Agents
An agent is the identity that wants to perform an action. You register agents in app.vulnify.io. A check names the agent by the registered name (agent) or by id (agentId).
{ "agent": "SalesBot", "action": "EXPORT_DATA", "resource": "Customer Database" }An unknown agent is rejected. The SDKs raise. They do not convert that rejection into ALLOW or into the fail-closed fallback.
Keys and permissions
Section titled “Keys and permissions”The app describes each agent as having an identity and its own API key. You can also create an organization key and optionally bind it to one agent. A bound key reports events only for that agent. See API keys.
Permissions are separate from policies. When no policy matches, the risk engine scores the action. A missing permission is the agent’s permission, not a policy. The organization setting block actions an agent has no permission for also blocks every action of a paused or disabled agent. That control lives in the app settings.
What gets stored
Section titled “What gets stored”The audit trail records the agent name on the decision, together with the action, resource, destination, record count, risk result, and any review. It does not store the contents of the records the agent touched.
Anomaly baselines
Section titled “Anomaly baselines”The app keeps a baseline per agent and can record anomalies when behavior leaves that baseline, including a volume spike, an action the agent has not used before, a new external destination, or a spike in requests per hour. Anomalies can fire webhooks. See Webhooks.

