> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs-beta.getzep.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs-beta.getzep.com/_mcp/server.

# Governance

> Govern unified context with RBAC, ABAC policies, source traceability, Audit Logs, and API Logs.

Governance applies to enterprise context graphs, agent memory, and customer or account context. Zep applies authorization and audit controls to Context Graph operations. Role-based access control governs dashboard users.

Attribute-based access control governs API keys and UserGroups.

Zep separates two problems:

* **Who can manage the account and projects**: teammates in the dashboard. Solved with [managing team access](/role-based-access-control) (role-based access control, RBAC), and, for how those teammates authenticate, [enterprise SSO](/enterprise-sso).
* **What context each agent and Context MCP user can reach**: agents and other callers. Solved with [policy-based access control](/policy-based-access-control) (attribute-based access control, ABAC), applied to API keys for [agent access](/attribute-based-access-control) and to UserGroups for [UserGroup access](/usergroup-access).

Use RBAC for humans. Use policies when you need least-privilege access to context for agents and Context MCP users. A [content policy](/content-policies) controls a third problem: what derived information is permitted to enter a Context Graph at all. Encryption, compliance certifications, and deployment trust boundaries live under [Security & Compliance](/security-compliance).

Zep access policies control which Zep context a caller can retrieve or change. They do not authorize an action in an external system. Your application must enforce its own tool and action permissions.

## Access and policy

#### [Managing team access](/role-based-access-control)

Grant dashboard permissions with account- and project-scoped roles (RBAC).

#### [Enterprise SSO](/enterprise-sso)

Make your identity provider the source of truth for member sign-in.

#### [Zep Support access](/support-access)

Give Zep Support read-only access to your account for 72 hours, and revoke it at any time.

#### [Policy-based access control](/policy-based-access-control)

Limit which actions and context each agent and Context MCP user can reach with ABAC policies attached to API keys and UserGroups.

#### [Content policies](/content-policies)

Define the categories of derived information that Zep must drop before it enters a Context Graph, and audit what was dropped.

## Source traceability and visibility

Facts and graph artifacts can retain references to the source episodes from which Zep derived them. Use these references to trace retrieved graph data to its source. If you must connect a generated answer to source material, retain the retrieval results and their source references in your application.

#### [Audit logging](/audit-logging)

Review the maintained list of recorded member, API key, project,
access-control, settings, and data-operation events.

#### [API logging](/api-logging)

Review recorded SDK and API request activity for debugging and query-audit workflows.

## Related

* [Episode metadata projection](/episode-metadata-projection): metadata attached at ingestion is what source-based policies evaluate.
* [Security & Compliance](/security-compliance): SOC 2, HIPAA, BYOK, BYOM, and deployment models.