> ## Documentation Index
> Fetch the complete documentation index at: https://docs.katyar.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

> What Katyar actually enables — secure, governed, autonomous AI agents at enterprise scale

Katyar is not just another API gateway or monitoring tool.\
It is a complete **governance plane** purpose-built for autonomous AI agents — giving enterprises strong identity, semantic safety, intent-aware policies, and graduated human oversight.

Below are the four core capability pillars that make Katyar the foundation for safe agentic automation in 2026 and beyond.

<div style={{ display: 'grid', gridTemplateColumns: 'repeat(auto-fit, minmax(300px, 1fr))', gap: '1.5rem', margin: '2rem 0' }}>
  <Card title="1. Agent Identity & Access Control" href="/capabilities/agent-identity">
    Strong, federated identity for every agent. No ghost users. Dynamic task-scoped access. Full non-repudiation.
  </Card>

  <Card title="2. Semantic Protection & Threat Detection" href="/capabilities/semantic-protection">
    Real-time defense against prompt injection, jailbreaks, PII leakage, secrets exfiltration, and emerging semantic attacks.
  </Card>

  <Card title="3. Policy & Governance Engine" href="/capabilities/policy-engine">
    Fine-grained, business-logic-aware authorization. Visual + Cedar policies. MCP-native tool governance.
  </Card>

  <Card title="4. Human-in-the-Loop & Oversight" href="/capabilities/human-in-the-loop">
    Async, low-friction approvals for high-stakes actions — integrated into Slack, Teams, dashboard, or custom workflows.
  </Card>
</div>

### Why These Capabilities Matter in 2026

* Regulators require **verifiable identity** + **human oversight** for high-risk AI systems (EU AI Act, NIST, DORA, UK ICO)
* Enterprises lose **millions** to prompt-engineered attacks and unauthorized agent actions
* Agent projects stall because teams cannot prove **auditability** or **risk control**
* Multi-agent systems need **isolation** and **blast-radius limitation** — Katyar enforces it natively

Each capability is deeply integrated — identity feeds policy, semantic checks run before policy evaluation, HITL triggers only on policy-flagged high-risk events, and everything is logged with cryptographic integrity.

→ Explore each capability in detail below.
