Your identity programme covers people and service accounts. Agents slipped through.

AgentValet gives every AI agent its own identity, only the access you grant it, a person’s approval before anything risky, and a signed record of every call. It covers the agents your developers already run, and none of them holds a key.

The same discipline you apply to people, applied to agents.

Authentication, authorisation and audit already cover your staff and your service accounts. An agent with a pasted API key gets none of the three. AgentValet sits between your agents and the tools they use and puts all three back.

Its own identity for every agent
Each agent signs every request with its own key, so every row in the record ties back to one named agent. Each gets a SPIFFE-format ID and, if you opt in, a W3C did:web document any resolver can check.
Access you grant, scope by scope
Nothing is allowed until you allow it. Organisation-wide guardrails sit above every agent’s grants, and a refusal always beats an approval rule, which always beats an allow. On Studio and above, grants can limit who an agent may email or message, and ask or block when a send would leave your organisation.
A person’s yes before anything risky
A held call waits while someone approves it on their phone, with a passkey, from an email link or in the dashboard. On Team and above, delegates share the load so agents don’t stall waiting on one person.
Keys the agent never sees
Credentials are encrypted with a key per organisation, held in hardware on paid plans, and decrypted in memory for a single call. The agent only ever holds its signing key.
A record nobody can rewrite
The audit log accepts new rows and nothing else, and every decision carries a signed receipt. Each connected account is labelled with its real identity, such as the GitHub login or Google email, so a row says which account acted.
Signals when behaviour changes
Rule-based detectors flag scope creep, a first call to a new platform, bursts of refusals and off-hours activity against a nightly baseline per agent, and can suspend an agent on a breach. The circuit breaker suspends one after repeated failures.

What your security team will see.

Real screens from our demo organisation, not mock-ups.

Rules that sit above every agent

Guardrails run before any agent’s own policy and can’t be overridden by it. Require a person’s sign-off for a kind of action, or refuse it outright, for every agent in the organisation at once.

The organisation guardrails screen with a rule requiring human approval for GitHub file writes, applying to all roles.
A guardrail that makes every GitHub file write wait for a person.

A log they can filter, export and check

Every call is a row: who, which agent, which tool and action, and the decision, each with a signed receipt. Filter by agent, action or date, and export it for your auditor.

The audit log: a list of agent calls with their platform, action and result, one pending approval, the rest allowed, each marked signed, with filters and export buttons.
The audit log with one call waiting for approval. Export to CSV, JSON or a printable PDF is on Team and above.

Microsoft governs the agents Microsoft builds. This covers the rest.

Entra Agent ID looks after agents built on Microsoft’s own platforms. The agents your developers run themselves, in their terminals and editors and in their own code, need an identity too.

Entra Agent ID covers

  • Microsoft 365 Copilot agents
  • Azure AI Foundry agents
  • Copilot Studio agents
  • Power Platform agents

AgentValet registers and governs

Acting on 25 platforms today, including Gmail, Slack, GitHub, HubSpot, Xero, Microsoft Outlook and the Google apps. See them all.

Subagents get their own, smaller identity.

In most multi-agent setups the orchestrator holds the access, and every worker it spawns inherits all of it. With AgentValet, the orchestrator mints a child identity for each worker: its own agent id, a lifetime you choose, and only the part of the parent’s access that the worker needs.

The cut is enforced by AgentValet, not requested politely. A child can never hold access its parent has lost, every call it makes is recorded under its own name, and revoking the parent stops every child on its next call.

Framework status, without the logo wall.

The same table as the trust centre. Where we say self-assessed, we mean our own mapping, not a certificate.

