Governance
Governance applies to enterprise context graphs, agent memory, and customer or account context. Zep applies authorization and audit controls to Context Graph operations. Role-based access control governs dashboard users.
Attribute-based access control governs API keys and UserGroups.
Zep separates two problems:
- Who can manage the account and projects: teammates in the dashboard. Solved with managing team access (role-based access control, RBAC), and, for how those teammates authenticate, enterprise SSO.
- What context each agent and Context MCP user can reach: agents and other callers. Solved with policy-based access control (attribute-based access control, ABAC), applied to API keys for agent access and to UserGroups for UserGroup access.
Use RBAC for humans. Use policies when you need least-privilege access to context for agents and Context MCP users. A content policy controls a third problem: what derived information is permitted to enter a Context Graph at all. Encryption, compliance certifications, and deployment trust boundaries live under Security & Compliance.
Zep access policies control which Zep context a caller can retrieve or change. They do not authorize an action in an external system. Your application must enforce its own tool and action permissions.
Access and policy
Source traceability and visibility
Facts and graph artifacts can retain references to the source episodes from which Zep derived them. Use these references to trace retrieved graph data to its source. If you must connect a generated answer to source material, retain the retrieval results and their source references in your application.
Related
- Episode metadata projection: metadata attached at ingestion is what source-based policies evaluate.
- Security & Compliance: SOC 2, HIPAA, BYOK, BYOM, and deployment models.