The runtime and the rules
Where the agent runs, which model and tools it uses, the policy it obeys, and the upstream credential it never hands to a person.
Zerker/Governance for Workforce
Workforce · the first rung
The company runs the agents. People just use them: through your identity provider, in Slack, Teams, an IDE, or an API, with every call passing through Gateway policy.
The workforce path
Every call passes through Gateway policy. No one on the team holds the upstream credential, and every routed call leaves an invocation record.
Your identity provider supplies the person, tenant, team, and role.
OIDC · TEAMSPeople see the approved agents assigned to their team, with a clear job and contract.
CATALOGAccess arrives by role, or on request with an owner's approval.
SCOPED ACCESSUse the agent in the web, Slack, Teams, an IDE, a command line, or over the API.
WEB · SLACK · IDE · APIThe model
Zerker connects agents that already run somewhere: an internal service, a Claude Code or Codex session, an agent on OpenAI, Anthropic, Bedrock, or Vertex, an MCP server, a vendor-hosted agent, a Slack or Teams agent, or one deployed in your own cloud. Then it sits between the organization, its workforce, those agents, and the systems they can reach.
Rollout
Most companies do not start clean. Different teams already use ChatGPT or Claude, Cursor or Claude Code, a sales research agent, internal data agents, Slack automations, and things individual engineers built. Zerker starts by organizing what exists.
Okta or Google Workspace supplies people, teams, roles, business units, and access groups.
OIDCImport or register each agent with its owner, runtime, and users.
CATALOGWho owns it, who can use it, what it can reach, which actions need approval, and its cost limit.
POLICYRegister an API-backed agent's endpoint and credentials, or add an adapter to a local one.
ROUTEAn agent that does not pass through Gateway is shown as observed, never as governed.
OBSERVED · GOVERNEDPeople sign in, see the agents assigned to their team, and launch them where they work.
DELIVERDelivery truth
Gateway governs workforce traffic now: identity from your provider, tenant boundaries, ordered policy, protected credentials, and an invocation record for every routed call. The Workforce Portal, where people browse, request, and launch approved agents, is the delivery layer Zerker is building on those same records. Zerker governs only the calls routed through it, and never claims enforcement it does not have.
The ladder
The same governed record serves each audience in turn. Start with your own people, extend selected agents to partners, then publish the ones that are ready to customers through Agent Portals.
Connect your identity provider, register the agent, and give one team access through Gateway.