Nodra
Menu
AI AGENT AUTHORIZATION GUIDE

What is AI agent authorization?

AI agent authorization decides whether a specific agent may perform a specific action on a specific resource before the consequential action executes.

Authentication is not authorization

Authentication establishes which agent is making a request. Authorization answers the separate question: is this agent allowed to perform this action on this resource right now?

Use explicit resource and action boundaries

Instead of giving an agent broad access, define authority such as a resource and action pair. This makes least privilege concrete and reviewable.

Enforce authorization before execution

The security decision should happen before the external API, tool, payment, database change or infrastructure action occurs. A deny decision should fail closed rather than execute first and audit later.

Human approval for high-impact actions

Some actions can be valid but still require a person. A require-approval decision lets policy pause execution until the configured approval requirement is satisfied.

Nodra runtime authorization

Nodra evaluates protected agent identity, explicit authority and policy, returns allow, deny or require-approval, and records security evidence around the decision and execution result.

See the JavaScript SDK