# Agent access follows the employment record

[Journal](/journal/)

August 27, 2026 · [evidence](/journal/#evidence)



Rippling ties agent permissions to workforce records. It reports two live governance products and two more on waitlists.

![An employment record drives a linked agent credential and policy mechanism, while a green recorded route passes through a valve to two tool connections.](/_astro/agent-access-follows-the-employment-record.BJ9DNXSU_zx9U8.avif)

An agent’s tool access should follow the employment record of the person who owns its work. Rippling [reports that its gateway derives access from each employee’s role, team, and employment status](https://www.rippling.com/blog/introducing-rippling-ai-governance). When that source record changes, agent access can change with it.

MCP, or Model Context Protocol, is [a standard for connecting an agent](https://www.rippling.com/blog/introducing-rippling-ai-governance) to approved tools. A gateway is software that checks a request before it goes onward. The useful boundary sits between an agent’s proposed call and the tool that could act on it.

## Four products have two availability states

Rippling’s announcement [reports two live products and two waitlist products](https://www.rippling.com/blog/introducing-rippling-ai-governance):

1.  Rippling [reports MCP Gateway as live](https://www.rippling.com/blog/introducing-rippling-ai-governance).
2.  Rippling [reports Agent Identity Management as live](https://www.rippling.com/blog/introducing-rippling-ai-governance).
3.  One waitlist offering [would route model requests under hard budgets and record usage and cost for each request](https://www.rippling.com/blog/introducing-rippling-ai-governance).
4.  Another waitlist offering [would find tools and agents that the company did not provision](https://www.rippling.com/blog/introducing-rippling-ai-governance).

Rippling [keeps the last two capabilities on waitlists](https://www.rippling.com/blog/introducing-rippling-ai-governance). Their descriptions do not make them available. This distinction matters because a four-part product diagram can otherwise flatten a launch into one apparent release.

## The person’s record drives access without copying it

Before a tool call goes onward, Rippling says MCP Gateway [checks who made the request and whether policy allows it](https://www.rippling.com/blog/introducing-rippling-ai-governance). Rippling says the live gateway then [records the call for review](https://www.rippling.com/blog/introducing-rippling-ai-governance). Approval happens against workforce context rather than a detached credential list.

Rippling says access [updates automatically when employees join, change roles or teams, or leave](https://www.rippling.com/blog/introducing-rippling-ai-governance). A role change can alter the allowed tool set. A departure can remove the authority that supported the connection. The employment record becomes the event source for access changes.

Following the person’s record does not mean copying the person’s permissions. Rippling says an agent working for an employee [should not automatically receive all of that employee’s permissions](https://www.rippling.com/blog/introducing-rippling-ai-governance). Its example [allows selected repository actions while blocking destructive or sensitive ones](https://www.rippling.com/blog/introducing-rippling-ai-governance). The agent gets authority shaped for its work, with the employment record supplying organizational context.

Agent Identity Management supplies [the other live half](https://www.rippling.com/blog/introducing-rippling-ai-governance). Rippling says companies can [create and manage agent records beside employee and service-account records](https://www.rippling.com/blog/introducing-rippling-ai-governance). Administrators can [assign owners, set permissions, and provision agents into third-party apps](https://www.rippling.com/blog/introducing-rippling-ai-governance). The agent remains a separate principal even when a person’s employment record governs its access.

## Product descriptions are not outcomes

Rippling’s announcement [reports product capabilities rather than measured outcomes](https://www.rippling.com/blog/introducing-rippling-ai-governance). It [gives no adoption count, policy-block rate, access-revocation time, cost reduction, or independent security result](https://www.rippling.com/blog/introducing-rippling-ai-governance). The evidence supports an architecture claim, not a performance claim.

Rippling is neither a Muniment customer nor an endorser.

## Sources

1.  [Rippling: Introducing Rippling AI Governance: Visibility and Control](https://www.rippling.com/blog/introducing-rippling-ai-governance) www.rippling.com
