Non-Human Identity for AI Agents

Non-human identity,
built for AI agents

Extend your identity programme to every AI agent in your organisation. SPIFFE-based identities, scoped credentials, AuthZEN policies, and full audit, across every agent platform your teams use.

Aligned with
ISO 42001
OWASP NHI Top 10
OWASP LLM Top 10
NIST AI RMF
AuthZEN 1.0
EU AI Act
SOC 2 in progress. Not yet certified for SOC 2 Type II or ISO 27001.
Platform Capabilities

Everything an enterprise needs
to govern AI agent access

From identity issuance to credential rotation, policy enforcement to real-time anomaly detection.

๐Ÿ”

Agent Identity (SPIFFE)

Every agent receives a SPIFFE-based identity with cryptographic attestation. Verifiable, non-repudiable, and compatible with your existing service mesh.

๐Ÿ”‘

Credential Vaulting (HSM)

Per-org KEK in a Key Vault Premium (HSM). One DEK per credential, AES-256-GCM with org-bound AAD. Plaintext is unwrapped only in proxy memory at request time and zeroed after use.

๐Ÿ“‹

Policy Engine (AuthZEN)

AuthZEN 1.0-compatible PDP endpoint. Scope-based access decisions today, with a policy language on the roadmap. Every decision is logged to the audit trail.

๐Ÿ‘ค

Human-in-the-Loop Approval

Server-Sent Events push approval flow, CIBA-inspired. Owner-approved actions via the dashboard or an email magic link. Sensitive scopes always queue for approval.

๐Ÿ“Š

Audit & Compliance

Append-only audit log with a dedicated INSERT-only Postgres role. JSON export. Control mapping published today for OWASP LLM, Agentic and API Top 10, plus NIST AI RMF.

๐Ÿ›ก๏ธ

Anomaly Detection

Rule-based detectors today: scope creep, first-time platform access, denial spikes, off-hours activity. Nightly per-agent behavioural baselines. Auto-suspend on threshold breach.

๐Ÿข

Multi-Tenant Administration

Org-level isolation via Postgres RLS and per-org KEKs. Multi-user RBAC and team workspaces are on the Enterprise roadmap.

๐Ÿ”„

Lifecycle Management

Agent statuses of active, suspended, and revoked. Per-permission approval flags. Credential expiry enforcement and rotation. From provisioning to decommissioning.

๐Ÿ”—

SSO & Directory Sync

Microsoft Entra ID and generic OIDC/SAML SSO available on the Enterprise tier, enforced per organisation. Each user can act under their own OAuth identity per platform.

The NHI Thesis

Built on the non-human identity stack
enterprises already trust

Identity is the foundation of AI governance. AgentValet extends the IAM discipline you already apply to users and service accounts, authentication, authorisation, audit, to the AI agents acting on your systems.

Standards-native

SPIFFE identities, RFC 7591 dynamic client registration, OASIS AuthZEN 1.0 policy decisions, RS256 JWTs per agent. No proprietary identity primitives.

Framework-aligned

Built against the OWASP Non-Human Identity Top 10 and ISO 42001 controls. Tracking the IETF AIMS draft as it develops. Published mapping for OWASP LLM, Agentic and API Top 10.

Identity carries intent

Every agent identity carries purpose and data-handling claims. What the agent is permitted to do, with which classes of data, under what human-approval conditions. Authentication without constrained intent is just a faster audit log.

Built on open standards,
not proprietary identity primitives

Every protocol on the wire is an IETF, OASIS, or CNCF standard. No lock-in to AgentValet-only formats.

Agent Layer

AI Agents

14 platforms supported

npx @agentvalet/register RFC 7591 metadata
โ†’
Governance Layer

AgentValet Core

Identity + Policy + Vault

SPIFFE IDs AuthZEN 1.0 RS256 JWTs
โ†’
Platform Layer

SaaS Platforms

14 supported today

Gmail, Slack, GitHub Google & M365 Airtable, HubSpot
Microsoft Ecosystem

The multi-platform companion
to Microsoft Entra Agent ID

Entra Agent ID governs the agents Microsoft builds. AgentValet governs the agents your developers build and run themselves: Claude Code, Cursor, Codex, Factory Droid, OpenClaw, and custom scripts. On the Enterprise tier, agent ownership can be surfaced through your Entra tenant via OIDC.

Entra Agent ID covers
  • Microsoft 365 Copilot agents
  • Azure AI Foundry agents
  • Microsoft Copilot Studio agents
  • Power Platform AI agents
AgentValet registers and governs
  • Claude Code, Cursor IDE, Cursor CLI
  • Codex CLI and Desktop, Factory Droid
  • OpenClaw and custom Node.js/Python agents
  • Acting on 14 SaaS platforms today: Gmail, Slack, GitHub, Airtable, HubSpot, Google Workspace, Microsoft 365, Supabase, Clerk

One identity plane for the agents you build. Every action audited. Entra OIDC link arriving on the Enterprise tier.

Governance Alignment

Mapped to the frameworks
your compliance team actually reads

A published OWASP control crosswalk today. Additional frameworks added quarterly as customer review packs demand them. The list below is what is mapped, not what we aspire to map.

