Your identity programme covers people and service accounts. Agents slipped through.
AgentValet gives every AI agent its own identity, only the access you grant it, a person’s approval before anything risky, and a signed record of every call. It covers the agents your developers already run, and none of them holds a key.
The same discipline you apply to people, applied to agents.
Authentication, authorisation and audit already cover your staff and your service accounts. An agent with a pasted API key gets none of the three. AgentValet sits between your agents and the tools they use and puts all three back.
- Its own identity for every agent
- Each agent signs every request with its own key, so every row in the record ties back to one named agent. Each gets a SPIFFE-format ID and, if you opt in, a W3C did:web document any resolver can check.
- Access you grant, scope by scope
- Nothing is allowed until you allow it. Organisation-wide guardrails sit above every agent’s grants, and a refusal always beats an approval rule, which always beats an allow. On Studio and above, grants can limit who an agent may email or message, and ask or block when a send would leave your organisation.
- A person’s yes before anything risky
- A held call waits while someone approves it on their phone, with a passkey, from an email link or in the dashboard. On Team and above, delegates share the load so agents don’t stall waiting on one person.
- Keys the agent never sees
- Credentials are encrypted with a key per organisation, held in hardware on paid plans, and decrypted in memory for a single call. The agent only ever holds its signing key.
- A record nobody can rewrite
- The audit log accepts new rows and nothing else, and every decision carries a signed receipt. Each connected account is labelled with its real identity, such as the GitHub login or Google email, so a row says which account acted.
- Signals when behaviour changes
- Rule-based detectors flag scope creep, a first call to a new platform, bursts of refusals and off-hours activity against a nightly baseline per agent, and can suspend an agent on a breach. The circuit breaker suspends one after repeated failures.
What your security team will see.
Real screens from our demo organisation, not mock-ups.
Rules that sit above every agent
Guardrails run before any agent’s own policy and can’t be overridden by it. Require a person’s sign-off for a kind of action, or refuse it outright, for every agent in the organisation at once.

A log they can filter, export and check
Every call is a row: who, which agent, which tool and action, and the decision, each with a signed receipt. Filter by agent, action or date, and export it for your auditor.

Microsoft governs the agents Microsoft builds. This covers the rest.
Entra Agent ID looks after agents built on Microsoft’s own platforms. The agents your developers run themselves, in their terminals and editors and in their own code, need an identity too.
Entra Agent ID covers
- Microsoft 365 Copilot agents
- Azure AI Foundry agents
- Copilot Studio agents
- Power Platform agents
AgentValet registers and governs
Acting on 25 platforms today, including Gmail, Slack, GitHub, HubSpot, Xero, Microsoft Outlook and the Google apps. See them all.
Subagents get their own, smaller identity.
In most multi-agent setups the orchestrator holds the access, and every worker it spawns inherits all of it. With AgentValet, the orchestrator mints a child identity for each worker: its own agent id, a lifetime you choose, and only the part of the parent’s access that the worker needs.
The cut is enforced by AgentValet, not requested politely. A child can never hold access its parent has lost, every call it makes is recorded under its own name, and revoking the parent stops every child on its next call.
Framework status, without the logo wall.
The same table as the trust centre. Where we say self-assessed, we mean our own mapping, not a certificate.
| Framework | Status today | Notes |
|---|---|---|
| SOC 2 | Not started | Type I is the first target. The controls that exist as code and CI are documented; an auditor, a compliance platform and the people-and-process controls are the remaining work. |
| Independent penetration test | Planned, not yet booked | When a report exists it will be available under NDA, and this row will say so. |
| ISO/IEC 27001 | Not certified | Not currently planned. |
| Privacy: GDPR and the Australian Privacy Principles | Designed for it | We hold credentials and decision records, not request contents. A data-processing agreement is available on request. Data stays in Australia for every customer; there is no EU region. |
| ISO/IEC 42001 (AI management) | Self-assessed | Our own mapping of controls, not a certificate. |
| NIST AI Risk Management Framework | Self-assessed | Mapped to the Govern and Manage functions. Our own assessment. |
| OWASP Top 10 for LLM, Agentic and API security | Self-assessed | A written control mapping, sent on request. |
| OWASP Non-Human Identity Top 10 | In progress | Mapping under way. |
Everything on the wire is a published specification: signed tokens, SPIFFE IDs, did:web, OAuth 2.1, AuthZEN and TRQP. Each one, in plain words.
What regulated teams ask first.
Public sector, financial services, legal and healthcare teams tend to ask the same five things. Here is what exists today.
AgentValet is a managed service run by us. Your agents’ credentials, grants and audit records are stored and processed in Australia. There is no self-hosted option today. Need data held in another region? We can stand one up for you. Tell us early and we’ll scope it with you before procurement, not after.
- Every action attributable to one agent
- Signed per-agent requests, a request id on every row on every plan, and the account each call used.
- Evidence an auditor will accept
- An append-only log, a signed receipt per decision, CSV and JSON export on Team and above, and retention sized to your contract on Enterprise.
- Detail for an investigation
- IP address, user agent and location on every action, on Enterprise, after a second opt-in.
- Sign-off on sensitive actions
- Approval rules on any scope, passkey approval on every plan, and delegates on Team and above.
- Data residency
- Your agents’ credentials, grants and audit records are stored and processed in Australia. Another region can be stood up for you on request.
Governance you pay for per agent is governance you ration.
The agent nobody wanted to pay for is the one that ends up holding a raw API key. So agent count isn’t priced on any plan, Enterprise included. Enterprise is priced on the volume your agents put through AgentValet and how long you keep the record.
- Register every agent. Put the experiments behind it too. The cheap way and the governed way should be the same way.
- Agree the number before you sign. We size it against your real volume and retention, and the contract states it. No per-seat maths.
- Prove it first. A pilot with your real agents comes before any commitment.
What Enterprise adds to Team.
Team is the most complete self-serve plan. Enterprise adds the identity, forensic depth and contract terms a security team asks for before agents touch production. Every plan compared.
| Feature | Team | Enterprise |
|---|---|---|
| Single sign-on with Okta | Not included | Included |
| Forensic fields on each action | Not included | Included |
| Audit history | 1 year | Agreed in your contract |
| Governed actions a month | 40,000 | Agreed in your contract |
| Approval delegates | 3 | No practical limit |
| Push approvals, anomaly alerts, containment, conditions on rules | Included | Included |
| Per-person tokens and connections | Included | Included |
| Audit export (CSV, JSON, printable PDF) | Included | Included |
| Price | $258 USD a month | Sized to your volume, agreed before you sign |
Okta single sign-on is live today: access follows your identity provider through your verified domain, and people who sign in that way join as members whose roles your admins control.
A pilot you can walk away from.
No procurement, no commitment. If the record and the approvals don’t satisfy your security team, that’s the answer.
Talk to Edwin about a pilotScope it together
Pick the agents and tools that matter, and what your security team needs to see before it would say yes.
Run your real agents
Against your real platforms, with the approvals and the record switched on from the first call.
Review the evidence
Your security team reads the audit log and the receipts, and tries to break the rules you set.
Decide
If it doesn’t satisfy them, walk away. No procurement until it has earned it.
If an agent changed a critical system today, would you know who authorised it?
That question is the starting point. Talk to Edwin about extending your identity programme to the agents already acting on your systems, or put one through the free plan and see the record for yourself.
Edwin Ashdown is the founder. Email [email protected] and he replies himself.