The gateway is not the end of the identity story.
Use Steward to connect enterprise AI clients to compatible local MCP tools while preserving user-bound access to supported AD resources.
Many AI integrations authenticate the user at the front door but then substitute a shared backend identity for the useful work. Steward is designed for the cases where the protected Windows resource should continue to authorise the actual user.
Four things are recorded
Each request can be described by the human, the agent the human is using, the configured backend and the target resource. Per-backend agent restrictions and local policy rules can refuse a request before the tool runs.
Two authority models
| Backend type | Authority at the target |
|---|---|
| Supported AD/Windows resource | Existing resource permissions can remain bound to the user. |
| API-backed MCP such as Falcon MCP | The target platform authorises the backend API credential; Steward still records the caller and agent. |
This distinction is important. Steward does not pretend that an API platform received a delegated user token when it did not.
Existing STDIO MCP tools
Compatible tool-oriented STDIO MCP servers can remain local processes. Steward exposes configured tools remotely over a governed Streamable HTTP boundary rather than making every tool server independently internet-facing.
