For the complete documentation index, see llms.txt. This page is also available as Markdown.

Mapping Identities and Credentials to Agents

Overview

Mapping identities and credentials to an agent records which identities and credentials the agent has access to.

This is an access association, not an ownership mapping.

Mapping in BalkanID
What it means

Identity → Employee (Identities page, Map to employee)

Ownership / accountability — which person the identity belongs to or is owned by

Identity or Credential → Agent (this page)

Access — which identities and credentials the agent can use or is associated with for governance

Use agent mapping when you need to answer: Which identities and credentials does this agent have access to?

Mapping identities to agents is available when Agents (Early Access) is enabled for your tenant. The Identity Mapping drawer then includes Map to employee and Map to agent.

Map identities to an agent

  1. Login to the BalkanID application and switch to the tenant you want to update.

  2. Head to Identities.

  3. Select one or more identities the agent has access to.

  4. Click Map identities.

  5. In the Identity Mapping drawer, select Map to agent (not Map to employee).

  6. Choose the target Agent.

  7. Confirm the mapping.

Result

BalkanID processes the mapping asynchronously. When complete:

  • The identities appear on the agent’s Identities tab

  • The agent appears under Accessible by agents on those identity detail pages

  • Identity counts on the Agents page update accordingly

Map credentials to an agent

  1. Login to the BalkanID application and switch to the tenant you want to update.

  2. Head to Credentials.

  3. Select one or more credentials the agent has access to.

  4. Click Map credentials.

  5. Choose the target Agent.

  6. Confirm the mapping.

Result

BalkanID processes the mapping asynchronously. When complete:

  • The credentials appear on the agent’s Credentials tab

  • The agent appears under Accessible by agents on those credential detail pages

When to map

Use mapping when:

  • An agent uses a human or non-human identity to act in an application

  • An agent uses or is bound to a credential (for example, an API key or vault secret)

  • You need a clear access inventory for blast-radius analysis

For extracted agents, some access associations may already be discovered from the source integration. Manual mapping fills gaps and covers agents that were registered or uploaded in BalkanID.

To remove an access association, see Unmapping Identities and Credentials from Agents.

Last updated

Was this helpful?