Tool & Runtime Security

Temporal Windows

Authority that only exists when it should.

Grant authority that is valid only within a defined time window, so permissions exist when the work happens and disappear when it does not.

Time-boxed permissions

Bind an agent's authority to a schedule or window, so it cannot act outside the times you intend.

  • Authority valid only in-window
  • Blocked outside the window
  • No lingering standing access

Pairs with delegation

Delegated and session authority can expire with the task, the session or a fixed window, narrowing the blast radius over time.

  • Expire with task or session
  • Fixed windows for sensitive work
  • Least privilege that keeps up

Enforced, not advisory

The window is checked at the intercept, so an out-of-window action is blocked, not merely flagged.

More in Tool & Runtime Security.

Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.

1.0MCP & Tool Security

Decide which agent may call which tool.

Learn more
2.0AI Gateway

Authorise every model call.

Learn more
3.0Runtime Containment

Contain or kill any agent, instantly.

Learn more
4.0Breakglass

Emergency access without invisible exceptions.

Learn more

See Temporal Windows in your workflow.

Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.