Concepts
Axec keeps software identity, human identity, credential custody, consent, and runtime authority separate. These pages explain each boundary independently and show how they compose.
Identity and credentials
Section titled “Identity and credentials”- Applications are software principals and gateway owners.
- Application Credentials authenticate confidential Applications.
- Service Accounts are non-human tenant-management principals, not MCP actors.
- Users and Workload Identities distinguish the human subject from an authenticated runtime actor.
Credentials and consent
Section titled “Credentials and consent”- Credentials explains User OAuth Connections, workspace Vaulted Credentials, governed OAuth credential release, and consent boundaries.
- Connectors describe configured upstream capability contracts.
- Connections bind one User’s upstream account to a Connector.
- Grants and GrantBundles represent delegated authority and its live lifecycle.
Runtime authority
Section titled “Runtime authority”- MCP Gateways expose an Application’s live capability surface.
- Connectors explain capability contracts, gateway Resources, and operation boundaries.
Controls and evidence
Section titled “Controls and evidence”- Policies and approvals explain how a policy narrows live authority and how an approved ActionRequest is retried.
- Evidence explains the secret-free record of Axec’s decision and execution boundaries.
Use the separate Governance operations section to configure policies, approvals, Data Protection, and auditing.