own — present an agent identity, owner, and task to PaloNexus. Inside PaloNexus, workforce identity providers (Okta, Entra ID, Google Workspace, Logto, HRIS) feed an authority directory; an authorization decision service evaluates agent, owner, task, action, resource, and context, answering allow, deny, or approve; a credential broker then issues short-lived, audience-bound credentials to reach enterprise systems — Kubernetes and cloud, GitHub and CI/CD, MCP servers and tools, SaaS and internal APIs, data platforms — which hold no standing credentials. Every result lands on a verifiable authority trail.

One product. Three connected surfaces.

Integrate, enforce, and observe the authority behind every agent action.

PaloNexus SDK

Integrate — identity and scoped action requests

Give developers and agent owners one integration contract for registration, identity provisioning, scoped requests, and typed allow, deny, or approval-required outcomes.

  • Agent registration and accountable ownership
  • DID/VC identity provisioning and revocation
  • Action context for task, resource, and duration
  • Framework adapters without changing authorization semantics

PaloNexus Control Plane

Enforce — policy, delegation, and revocation

Operate the policy, identity, delegation, approval, and revocation boundary in the runtime you already run. Kubernetes and supported IdPs are current integrations, not the product definition.

  • Authorization decisions at the action boundary
  • Human-backed delegation and lifecycle revocation
  • Durable identity and authority controls
  • Self-hosted Kubernetes deployment today

PaloNexus Command Center

Observe — posture, approvals, and the authority trail

Give security administrators and leaders one read surface for fleet posture, identity, approvals, decisions, ownership, and the verifiable authority trail.

  • Shipped operator portal with approvals and audit investigation
  • Identity, ownership, delegation, and revocation posture
  • Policy Studio (planned authoring workspace)
  • Cloud team Command Center (private beta)

PaloNexus deployment paths

Local, Cloud Private Beta, or Self-hosted

Start locally, request access to a hosted team cell, or operate the same Control Plane in your Kubernetes environment. One product, different deployment boundaries.

  • Local Runtime for developer onboarding
  • Cloud Beta for teams up to 10 (Request access)
  • Self-hosted Kubernetes with supported IdPs
  • Codex, Claude Code adapters, and Companion (planned)

Why now

Sandboxes isolate where agent code runs. Nobody isolates what it may do.

The agent ecosystem itself is pointing at the gap: LangChain’s sandbox guidance says to keep credentials outside the sandbox and inject them through an outbound proxy, and OpenAI’s agent architecture keeps authentication and audit outside the workspace. Both name the broker; neither ships it. PaloNexus is that missing layer — it resolves the agent’s owner, task, and delegation, then issues short-lived, scoped access outside the untrusted boundary, so no agent or sandbox ever holds a standing production credential.

Enforce — PaloNexus Control Plane

One enforcement contract across the systems your agents already use.

Agents

The SDK registers an agent, provisions its identity, and carries the human, task, action, and resource context into every governed request.

Control Plane

The shipped self-hosted Control Plane verifies identity, evaluates authorization, manages delegation and revocation, and records the decision with fail-closed behavior.

Enterprise systems

Kubernetes, source control, CI/CD, data platforms, and internal APIs receive only the scoped authority the active policy permits.

Observe — PaloNexus Command Center

Give security teams one view of agent authority and accountability.

When developers govern agents through the PaloNexus SDK and Control Plane, security teams get one read surface over authority — every action answers which agent acted, on whose authority, who approved it, and what policy context applied.

Authority Command Center portal capture: header reads 'Every agent action answers to four questions — which agent acted, on whose authority, who approved it, and what credential it carried', with a green 'Verifiable authority trail — chain verified' strip; an agent fleet and accountable ownership panel shows governed and ungoverned counts, posture (active & healthy, owner inactive, blocked), and bars of agents by accountable owner and by department; a live enforcement feed shows a deny with reason 'no approved delegation' followed by an allow carrying task chip INC-4821 and a delegation chip whose expiry counts down from 4m 39s.

Every decision carries its authority reason

The shipped portal records why, not just what: identity, owner, delegation, policy context, outcome, and expiry are visible alongside the decision.

The authority trail proves its own integrity

Each decision record is part of a verifiable audit trail so investigators can distinguish checked evidence from an assertion.

Accountable ownership across the fleet

Governed and ungoverned counts, per-agent posture, ownership, and lifecycle revocation make changes visible instead of surprising.

Planned next: Policy Studio for version-controlled policy authoring and deployment.

Works with

Keep your runtime. Add accountable authorization.

Working today

  • LangChain
  • LangGraph
  • Deep Agents
  • Kubernetes / Envoy
  • Okta
  • Entra ID
  • Logto

Planned

  • kagent Planned
  • Agent Sandbox Planned
  • OpenAI Agents SDK Planned
  • MCP Planned

Start here

Prevent agents and coding sandboxes from receiving standing production credentials.

Denied by default. During a live incident (INC-4821 in the demo), an SRE agent requests a production deployment restart. It holds no standing credentials, so the action stops at the decision point.

Owner-verified approval. PaloNexus routes the request to the service owner — and verifies that this person is actually entitled to approve this action on this resource.

Five minutes of scoped access. On approval, the agent receives a short-lived credential bound to that task, that deployment, and that window. Nothing else.

Auto-revoked, fully attributable. Access expires with the elevation window, and the authority trail records the agent, owner, delegation, approver, policy, and credential behind the action.

Human approval across the surfaces

Approval is a workflow, not a fourth product.

PaloNexus answers the question approval checkboxes skip — was this person entitled to grant this authority? — so security teams can say yes to agents without handing out standing access.

Choose your deployment path

Start with the SDK. Enforce in your Control Plane. Observe every decision.