- Why Primary?
- /
- What is Primary
- /
- Zero Trust Architecture
Zero Trust Security
Trust Is Not a Control Strategy
A Reliable Control Plane Must Continuously Verify Every Identity, Request, Action, and Data Interaction.

A New Security Model
Why the Agentic Enterprise Changes the Security Model
Enterprise security was designed for a world in which people signed into applications, performed defined tasks, and operated within relatively predictable workflows.
Agentic systems change that model.
Agents can operate continuously, invoke tools, retrieve sensitive information, call other agents, move between systems, and execute multistep processes at machine speed. Their identities may be temporary. Their permissions may be inherited. Their actions may change as context changes.
A control plane cannot safely govern this environment by assuming that an authenticated actor, approved application, or trusted network remains trustworthy.
Every interaction must be continuously evaluated.
Zero Trust at the Core
The Foundation of a Reliable Control Plane
A control plane becomes valuable only when enterprises can trust its decisions and depend on its enforcement.
Primary’s Zero Trust architecture connects identity, context, data sensitivity, permissions, application state, workflow stage, and real-time risk before determining whether an action should proceed.
No human, agent, application, device, model, or workload is inherently trusted. Authority is granted for a specific purpose, within a defined scope, and for only as long as it is required.
This creates a dependable foundation for controlling activity across a distributed and increasingly autonomous enterprise.
Continuous Verification
Secure Every Human and Agentic Interaction
Verify Every Identity
Primary establishes who—or what—is making each request. Human identities can be evaluated alongside device posture, session state, role, location, and authentication signals. Agentic identities can be evaluated according to ownership, purpose, credentials, delegated authority, runtime environment, and approved workflow. Identity becomes more than a login event. It becomes a continuously assessed security signal.
Apply Least-Privilege Authority
Humans and agents receive access only to the information, systems, tools, and actions required to complete an authorized task. Primary can narrow permissions according to the actor, data classification, application, workflow stage, and current business context. Authority can be temporary, conditional, or limited to a single transaction.
Reevaluate Trust Continuously
The conditions surrounding an interaction can change after access has been granted. A device may become compromised. An agent may invoke an unexpected tool. A workflow may begin accessing data outside its normal scope. A user may attempt to move information into an unapproved application. Primary continuously reevaluates trust as activity unfolds and can restrict, challenge, isolate, or terminate access when risk changes.

Distributed Enforcement
Zero Trust Enforcement Across Every Touchpoint
A centralized policy is not enough. Security must be enforced wherever humans and agents interact with enterprise data.
Primary extends the control plane across SDKs, agent workspaces, enterprise Workspaces, gateways, applications, APIs, models, and data environments.
SDKs
Primary SDKs embed identity, policy, telemetry, and enforcement directly into applications and agentic workflows. They provide context about the requested action, the executing actor, the data involved, and the intended outcome.
Agent Workspaces
Within agent workspaces, Primary can govern which agents are available, which tools they may invoke, which data sources they can reach, and which actions require human review or approval.
Zero Trust Workspace
The Workspace provides visibility and enforcement at the point where human users and Workspace-based agents interact with SaaS applications, AI platforms, websites, and enterprise information. Primary can inspect data movement, restrict application behavior, mask sensitive information, and prevent unauthorized transfers.
Gateway
The Gateway governs traffic between agents, models, applications, APIs, tools, and enterprise systems. It can authenticate requests, apply policy, inspect context, limit downstream access, and block unsafe activity before it reaches protected resources.
Data Touchpoints
At each data access point, Primary connects the request to the identity, purpose, workflow, and applicable policy. Sensitive information can be masked, tokenized, encrypted, filtered, or withheld according to the requirements of the interaction.

Controlled Autonomy
Govern Autonomy Without Slowing Innovation
The objective of Zero Trust is not to prevent agents from acting. It is to establish the conditions under which they can act safely.
Primary allows organizations to define clear boundaries around autonomy.
Low-risk actions may proceed automatically. Sensitive requests may receive limited access. Material transactions may require additional verification. High-impact decisions may be routed to a human for approval.
These controls allow teams to adopt new models, agent frameworks, applications, and tools without creating a separate security architecture for each one.
Innovation remains distributed. Governance remains consistent.
Runtime Protection
Security That Operates While Work Is Happening
Real-Time Policy Enforcement
Primary evaluates policy at the moment an identity requests data, invokes a tool, transfers information, initiates a transaction, or performs a sensitive action. Security decisions are enforced during execution—not simply recorded for later review.
Human Oversight Where It Matters
Primary allows enterprises to define when humans must remain in the loop, when they can supervise from outside the workflow, and when an agent may act autonomously. Approval requirements can reflect the sensitivity, value, reversibility, and potential impact of each action.
Complete Auditability
Every access request, policy evaluation, approval, denial, tool call, data interaction, and enforcement decision can be captured as part of a continuous workflow record. Security and compliance teams gain the evidence required to understand what happened, why it was allowed, and whether the process operated as intended.
Containment by Design
When a human account, agent, application, or credential is compromised, Primary limits the potential impact through scoped permissions, isolated execution, continuous verification, and immediate revocation. One compromised actor does not need to become an enterprise-wide incident.
Consistent Security Across a Heterogeneous Enterprise
Primary applies a common Zero Trust model across different clouds, applications, data platforms, models, agent frameworks, and execution environments. Enterprises can preserve technology choice while maintaining one consistent security and governance architecture.

Built to Scale
Security That Scales with the Enterprise
As organizations move from a handful of agents to thousands of human and non-human actors, static permissions and perimeter-based defenses become increasingly unreliable.
Primary turns Zero Trust into a shared enterprise service.
Identity, policy, context, telemetry, and enforcement operate through one control plane, allowing security to scale alongside the workforce, the application environment, and the volume of autonomous activity.
The result is not simply a more secure control plane.
It is a control plane the enterprise can rely on.