EAP Status ¶
This page defines the scope of each EAP platform capability and shows its current delivery status. Target dates are planning targets, not SLAs.
Environment Availability ¶
- Commercial Production — Available. EAP is operating and open for onboarding in the commercial production environment.
- W4G — Planned. EAP deployment is planned by the end of F27 Q1.
Platform Capabilities ¶
| Capability area | What it provides | Current status and limitations | Target/ETA |
|---|---|---|---|
| Identity and authorization | Give each Agent its own non-human identity instead of using a human engineer's identity. Control which people and applications can call each Agent. | Available. Non-human Agent identities and caller authorization are implemented. | — |
| Onboarding and change governance | Review the customer team's agent repo and Agent Registry configuration before onboarding a new Agent or deploying a change to either input. Review prompt-injection risks, risky commands, data-exfiltration paths, hard-coded secrets, new or untrusted MCP servers, and other security or governance concerns. Automated analysis may support the review, but human reviewers make the final decision. | Available (manual). Reviews are performed manually today. | F27 Q1 — automate more of the process with GitHub Actions and an Agent. |
| Action gating | Let customer teams define in their agent repos which tool calls require human approval. Enforce those approval rules at runtime so Agents cannot bypass them. | In progress. The planned runtime enforcement is not yet complete. | Early F27 Q1 |
| Sandboxing and egress control | Isolate runtime execution. Deny network egress by default and allow it only to approved destinations. | In progress. Remaining work will complete the planned implementation of these controls. | End of F27 Q1 |
| Runtime prompt-injection and sensitive-data protection | Detect and reduce unsafe instructions and sensitive-data exposure risks at runtime. | Planned. These runtime protections are not yet implemented. | End of F27 Q1 |
| Centralized secrets | Store credentials in an EAP-owned path in Keeper and inject them into the runtime as environment variables through Kubernetes Secret objects. | Available. Central storage and runtime injection are implemented. | — |
| Cost control | Use Cisco Collab LLM Proxy for model-usage tracking and cost control instead of building a separate EAP cost-control system. | Available. EAP relies on Cisco Collab LLM Proxy for these controls. | — |
| Artifact lifecycle and access control | Govern generated artifacts, their authorized access, retention, and removal throughout their lifecycle. | Available with limitations. Retention, access, and removal controls need more work. | End of F27 Q1 |
| Audit and observability | Provide execution evidence, metrics, logs, traces, and operational visibility. | Available with limitations. Audit records and operational telemetry need more work. | Early F27 Q1 |
| Kill switches | Let authorized operators stop unsafe or unstable Agent runs. | In progress. Central stop controls are not yet complete. | Early F27 Q1 |
| Model-provider scope | Use Cisco Collab LLM Proxy as EAP's only model provider. | Available. Other model providers are not supported and support is not planned. | — |
| Resilience, high availability, and disaster recovery | Maintain service availability and recover from infrastructure or datacenter failures. | Available with limitations. Resilience, high availability, and disaster recovery need more work. | End of F27 Q1 |