IAM.Core
Coordination layer for tools, agents, APIs and MCP contracts.
Key capabilities
- Tool catalog and capability discovery
- Agent session context and tenant scope
- Cross-product MCP and API call composition
Step-by-step guides
Use cases
Start with the outcome: open a guide, prepare prerequisites, follow the steps and verify the success signals.
01 Connect a product or MCP tool to IAM.CoreThe tool appears in the catalog and is available to the agent only in the permitted tenant scope.
- Audience
- Integration developer
- Outcome
- The tool appears in the catalog and is available to the agent only in the permitted tenant scope.
Before you start
- Service URL and health endpoint
- MCP manifest or OpenAPI contract
- Tenant and minimum required scopes
Steps
- Open the tool catalogIn IAM.Core, open Tools → Registry and select the target tenant.
- Register the capabilitySet the transport, endpoint, schema, timeout and scopes. Never put a secret in the manifest.
- Verify discoveryRun Probe; Core must receive health=ready and read the tools/resources list.
- Make a safe callCall a read-only method in a test session and verify the correlation id in the audit log.
The capability is Ready and the call and response share one correlation id.
If Probe is unavailable, check DNS/NetworkPolicy, token audience and schema-version compatibility.
02 Run an agent session with approval for risky actionsThe agent completes permitted steps and pauses before write or execute actions.
- Audience
- Project owner or operator
- Outcome
- The agent completes permitted steps and pauses before write or execute actions.
Before you start
- Registered tools
- Ask permission profile
- A user allowed to start sessions
Steps
- Create a sessionSelect Agent Sessions → New, then tenant, project and the ask profile.
- Describe the resultState the task and completion criterion; do not include secrets in the prompt.
- Review the approval requestReview the tool, arguments, affected resources and call rationale.
- Approve or rejectApprove one call or reject it with a note; do not enable a global bypass.
The timeline contains the request, approval decision, tool result and final session state.
If approval is not requested, check the permission profile and the tool classification.
Open detailed manual
Every application screen has a separate page with controls, safe example values, CLI/API alternatives and status-specific recovery steps.
Role in the ecosystem
IAM.Core connects stand-alone IAM products into a controlled chain. He gives the agent a catalog of available capabilities, a permission context, and a single method call the tool. Core does not perform the domain functions of Router, Secure, Docs or Comm does not turn the portfolio into a monolith.
Main scenario
- The agent or application opens a session with the tenant/user context.
- Core returns the available MCP/API tools for this scope.
- The client selects a capability and forms a structured call.
- Policy/identity checks are performed before domain action.
- The result and audit context are returned to the initiator.
agent session → tool discovery → scoped invocation → product capability → receipt
Architecture and integrations
Core acts as a control-plane boundary for the tool registry. Typical outline uses IAM.Identity for identity/tenant scope, IAM.Secure for inspection and IAM.Router for a model route. Agent clients connect via MCP or HTTP API.
Only capability metadata and scoped calls are exchanged with Marketplace Core: The user agent runtime remains at IAM.Hosting.
Data and security
- capability catalog should not contain secrets;
- credential references remain scoped to the user/tenant;
- unknown tool or unsuitable role ends in fail-closed;
- downstream content is considered untrusted until the policy check;
- correlation/request id goes through the entire chain for auditing.
Operation
Check registry health, availability of critical tools, latency and share failures for each downstream. The new instrument is first registered and checked for staging; only then the capability is published to production agents.
Limit of responsibility
Core coordinates but does not store the shared memory of all products and does not replace them own API. If you use one product without cross-product workflow, direct integration with its API may be sufficient.
Verified entry points
- Application
- https://core.iamrouter.ru/
- Portfolio
- https://iamgroup.ru/en/