Framework status
FrameworkStatus todayNotes
SOC 2Not startedType I is the first target. The controls that exist as code and CI are documented; an auditor, a compliance platform and the people-and-process controls are the remaining work.
Independent penetration testPlanned, not yet bookedWhen a report exists it will be available under NDA, and this row will say so.
ISO/IEC 27001Not certifiedNot currently planned.
Privacy: GDPR and the Australian Privacy PrinciplesDesigned for itWe hold credentials and decision records, not request contents. A data-processing agreement is available on request. Data stays in Australia for every customer; there is no EU region.
ISO/IEC 42001 (AI management)Self-assessedOur own mapping of controls, not a certificate.
NIST AI Risk Management FrameworkSelf-assessedMapped to the Govern and Manage functions. Our own assessment.
OWASP Top 10 for LLM, Agentic and API securitySelf-assessedA written control mapping, sent on request.
OWASP Non-Human Identity Top 10In progressMapping under way.

Everything on the wire is a published specification: signed tokens, SPIFFE IDs, did:web, OAuth 2.1, AuthZEN and TRQP. Each one, in plain words.

What regulated teams ask first.

Public sector, financial services, legal and healthcare teams tend to ask the same five things. Here is what exists today.

AgentValet is a managed service run by us. Your agents’ credentials, grants and audit records are stored and processed in Australia. There is no self-hosted option today. Need data held in another region? We can stand one up for you. Tell us early and we’ll scope it with you before procurement, not after.

Every action attributable to one agent
Signed per-agent requests, a request id on every row on every plan, and the account each call used.
Evidence an auditor will accept
An append-only log, a signed receipt per decision, CSV and JSON export on Team and above, and retention sized to your contract on Enterprise.
Detail for an investigation
IP address, user agent and location on every action, on Enterprise, after a second opt-in.
Sign-off on sensitive actions
Approval rules on any scope, passkey approval on every plan, and delegates on Team and above.
Data residency
Your agents’ credentials, grants and audit records are stored and processed in Australia. Another region can be stood up for you on request.

Governance you pay for per agent is governance you ration.

The agent nobody wanted to pay for is the one that ends up holding a raw API key. So agent count isn’t priced on any plan, Enterprise included. Enterprise is priced on the volume your agents put through AgentValet and how long you keep the record.

  • Register every agent. Put the experiments behind it too. The cheap way and the governed way should be the same way.
  • Agree the number before you sign. We size it against your real volume and retention, and the contract states it. No per-seat maths.
  • Prove it first. A pilot with your real agents comes before any commitment.

What Enterprise adds to Team.

Team is the most complete self-serve plan. Enterprise adds the identity, forensic depth and contract terms a security team asks for before agents touch production. Every plan compared.

Team compared with Enterprise
FeatureTeamEnterprise
Single sign-on with OktaNot includedIncluded
Forensic fields on each actionNot includedIncluded
Audit history1 yearAgreed in your contract
Governed actions a month40,000Agreed in your contract
Approval delegates3No practical limit
Push approvals, anomaly alerts, containment, conditions on rulesIncludedIncluded
Per-person tokens and connectionsIncludedIncluded
Audit export (CSV, JSON, printable PDF)IncludedIncluded
Price$258 USD a monthSized to your volume, agreed before you sign

Okta single sign-on is live today: access follows your identity provider through your verified domain, and people who sign in that way join as members whose roles your admins control.

A pilot you can walk away from.

No procurement, no commitment. If the record and the approvals don’t satisfy your security team, that’s the answer.

Talk to Edwin about a pilot
  1. Scope it together

    Pick the agents and tools that matter, and what your security team needs to see before it would say yes.

  2. Run your real agents

    Against your real platforms, with the approvals and the record switched on from the first call.

  3. Review the evidence

    Your security team reads the audit log and the receipts, and tries to break the rules you set.

  4. Decide

    If it doesn’t satisfy them, walk away. No procurement until it has earned it.

If an agent changed a critical system today, would you know who authorised it?

That question is the starting point. Talk to Edwin about extending your identity programme to the agents already acting on your systems, or put one through the free plan and see the record for yourself.

Edwin Ashdown is the founder. Email [email protected] and he replies himself.