Pages
Policy Config — Org-Backed Identity
Source: c65 policy-definitions.md P2 — toggle + exceptions shape
‹ Policy Catalog
Org-Backed Identity
BetaAgents run under org-issued identity, not personal accounts or static keys on consumer aliases. Accountability starts with knowing who an agent acts as.
Identity & Access
high
P2Satisfies
OWASP ASI
ATLAS
AI RMF
CSF 2.0
ISO 27001
ISO 42001
SOC 2
HIPAA
GDPR
Underlying control— show
run: auth_method = "api_key"edit as custom control →2 static-key runs in the last 24h
jake@gmail.com (consumer alias, api_key) · svc-deploy@qpoint.io (covered by exception) — everything else ran on org OAuth.
Exceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| user | svc-deploy@qpoint.io | Approved service account with vaulted static key | 2027-01-31 | |
Remediation shown on findings: Move the agent to org-backed OAuth; revoke the personal/static credential.