OWASP LLM Top 10
Mapping published
OWASP Agentic Top 10
Mapping published
OWASP API Top 10
Mapping published
OWASP NHI Top 10
Mapping in progress
NIST AI RMF
Aligned to Govern + Manage
ISO 42001
Aligned, not yet certified
Administration

Centralised agent management
for your security team

Full visibility into every agent's identity, credentials, permissions, and activity โ€” across all teams and environments.

enterprise.agentvalet.ai/dashboard
โ—‰ Agents
โ—Ž Credentials
โ—ˆ Policies
โ—‡ Audit Log
โ—† Teams
โ˜ฐ Anomalies
โš™ Settings

Registered Agents (47)

Agent SPIFFE ID Owner Status Last Active
invoice-processor spiffe://corp/agent/inv-proc finance-ops@corp Active 2 min ago
code-review-bot spiffe://corp/agent/cr-bot platform@corp Active 14 min ago
hr-onboarding-agent spiffe://corp/agent/hr-onb people-ops@corp Suspended 3 hrs ago
data-pipeline-v2 spiffe://corp/agent/dp-v2 data-platform@corp Revoked Dec 14, 2025
Deployment

Managed in the cloud,
in the region your data needs

AgentValet runs as a managed cloud service. The production tenant is in Australia East today. For Enterprise customers, we can stand up a dedicated managed tenant in any major cloud region your data residency requirements demand. No customer infrastructure to install or maintain.

Fully managed cloud service

Run by AgentValet. Per-org KEK in a Key Vault Premium (HSM). PostgreSQL RLS tenancy isolation. Append-only audit log. SLA available on the Enterprise contract. Choose your region: 60+ cloud regions worldwide.

Managed container runtime Per-org HSM KEK RLS tenancy isolation Region of your choice
Regulated Environments

Built for industries where
AI accountability is not optional

AgentValet's identity-first architecture is designed for environments where every agent action must be attributable, auditable, and aligned to a regulatory framework.

Public Sector
Hosted in your chosen cloud region for data residency. Aligned to Australia's AI Ethics Principles and the Voluntary AI Safety Standard, with equivalent regional frameworks on request. Every agent action attributable to a signed RS256 JWT.
Financial Services
Append-only audit log with INSERT-only Postgres role. Per-org HSM-backed KEKs. Owner-approved workflows for sensitive scopes. NIST AI RMF crosswalk on request.
Legal & Professional Services
Owner-approval flow for any sensitive action. Immutable, append-only audit trail of who ran what, when, with which scope. Forensic columns opt-in per organisation.
Healthcare
Per-org tenancy isolation in HSM. Scoped agent permissions with explicit approval on every sensitive call. Mapped to ISO 42001 controls.
Trusted Foundations

Aligned with the frameworks defining
AI agent identity

AgentValet is built to the open standards and governance frameworks shaping the next generation of identity, security, and AI accountability.

IETF AIMS
AI Agent Identity & Management Specification
OWASP NHI Top 10
Non-Human Identity Risk Framework
OASIS AuthZEN 1.0
Authorisation API Standard
SPIFFE / SPIRE
Cloud-Native Workload Identity
ISO/IEC 42001
AI Management System Standard
NIST AI RMF
AI Risk Management Framework

AgentValet tracks the developing IETF AIMS draft and maps its control surface to the OWASP Non-Human Identity Top 10 as that framework evolves.

Compare

Developer vs Enterprise

Same core platform, different operational posture.

Feature AgentValet for teams Enterprise
Agent registration CLI self-serve CLI + Admin console + API
Identity SPIFFE ID (shared trust domain) SPIFFE ID (dedicated trust domain on roadmap)
Credential storage Per-org HSM KEK + DEK envelope Per-org HSM KEK + DEK envelope
SSO Built-in login Entra ID / OIDC / SAML, enforced per org
Multi-user admin Single owner RBAC with team workspaces (roadmap)
Audit logs 7 to 365 days by plan 7 years + JSON export (SIEM forwarder on roadmap)
Anomaly detection โ€” (Team tier and above) 4 rule-based detectors + nightly baselines
Governance mapping OWASP LLM / Agentic / API crosswalk Same, plus NIST AI RMF + ISO 42001 alignment statement
Deployment Managed cloud (shared region) Managed cloud (region of your choice)
Support Community + docs Direct access + Enterprise SLA on contract
What Enterprise adds

The controls your security team
asks for before agents touch production

Everything in Team, plus the identity, attribution, and forensic depth a regulated org needs โ€” and a pilot that lets you prove it before you commit.

๐Ÿ”‘

SAML / SSO, per org

Log in through your own identity provider โ€” Entra ID, Okta, or any OIDC/SAML source. SSO is enforced per organisation, so access follows your directory's joiners and leavers.

๐Ÿ‘ค

Per-user OAuth identity

Each person acts under their own OAuth identity on each platform. Actions attribute to the real human who authorised them โ€” not a shared service bot.

๐Ÿ”Ž

Forensic audit

IP, geo, device, and request ID on every action โ€” dual-gated by entitlement and per-org consent. A real investigation trail, not a guess.

โœ…

Unlimited approval delegation

Up to 999 approval delegates, so sign-off authority scales across a real org and agents never stall waiting on one person.

โˆž

No metered ceilings

Effectively unlimited agents, calls, and audit retention. Governance that doesn't meter your growth.

๐Ÿค

Scoped pilot, no commitment

Run a pilot with your real agents and platforms. If the audit trail and approval flow don't satisfy your security team, walk away โ€” no procurement, no commitment.

Book a call Request the security review pack

If an AI agent made a change to one of your
critical systems today, would you know who authorised it?

That question is the starting point. AgentValet is the answer. Talk to our team about extending your identity programme to the AI agents already acting on your systems.