The keeper of trust.
Access control, audit trails, credential rotation and compliance — the Admin agent is the security enforcer and approval authority for the whole platform.
What it runs
Every privilege change is approval-gated — the Admin agent never self-approves.
Audit log
Append-only record of every action — actor, tool, target, decision, timestamp.
guarded_autoRole-based access
Entitlements per role; scope checks before any tool runs.
autoCredential rotation
Rotates stored secrets only with a literal confirmation phrase.
approval_requiredAccess reviews
Periodic entitlement reviews (SOC 2 CC6.3 / PDPA s.9) with snapshots.
guarded_autoApproval authority
The single point that grants or denies high-risk actions across agents.
approval_requiredCompliance
PDPA breach notification, audit-exemption criteria, retention.
guarded_autoPrivilege changes, rotation, policy changes, exports and purges are all approval-required (protected). The Admin agent is the enforcement point for the ten safety controls.
How it connects
Grants access and policy to everyone; receives approvals and audit events from all.
Lock the platform down, provably.
Bring the Admin agent into your business.