The runtime and the rules
Where the agent runs, which model and tools it uses, the policy it obeys, and the upstream credential it never hands to a person.
People sign in with your identity provider and use the agents you approved. Every call goes through Gateway.
The workforce path
Nobody holds the upstream credential. Every call leaves a record.
Your identity provider supplies the person, tenant, team, and role.
OIDC · TEAMSPeople see the approved agents assigned to their team, with a clear job and contract.
CATALOGAccess arrives by role, or on request with an owner's approval.
SCOPED ACCESSUse the agent through Gateway today, over HTTP or MCP. Slack, Teams, IDE, and command-line delivery are part of the Workforce Portal being built.
HTTP · MCPThe model
Zerker connects agents that already run somewhere: an internal service, a Claude Code or Codex session, a model provider, an MCP server, a vendor agent. Gateway sits between your people and those agents.
Rollout
Most companies already have agents spread across teams: ChatGPT and Claude, Cursor and Claude Code, a sales research agent, Slack automations, and things individual engineers built. Zerker starts by organizing what exists.
Okta or Google Workspace supplies people, teams, roles, business units, and access groups.
OIDCImport or register each agent with its owner, runtime, and users.
CATALOGWho owns it, who can use it, what it can reach, which actions need approval, and its cost limit.
POLICYRegister an API-backed agent's endpoint and credentials, or add an adapter to a local one.
ROUTEAn agent that does not pass through Gateway is shown as observed, never as governed.
OBSERVED · GOVERNEDPeople sign in, see the agents assigned to their team, and launch them where they work.
DELIVERStatus
Gateway governs workforce traffic today: identity, tenant boundaries, policy, protected credentials, and a record of every call. The Workforce Portal, where people find and launch agents, is being built on those records. Only calls routed through Gateway are governed.
Sequence
Start with your own people. Extend selected agents to partners. Publish the ones that are ready to customers through Agent Portals.
Connect your identity provider, register the agent, and give one team access through Gateway.