Authentication/SSO/MFA (FAQ)
The questions below cover how GUIDE works with enterprise identity, authentication, Single Sign-On (SSO), Multi-Factor Authentication (MFA), credentials, and application access.
Enterprise AI agents need to securely access both the GUIDE platform and the applications required to perform their work.
GUIDE separates platform access from agent execution, enabling organizations to control who can build, administer, publish, and invoke agents while independently managing the credentials and permissions agents use when executing workflows.
Because GUIDE agents run in controlled remote Windows desktops, authentication can also be separated from the user's active desktop session, allowing work to be delegated to an agent without requiring the user to surrender control of their PC.
Three Layers of Authentication:
GUIDE User Identity
Controls who can access GUIDE and what they are authorized to do, including building, administering, publishing, and invoking agents.
Agent / Runtime Identity
Controls the Windows identity and permissions available to an agent when it executes within its remote runtime environment.
Application Identity
Controls how the agent authenticates to the applications required by the workflow, such as ServiceNow, SAP, Microsoft applications, websites, and other enterprise systems.
Together, these layers allow enterprises to separate who can use an agent, where the agent runs, and what the agent is authorized to access.