Back to MeshGuard

Layer comparison

In-process governance is necessary. It is not the fleet control plane.

MeshGuard is complementary to in-process libraries. Use AGT or another PEP inside the agent, then delegate production operations to a neutral control plane.

CapabilityIn-process governanceMeshGuard control plane
Policy enforcement pointAGT, framework adapter, or custom codeUses any PEP as a client
Policy decision pointLocal process or local YAMLTenant-scoped remote PDP with audit and SLOs
Human identityOut of scopeSSO, SCIM, RBAC, JIT, break-glass audit
AuditProcess-local emissionTamper-evident tenant stream with export and SIEM egress
DeploymentWhere the agent runsSaaS, dedicated, customer cloud, sovereign, self-hosted, air-gapped
FederationOut of scopeCross-tenant trust and linked audit evidence