Cakewalk Documentation
Access Management for your entire workforce. AI agents and human identities.
Cakewalk governs access for the people in your company and for the AI agents working alongside them. Human Access automates the access lifecycle for your people. Agent Access decides what an agent is allowed to do in your apps. Both draw on one directory and one policy model, and these docs cover all three.
🧩 How the two modules fit together
Before you pick a path, it helps to know how the two halves relate. People and agents draw on the same identities, the same apps and the same policy model. An agent's access is its person's access, which is why joining, moving and leaving change both at once.
🧭 Find your starting point
Now to the practical part. What you do first depends on your role and on the module your company runs.
🔁 Follow the access lifecycle
Setup done, the work settles into a cycle. Access moves through the same four stages whether it belongs to a person or an agent.
Bring your systems in, so Cakewalk knows who works here and what they use.
Human Access
Identity sources: sync people from your HRIS or identity provider
Apps: discover and import what your company already runs
Agent Access
Connections: the apps an agent is allowed to reach through
Agents: the agent platforms your company approves
Get access to the right people and agents, without a ticket queue.
Human Access
Auto provisioning Agent Cake creates the account for you
Requests: self serve, routed to the right approver
Users and groups: what a group carries by default
Agent Access
An agent holds nothing of its own. It inherits the Connections its person already authorized, which is why Connections are the grant.
Decide what is allowed while it happens, not afterwards.
Human Access
Policies: who gets what automatically, and what needs a human
Agent Access
Policies: evaluated per tool call, not per session
The tool call lifecycle: where the decision happens and how approval reaches a person
The default posture allows Read, escalates Write and denies Destructive and External.
Confirm the picture is still true, and prove it to an auditor.
Human Access
Access reviews: campaigns that ask owners to confirm or revoke
Request log: every request and the task trail behind it, kept for auditability
Agent Access
Agent activity: what each agent has been doing, per tool call
📖 Go deeper
When the how to guides are not enough, these explain the model underneath and how to drive Cakewalk from your own code.
How the platform works underneath, for when the how to guides are not enough.
Human Access
Access governance pillars: the model the whole module is built on
Roles and permissions: who can do what inside Cakewalk
Data models: users, apps, policies, requests and tasks
Agent Access
The three actors: the person, the agent and the app, and who holds what
The MCP Gateway: the proxy every tool call passes through
The tool call lifecycle: where a call is evaluated and how approval reaches a person
Trust and security: what the gateway holds and what it never returns
Call Cakewalk from your own code. This is a Human Access surface. Agent Access has no public API.
Getting started: your first call
Authentication: how to get a token and use it
API reference: users, applications, requests, policies and access reviews
Connect an MCP client: point your own agent at Cakewalk's data
Webhooks: get told when something changes, instead of polling
Rate limits and pagination are documented alongside the reference.
🔌 Integrations
None of it matters until Cakewalk is connected to the systems you already run. There are three families.
🛟 Running into something?
Finally, the problems people actually hit most often.
Need a hand? Email service@getcakewalk.io.