A hands-on lab that governs humans and non-humans on one identity truth — agents, LLMs, tools, services, and doors. Built to present and validate a Duo Agentic Identity + Zero-Trust-for-AI approach end to end. A personal skills lab — synthetic identities only, no customer data.
← / → or space to advance · F for fullscreen · ◐ toggles light / dark
Enterprises adopting agentic AI face a new identity population — agents, MCP tools, LLMs — with no owner, no lifecycle, no least-privilege. This lab shows the answer is the identity fabric they already run: Duo as the decision point, the same joiner/mover/leaver, the same groups, extended to non-humans. It de-risks the customer's path before they build it.
Every plane is a Policy Enforcement Point (PEP) in front of one resource class; Duo's cloud Authorization API is the shared Policy Decision Point (PDP). One identity truth, three doors.
0.12.0 + Duo Authorization Connector. Per-tool-call ext_authz against the sponsor's groups. Federates GitHub · MS Learn · Splunk.
aigw run fronts LiteLLM at loopback :8210 — model virtualization, provider fallback, token accounting; three tier keys (local / external / frontier).
CF Access + Duo live at the edge today; the Private-App API is the target for programmatic grant / revoke of private apps and device trust.
Authenticates the agent's Duo JWT, then authorizes the action against the human sponsor's AD-synced groups. Default-deny. Every decision is logged to the Duo Client Authorization Log.
One Windows/Hyper-V host: the identity VMs, the Docker fabric, egress through a default-deny Squid proxy, and Cloudflare tunnels publishing everything Duo-gated at the edge — no inbound ports.
The 17 SG-* groups reach Duo on the AD path — not through Entra. SYNC01 runs two sync engines side by side; three inbound directory syncs converge on one Duo the gateways then read.
Groups = f(roles × tiers) — an identity-plane object, independent of gateway or tool count. Authored once in mcp-authz-intent.yaml, rendered to each PDP. T3/T4 bind to an elevated .adm identity, so neither a human on their daily account nor an agent acting on-behalf-of them can reach destructive tools.
| Plane | Representative groups | Provisioning |
|---|---|---|
| MCP · GitHub | SG-MCP-GitHub-Read / Write / Merge / Admin | birthright → JIT·.adm |
| MCP · Splunk | SG-MCP-Splunk-Read / Query / IAMData | birthright → JIT+alert |
| MCP · AppSec | SG-MCP-AppSec · SG-MCP-MSLearn | JIT+alert · birthright |
| LLM | SG-LLM-Local / External / Frontier | birthright → JIT |
| Fabric API | SG-AGW-Fabric-Read / Operator | requestable → JIT·.adm |
| Gateway admin | SG-MCP-AgentGW / EnvoyGW / SecureAccess-Admin | JIT · .adm |
Two checks on every call: authenticate the Duo JWT, then authorize the target tool against the sponsor's groups. Default-deny — a tool not in any of the sponsor's group bundles is hidden.
Validated: agentgateway 0.12.0 + Duo Authorization Connector live, federating GitHub · MS Learn · Splunk; every ext_authz decision feeds the Duo Client Authorization Log (config ↔ tenant confirmed across all five gateway Duo apps).
Envoy fronts LiteLLM as one OpenAI-compatible upstream; LiteLLM keeps provider custody and the 7-model fan-out, Envoy adds the edge, model virtualization, and token accounting. Three tier keys (local / external / frontier) exist and are vaulted; the tiers are declared in the policy SSOT. Binding group→tier at the gateway (Option B) is the near-term step — today the plane runs on a tier key.
Validated: HTTP 200 across Anthropic (haiku) and OpenAI (gpt-4o-mini). Tier keys llm-local / external / frontier vaulted to 1Password. The gateway is loopback-only — no unauthenticated public exposure.
Access is Duo-gated at the Cloudflare edge; the leaver signal inverts the model — disable-first, notify-after — and a single signed SSF/CAEP event drops the agent's token and every access it held, instantly.
| Capability | Evidence | Status |
|---|---|---|
| MCP per-tool-call authz | 57 tools; allow + deny; Duo audit 5/5 apps | proven |
| LLM gateway + tiering | HTTP 200 · 2 providers; 3 vaulted tier keys; :8210 loopback | proven |
| Directory sync (two-path) | 31 AD / 5 Entra / 1 Google = 46; 17 SG-* on AD path | proven |
| JML + Duo-push CAB + SSF revoke | fabric end-to-end; SSF vs CII + caep.dev | proven |
| Duo Authorization Policy (user-level) | mcpgw group→tool policy not yet configured | pending |
| LLM group→tier binding (Option B) | tier keys exist; group-driven selection not wired | pending |
| Public LLM downstream auth · Ollama Local tier | loopback-only today; no public auth / no local tier | pending |
| Secure Access private-app API | edge live (CF+Duo); programmatic grant/revoke | roadmap |
Every "proven" row maps to a test case in the end-user test plan's coverage matrix; every "pending" is a named prerequisite, not a silent gap.
The same fabric shape maps onto a real acute-care hospital. The healthcare-specific twist: providers aren't hired, they're credentialed — the Medical Staff Office is a second source of truth alongside HR, and Epic role/template assignment is its own governed step.
| Activity | HR | Med Staff | IAM | Epic Sec | IGA | SOC/ITDR | Compliance/HIM |
|---|---|---|---|---|---|---|---|
| Onboard staff (nurse / tech) | A | — | R | C | I | — | I |
| Credential + onboard provider | C | A | R | C | I | — | C |
| Epic role / template assignment | — | C | C | A | C | — | C |
| Access request (add'l system) | — | C | R | C | A | — | I |
| Mover (unit / role / locum) | A | C | R | C | C | — | I |
| Leaver + real-time revoke | C | C | A | R | R | C | I |
| Break-glass emergency access | — | C | I | R | I | R | A |
| Access certification / recert | I | C | C | C | A | — | C |
| HIPAA access audit / ITDR | — | — | I | C | C | R | A |
Clinicians invoke break-glass; the data / application owner approves access requests — folded into Consulted above. The point for a Duo customer: this ownership map already exists in their org — the fabric just makes each lane a governed, auditable step.
Read as a Duo Care Signature Support engagement: a reference architecture and de-risking rehearsal for a customer's own agentic-AI adoption — standards-first, mapped to what they already own. Success has to land for both sides of the table.
The Care Signature win is the customer's win, restated: durable adoption of Duo as the identity control plane for AI — the reference build, validated, in their hands.
Gary Townsend · Customer Success Technical Leader · Duo Care Signature Support · Customer Experience · Cisco · personal skills lab, synthetic data only.