Workload identity is an enterprise feature. Contact support@abundly.ai to enable it for your workspace.
The agent’s identity
Workspace admins find the values your cloud needs under Workspace → Workload identity:- Issuer URL — the URL your cloud trusts, for example
https://app.abundly.ai/oidc. It’s the same for every agent in your deployment. - Workspace ID — used to restrict the trust to your workspace.
workspace:<workspace id>:team:<team id>:agent:<agent id> (agents without a team have team:none). When a capability is set to workload identity, its settings show the exact principals to grant for that agent, its team and the whole workspace.
Each token also carries these claims. Every claim is always present, empty when it doesn’t apply:
Tokens are minted per run, so a token issued for one user or run is never reused for another.
For example, the decoded token of an agent in a team, working in a chat started by a signed-in user, used for Google Cloud:
"trigger": "scheduler", a run_id, and empty chat_id and user_id.
Set up Google Cloud
1
Enable the APIs
In your Google Cloud project, enable the IAM Service Account Credentials API and the Security Token Service API, plus the APIs the capability uses (Drive, Docs and Sheets for Google Drive; BigQuery for BigQuery).
2
Create a workload identity pool that trusts Abundly
Replace the issuer URL and In Google Cloud, a pool trusts an external issuer through what Google calls a provider. Open it under IAM & Admin → Workload Identity Federation and copy its Default audience (
YOUR_WORKSPACE_ID with the values from Workspace → Workload identity.https://iam.googleapis.com/projects/<project number>/locations/global/workloadIdentityPools/abundly/providers/abundly). That’s the value you paste into Abundly.3
Grant access
Choose who gets access with the BigQuery can grant roles to the agent directly, without a service account:Add
--member value:Google Drive needs a service account, because Drive files are shared with an email address. Create one, let the agent act as it, then share files or folders with the service account’s email:
roles/bigquery.dataViewer and roles/bigquery.metadataViewer the same way, on the project or on specific datasets. Queries run, and are billed, in a project where the agent has BigQuery Job User.4
Connect your workspace
In Workspace → Workload identity, add the Default audience under Audiences, with a label such as “Google Cloud”. Each relying party that trusts your agents gets its own audience in this list, so tokens meant for one can’t be used at another.
5
Configure the capability
- BigQuery: set Authentication to Workload identity and save. If the workspace has more than one Google Cloud audience, pick which one to use. There’s no project to configure: the agent works in the projects you granted it access to. To point agents at the right projects and datasets, add a note to the capability in the workspace or team settings, or keep a data guide as a workspace document.
- Google Drive: choose Workload identity mode, pick the audience if there are several, enter the service account email, save, then click Test connection.
Good to know
- An agent’s subject includes its team, so moving an agent to another team changes its identity. Team-based grants follow the agent automatically; grants on the old subject stop working.
- Tokens are valid for five minutes and are only used by the platform to obtain Google credentials. They are never shown to the agent’s model.

