Pages
Policy Config — Org-Backed Identity

Source: c65 policy-definitions.md P2 — toggle + exceptions shape

‹ Policy Catalog

Org-Backed Identity

Beta

Agents run under org-issued identity, not personal accounts or static keys on consumer aliases. Accountability starts with knowing who an agent acts as.

Identity & Access
high
P2
SatisfiesOWASP ASIATLASAI RMFCSF 2.0ISO 27001ISO 42001SOC 2HIPAAGDPR
Underlying control— show
run: auth_method = "api_key"edit as custom control →

2 static-key runs in the last 24h

jake@gmail.com (consumer alias, api_key) · svc-deploy@qpoint.io (covered by exception) — everything else ran on org OAuth.

Exceptions

Scoped carve-outs with a reason and an expiry — accepted risk, on the record.

ScopeValueReasonExpires
usersvc-deploy@qpoint.ioApproved service account with vaulted static key2027-01-31

Remediation shown on findings: Move the agent to org-backed OAuth; revoke the personal/static credential.

Qpoint Brand Style Guide