How To Use This Guide
This guide is built for solution sprints. Use it to align business priorities, validate technical controls, and produce a decision-ready readout.
Use this guide to validate two outcomes: O4AA features operate as documented, and your highest-priority AI use cases can be supported with appropriate security, governance, and developer velocity.
This guide is built for solution sprints. Use it to align business priorities, validate technical controls, and produce a decision-ready readout.
Feature Validity
Evidence: Protocol traces, policy outcomes, token claims, and audit logs prove behavior.
Success: All required controls pass acceptance tests with reproducible steps.
Use Case Fit
Evidence: End-to-end workflows complete across selected systems with scoped permissions.
Success: Priority use cases meet predefined business and technical success criteria.
Granular policy controls for every agent action across models, APIs, and data resources.
Provision, rotate, and deprovision agent identities with standardized governance controls.
A consistent identity layer for agent integrations that reduces one-off auth implementations.
Action-level traceability with user and agent attribution for defensible compliance posture.
Visibility into discovered agents, owners, and permissions to identify high-risk exposures early.
Where Are My Agents?
What Can My Agents Connect To?
What Can My Agents Do?
Business objective: Validate a shared team agent model where effective permissions are the governed intersection of user context, agent authorization, and organizational policy.
Business objective: Prove read-only and constrained delegation where developer agent permissions never exceed explicit agent grants even for privileged users.
Business objective: Validate on-behalf-of token exchange for Bedrock AgentCore with scoped, short-lived tokens preserving both user and agent identity.
Business objective: Validate group-based fine-grained policy enforcement for Claude Code access without distributing API keys or cloud credentials to end-user devices.
Map customer business priorities to testable use cases, then define measurable success criteria before technical execution.
Validate identity issuance, delegated authorization, and policy enforcement against enterprise resource integrations.
Prove operational governance with access workflows, certifications, and audit-ready evidence capture.
Align business priorities, finalize use cases, define proof criteria, and lock environment prerequisites.
Validate discovery and registration controls for managed and unmanaged agents.
Validate token exchange, delegated authorization, and bridge patterns across selected resources.
Validate governance controls and produce executive-ready recommendations for production adoption.
Delegated user-context-aware access using ID-JAG where tokens carry both user and agent identity context.
Okta brokers third-party OAuth tokens so agents use short-lived delegated tokens instead of long-lived credentials.
Static secrets are vaulted and retrieved at runtime through governed connections rather than embedded in code or config.
Credentialed service identity managed with lifecycle controls and mapped to policy-governed enterprise access boundaries.
Identity-aware mediation layer for commercial and internal MCP access with policy-enforced delegated execution.
Next Step
This guide replaces one-off docs with a repeatable evaluation model for customer teams. Keep it as the living source of truth throughout kickoff, testing sessions, and executive readout.