Stewardvault
A multi-tenant agency control plane that provisions disclosed agent email identities, brokers provider authorization into action- and time-bounded grants where supported, keeps secrets outside model context, and verifies revocation, mailbox disposition and evidence retention at engagement end.
Agencies deploying agents for clients need identities and external-system access without sharing permanent administrator tokens across tenants or model context. The supplied research confirms adjacent human vaults, self-managed secret infrastructure, email delivery services and an early agent mailbox product, but finds no commercial agency-tier control plane combining the full workflow. The original stage verified one interface. Stewardvault treats an agent mailbox as a service identity, not a human or proof of authority. Sender disclosure, domain ownership, authentication records, provider acceptance, inbox placement and recipient trust are different; no inbox is guaranteed deliverable-grade. Authorization is granted only by a client owner and bounded to tenant, provider, account, action, resource, purpose and time. Short-lived delegation is used only when the provider supports it. A long-lived API key cannot be made short-lived by relabeling; it must remain in a broker, face strict allowlists, rotation and revocation. Secrets never enter prompts, logs or agent-visible responses. Request, policy decision, approval, token exchange, action command, provider acknowledgment, destination readback and revocation remain separate. Engagement closure requires deny-first enforcement, provider revocation or rotation, mailbox forwarding or archive policy, outstanding-action review and independent readback. Isolation is proven per boundary and test, never by a claimed pod count.
An agency security, platform or operations leader running client-specific agents that need disclosed email identities and bounded access to client systems.
Agency platform and security leaders managing client agents form an actionable buyer with clear liability.
Agents need persistent identity and useful access while clients require minimal, revocable authority and tenant isolation.
The gap is clearer than the historical barrier, while recent agent mailboxes and delegated authorization create feasibility.
A clear agency buyer, active adjacent identity and vault primitives and a concrete engagement-revocation problem make a narrow control plane testable.
Only one original interface was verified, provider authorization varies, email reputation and managed security add cost, and no structural incumbent barrier is proven.
Discussion
No comments yet — be the first to weigh in.
