GraphOS Agent Services

Govern how agents access your graph


PREVIEW
GraphOS Agent Services is in private preview. You need an Apollo team member to help you onboard. Use this documentation for reference only.

GraphOS Agent Services allows you to govern what data an agent can access in your organization. Connect a service, classify its data fields with tags, and write rules to restrict access for specific clients, groups, or users.

How it works

Connect a service

Add a service from the catalog and deny its fields until a rule grants them. Catalog services include a base URL and default tags on their fields.

For more information, go to Connect Services.

Assign tags to fields

A tag is a label that rules reference to determine whether they apply to a field. Use tags to classify data fields, then write rules to restrict or allow access on tags for specific clients, groups, or users.

GraphOS Agent Services includes predefined tags for common data classifications:

  • sensitivity:PII for names, email addresses, and other personal data

  • sensitivity:financial for payments, billing, and other financial data

  • require-approval for mutations or fields that require approval

Create a custom tag when a field needs an access decision the predefined tags don't cover. For more information, go to Classify Fields using Tags.

Configure access rules

Each rule names an actor, a client, the data the rule protects, and what effect it has:

  • Actor: Everyone, a group, or a person

  • Client: All clients or one specific client

  • Data: one tag, or every tagged field in one service

  • Effect: Allowed, Masked, or Denied

Actor is based on identity — who's behind the request. Client is based on the calling application or session — what's making the request.

Use Denied for data the client shouldn't see, Masked when the client needs the field but not the stored value, and Allowed when the client should receive the value as-is. A more specific actor or client overrides a broader rule. When a field carries more than one tag, the stricter effect wins: Denied overrides Masked, and Masked overrides Allowed.

Choose what the client experiences for denied fields:

  • Hidden removes the field when the client shouldn't know it exists.

  • Error tells the client that a rule has blocked the field.

  • Can Request blocks the field and lets the client ask for access. Access requests can be found in the Access requests page.

For more information, go to Configure Access Rules. For a starting rule, go to Common Rule Scenarios.

Connect to GraphOS Agent Services

Teammates in your organization can connect their agent to GraphOS Agent Services through a runtime. The runtime applies the rules to every request and can submit access requests for denied fields.

Clients lists each client:

  • An interactive session is a person using an agent while signed in. GraphOS Agent Services adds the session the first time the person connects. The row shows that person's email and an Interactive session badge.

  • An agent app calls the graph with its own API key. Register the app on Clients before it appears in the list.

Track what data each client can access on Clients and all agent activity on Monitor.

Review access requests

When a denial uses Can Request, the client asks the agent to submit an access request. The request includes the fields, the reason, and the rule that blocks them. To grant or decline a request on Access requests, you need an Org Admin role.

Monitor lists each request, the client that made it, and whether a rule changed the response. For more information, go to Manage Access Requests and Audit Agent Activity.

Get started

GraphOS Agent Services is in private preview. To get started with onboarding, contact us.

Feedback