Gradient Tesseral

The control plane for agentic AI trust.

Tesseral secures AI agents from creation through end of life: hardware-anchored identity, integrity-bound permissions, and temporal authorization — continuously re-verified at every interaction. Every action provable. Every delegation traceable to an accountable human. Built on the Gradient identity platform already proven in production.

Platform-anchored Continuously verified Clear accountability
● Task-scoped
Agent Capability Token

payments.settle

Issued toreconciler-7
Provenancec.white treasury-ops reconciler-7
Scopesingle transaction
Token expires in07:18
The architecture

Trust, rebuilt for a new kind of actor

Six mechanisms, one control plane — securing what an agent is, what it may do, and who answers for it.

001

Composite agent identity

An agent’s identity is a measurement of everything it actually is — we developed a composite identity to reflect this — capable of representing code, model weights, system prompt, and registered tools, in one identity. Change any of them, and the agent is, cryptographically, no longer itself.

002

Platform-anchored keys

Private keys are generated inside the hardware root of trust already in the host — cloud instance, server, laptop or GPU — and can never leave it. A stolen Tesseral credential works nowhere else, and expires anyway.

003

Continuous re-verification

Before every renewal, on a clock measured in minutes or less, the agent must re-prove its identity and integrity from the hardware up. Verification isn’t an onboarding event — it’s a heartbeat.

004

Agent Capability Tokens

Permissions are issued as short-lived tokens scoped to exactly the task at hand. A payments agent holds payment authority for the transaction window it needs — and not a second longer. Authorization becomes temporal, and verifiable at every interaction.

005

Governed delegation

Whether an agent may spawn sub-agents at all is a token-governed decision. Every child is strictly bounded to no more than its parent’s permissions, valid only as long as its parent’s remaining lifetime.

006

Provenance, end to end

Every delegation is cryptographically traceable back through sub-agent, to parent agent, to the human or team that originally authorized the work. Provenance is a property you verify — not one you take on faith.

What this buys you

Outcomes an AI-speed adversary can’t argue with

A stolen credential is worthless

It is bound to attested hardware, so it works nowhere else — and it expires, by design, within minutes. Not harder to abuse. Pointless to steal.

Tampering costs the credential

A modified binary, substituted weights, a poisoned prompt, an unauthorized tool — any of them fails the next attestation, and the agent’s authority ends automatically.

A rogue agent contains itself

Whether an agent goes off-script through emergent behavior or outside manipulation, its authority is capped at what its current token permits and expiring on its own. No scramble. No revocation lists.

An audit trail you can hand a regulator

Every action maps, in real time, to a specific agent, in a specific verified state, holding specific authority, under a named human owner. Forensics becomes lookup, not reconstruction.

The standard

Meets the highest tier of published guidance

The NSA-led Five Eyes guidance and Anthropic’s Zero Trust for AI Agents framework converge on the same top tier: identity cryptographically rooted in hardware with remote attestation, permissions scoped just-in-time to the task, and delegation with verifiable provenance. Tesseral meets or exceeds that bar on all three — it is the architecture the guidance describes.

Works with what you have

A control plane, not a construction project

Tesseral works with the systems you already run — your identity provider, your directory, your network, your agent frameworks. Credentials are standard certificates your tools already understand, and deployment is incremental, without interrupting what’s running.

It plugs into your identity stack rather than standing in front of it: no data-path proxy, no TLS decryption, no latency tax. Your IdP stays the source of record.

Tesseral extends the same Gradient platform that secures human authentication — StealthMFA for your people, Tesseral for your agents. One attestation-driven architecture under both.

No proxy. No rip-and-replace.

Beyond AI agents

One trust plane for every non-human identity

The same architecture that secures your agents secures your CI/CD pipelines, service accounts, and automated workloads. You’re not buying a point solution for the GenAI moment — you’re replacing the brittle machine-credential model across the enterprise.

Get started

Put a control plane under your agents

See Tesseral in a 30-minute working session.

Request Demo