Skip to content

Organizational Support in AgentZ

Isolation, roles, inheritance, and secret handling turn one model into a multi-team platform.

Editorial brief

Slug   /blog/agentz-organizational-support

Reader   Platform leads, security leads, IT admins, and buyers who evaluate AgentZ for many teams at once.

Tone   Explanatory, credibility-first, concrete. Show the structure and name the real mechanisms.

Primary keywords   multi-tenant AI platform, organizational RBAC, capability-based access control, resource inheritance, agent sharing, zero credential exposure

Pain points to hit   AI tools locked to one team. No isolation between teams. Secrets exposure. Duplicated setup in every workspace.

A demo needs one model. A company-wide capability needs an operating layer around that model. AgentZ builds that layer first. The layer controls five things:

  • It grants access per workspace and agent.
  • Each user reaches only the resources that their role allows.
  • A workspace inherits shared resources from the organization.
  • Isolation keeps one team's data away from another team.
  • Governance controls how each agent runs.

Why organizational structure comes first

AgentZ is a multi-tenant platform. Multi-tenant means many separate organizations run on shared infrastructure. Each organization needs isolation, credential control, and a defined network posture. Without organizational structure, there is no safe way to share resources across teams and still enforce least privilege.

The platform started from one enterprise question. Would you hand raw credentials to an AI for site reliability tasks? The answer was no. So an AgentZ agent never receives a raw secret.

Teams also need different tools. HR, DevOps, security, and sales each need distinct access. None of them should see another team's config or admin controls. Admins configure the shared infrastructure. Each team uses only what its roles permit.

Execution stays zero-trust by default. Zero-trust means the system denies every action until a rule allows it.

A sandbox denies all traffic first. Admins then add explicit allowlists for packages, tools, external hosts, and MCP servers. MCP means Model Context Protocol, the standard AgentZ uses to connect an agent to an external tool. Cilium network policies enforce this deny-by-default rule. An agent pod sends no traffic until an explicit rule permits it.

The hierarchy

The platform nests three levels. An organization holds workspaces. A workspace holds agents.

graph TD
    ADMIN["Super admin<br/>configures shared resources"] --> ORG["Organization"]
    ORG --> WS["Workspace"]
    WS --> AG["Agent"]
    WS -. inherits .-> RES["Sandboxes, Skills,<br/>MCP connections,<br/>Inference providers"]

A super admin manages the organizations, workspaces, teams, roles, invitations, and users. An ordinary user sees only the workspaces and capabilities that their roles grant.

One user can belong to many organizations. The same user can be super admin in one organization and hold limited access in another.

The hierarchy maps to Kubernetes CRDs and Gateway API routes. CRD means custom resource definition. The routes are /api/tenants, /api/workspaces, and /api/agents.

Roles and capability-based access control

Permissions attach to roles. Roles attach to users directly, or through teams. Workspace access comes through role permissions.

Every agent carries a set of capabilities. The set includes Delete, Modify, Share, Use, ReadSecrets, WriteSecrets, ManageOwnership, and DeleteSecrets. AgentZ resolves each capability per organization and workspace scope. It builds the authorization scope from the OrganizationID and the WorkspaceID.

Resource inheritance

Admins configure the shared resources once at the organization level. Workspaces then inherit them. The shared resources are sandboxes, skills, MCP connections, and inference providers.

A scope flag, ResourceScopeOrganisation, marks an organization-level resource. Agents across the organization reuse that resource, and no one duplicates it. An HR team uses a preconfigured connector and never edits the underlying MCP or inference-provider config.

Agent sharing

A user shares an agent with specific users or teams inside a workspace. AgentZ gates every share with an organization-membership check, GatewayIsActiveOrganizationMember. It then resolves effective permissions with CanReceiveAgentShare. It records each share and resolves it against team and user capabilities.

Consumer-safety checks

An inherited resource often has consumers. A consumer is an agent, sandbox, or pool that depends on the resource. Before an admin can unselect an organization-level resource, AgentZ computes every consumer. If any consumer exists, AgentZ blocks the removal. This stops a breaking change when someone disables an inherited resource.

Onboarding and identity

Three onboarding paths bring users in. Admins send invitation links. Google Workspace sign-up restricts access by email domain. GitHub access follows organization and team membership.

What you get

Users create their own agents and inherit the organization-level models, tools, and sandboxes. Shared connectors and inherited resources remove repeated setup, so no team rebuilds the same infrastructure.

One platform covers many business functions. Teams run AI SOC automation, internal SRE and DevOps checklists, HR resume screening, and general business-process automation. AI SOC means AI security operations center. Each workspace gets its own environment. An organization that uses AgentZ for HR does not automatically get AI SOC.

There is no model lock-in. Teams bring their own inference providers, and they switch providers while they keep their workflows. Workflows run on schedules or webhooks, keep session context, and connect to external tools through MCP or the Composio OAuth gateway.

The Enterprise tier adds governance. It includes centralized admin, SAML and OIDC, workspace-level compute delegation, dedicated deployment, priority support, and domain-specific guardrails.

Proof in real workflows

Teams already run these workflows today.

  • One workflow builds a daily report of billable assets across 17 cloud accounts.
  • Another workflow pulled 16 critical cloud findings through the AccuKnox API and emailed an HTML remediation report.
  • A KubeArmor alert workflow triggers on a webhook at IOC detection and generates a severity-classified investigation report. IOC means indicator of compromise.
  • On-prem and air-gapped deployment covers data-residency needs.

The security backdrop

Organizational support sits on top of the sandbox. Two mechanisms keep it safe.

AgentZ never gives an agent a raw secret. It injects a placeholder such as agentz:resolve:env:API_KEY. A Secret Injection Proxy, called Sinjector, swaps the placeholder for the real credential at call time. The agent never touches the credential.

The network denies traffic by default through Cilium. Each agent runs in its own isolated Kubernetes pod. A stateful agent keeps a home directory backed by a PVC. PVC means persistent volume claim.