For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cakewalk Documentation

Access Management for your entire workforce. AI agents and human identities.

Cakewalk governs access for the people in your company and for the AI agents working alongside them. Human Access automates the access lifecycle for your people. Agent Access decides what an agent is allowed to do in your apps. Both draw on one directory and one policy model, and these docs cover all three.

GitBook Assistant

Auto provisioningConnect an agent

🧩 How the two modules fit together

Before you pick a path, it helps to know how the two halves relate. People and agents draw on the same identities, the same apps and the same policy model. An agent's access is its person's access, which is why joining, moving and leaving change both at once.

How they connect User lifecycle

🧭 Find your starting point

Now to the practical part. What you do first depends on your role and on the module your company runs.

👥 Human Access

1

Connect your identity source

Your HRIS or identity provider. Cakewalk imports your people with their team, title and manager.

2

Import and govern your apps

Bring in the apps your company already uses and assign an owner to each one.

3

Set policies and run a review

Policies decide who gets what automatically. A review confirms the picture is still true.

The identity source is the spine. Everything downstream keys off it, so connect it before anything else.

Human Access setup App Owners

🤖 Agent Access

1

Set up your company

Organization name, domain and the provider your team signs in with.

2

Import your team

Sync from your HRIS or identity provider, or add people by hand.

3

Build your catalogs

Choose the Connections and Agents your company makes available.

The default posture allows Read, escalates Write and denies Destructive and External. Tune it before you widen access, not after.

Agent Access setup Policies

👥 Human Access

1

Find the app you need

Browse what your company already runs, from Slack or the web.

2

Request access

Say what you need it for. No ticket, no waiting on IT to notice.

3

Track it and tidy up

Follow the request through, and drop access you no longer use.

Requests route to your manager, so that field has to be set on your profile before anything can be approved.

Employee quick start

🤖 Agent Access

1

Connect the apps you use

Open My Connections and authorize each app your agent will need.

2

Set up your agent

Open My Agents, pick yours and follow the install method it shows.

3

Answer approval prompts

Sensitive actions pause and ask you before they run.

Your agent inherits exactly your access and nothing more. Connections are per person, so nobody else's apps come with it.

Employee setup

🔁 Follow the access lifecycle

Setup done, the work settles into a cycle. Access moves through the same four stages whether it belongs to a person or an agent.

Bring your systems in, so Cakewalk knows who works here and what they use.

Human Access

  • Identity sources: sync people from your HRIS or identity provider

  • Apps: discover and import what your company already runs

Agent Access

  • Connections: the apps an agent is allowed to reach through

  • Agents: the agent platforms your company approves

Get access to the right people and agents, without a ticket queue.

Human Access

  • Auto provisioning Agent Cake creates the account for you

  • Requests: self serve, routed to the right approver

  • Users and groups: what a group carries by default

Agent Access

  • An agent holds nothing of its own. It inherits the Connections its person already authorized, which is why Connections are the grant.

Decide what is allowed while it happens, not afterwards.

Human Access

  • Policies: who gets what automatically, and what needs a human

Agent Access

  • Policies: evaluated per tool call, not per session

  • The tool call lifecycle: where the decision happens and how approval reaches a person

The default posture allows Read, escalates Write and denies Destructive and External.

Confirm the picture is still true, and prove it to an auditor.

Human Access

  • Access reviews: campaigns that ask owners to confirm or revoke

  • Request log: every request and the task trail behind it, kept for auditability

Agent Access

  • Agent activity: what each agent has been doing, per tool call

📖 Go deeper

When the how to guides are not enough, these explain the model underneath and how to drive Cakewalk from your own code.

How the platform works underneath, for when the how to guides are not enough.

Human Access

Agent Access

Call Cakewalk from your own code. This is a Human Access surface. Agent Access has no public API.

  • Getting started: your first call

  • Authentication: how to get a token and use it

  • API reference: users, applications, requests, policies and access reviews

  • Connect an MCP client: point your own agent at Cakewalk's data

  • Webhooks: get told when something changes, instead of polling

Rate limits and pagination are documented alongside the reference.

🔌 Integrations

None of it matters until Cakewalk is connected to the systems you already run. There are three families.

🛟 Running into something?

Finally, the problems people actually hit most often.

life-ring

Need a hand? Email service@getcakewalk.io.