Registration and enrollment
An Agent identity records its accountable owner, optional owning group, purpose, tags, lifecycle, and optional inventory relationship. Creating it does not create a provider principal, credential, grant, or enrollment. Each runtime enrolls independently:- Create an enrollment for the Agent identity.
- Copy the one-time setup token when Forge displays it.
- The runtime generates an EC P-256 key pair and exchanges the token with its public key.
- Forge consumes the short-lived token atomically and stores no private key or recoverable setup token.
Agent access
Select Manage agent access to configure each connected provider. Provider setup is separate from the inventory connection because discovery and mutation are different authorities.
AWS, Azure, Google Cloud, and GitHub profiles are isolated from one another.
Forge activates an access limit only after exact provider or broker readback
matches its desired configuration. A stale or mismatched readback blocks new
issuance without changing the saved profile.