Anyone in your company can spin up an agent in minutes and hand it the keys to your most sensitive data. Mandate ID gives every agent a mandate — an identity, least-privilege access, and a live behavioural conscience — without blocking the work.
Every autonomous action is a decision. Most software records what happened. Some software prevents what shouldn't happen. Mandate ID is built for the question that comes next: now that reality has happened, what should the organisation do?
Every identity tool you own assumes a person: one login, one manager, one job description. Agents break every one of those assumptions on day one — and every action they take is a decision nobody is accountable for.
A human joins through HR, IT and a laptop build. An agent joins because someone in marketing had a spare lunch break. Onboarding process — there isn't one.
Agents run on borrowed API keys and OAuth grants scoped for their owner — which means an intern's side-project agent can read whatever the intern can. Or worse, whatever the shared service account can.
Agents are the biggest productivity gain your business has seen in years. Ban them and they go underground; shadow AI is still AI. The answer is governance, not prohibition.
Three things, in order. Give every agent a mandate. Decide what it may touch. Watch that what it does matches what it said it would do.
Each agent gets a first-class identity the moment it's provisioned: a named human owner, a department, a rotating credential, and — the part that matters — a declared purpose in plain English. That's its mandate.
Least privilege, enforced. Scopes attach to identities, everything else is deny-by-default and logged. When an agent needs more, the request lands in an approval queue with our recommendation attached — a human decides in one click.
This is the piece no traditional IAM has: every action is scored against the agent's declared mandate, live, and stored as a decision record — what acted, on what, why it was allowed or stopped, and what happened next. When behaviour drifts, you know before it's an incident. Over time, that record becomes the thing your IAM never had: the evidence base for what to do next.
No agents ripped out. No workflows broken. No demos to book.
Connect your SaaS estate and we surface every agent already operating in it — including the ones nobody admits to owning. Each gets claimed by a human owner or switched off.
~1 hourOwners re-register their agents through the self-serve flow: mandate, scopes, credential. Old shared keys are retired as each identity goes live.
60 seconds per agentThe alignment engine takes over: live scoring, drift alerts, approval queues. Your security team reviews exceptions, not spreadsheets.
ContinuousActivations, scope requests and policy exceptions queue for a named approver — with the engine's recommendation attached to every request.
A 14-day alignment history per agent. See the slide before it becomes the incident.
22 refunds in 4 minutes against a baseline of 3 an hour? Auto-suspended, funds held, owner paged.
Auto-rotating scoped tokens, mTLS and workload identity. Dormant credentials get flagged, not forgotten.
Every action, verdict and approval is logged against an identity in a tamper-evident chain. Your next audit is an export, not an archaeology dig.
We govern the agent layer; Okta, Entra and CyberArk keep governing the humans. No rip-and-replace, no migration project.
Qyli Cyber teaches your team to spot the phish. Mandate ID makes sure the agents they build don't become the next attack surface. One vendor, both halves of the human-and-machine risk picture.
Explore Qyli Cyber training →Escape-room-style security scenarios your team will actually finish. Deployed in 60 seconds.
Identity, least-privilege access and behavioural alignment for every AI agent in the business.
Human click rates and agent alignment scores, side by side. Board reporting that finally covers both workforces.
The platform is built and running. We're taking a small number of founding partners through it before general launch — free, in exchange for honest feedback.
No, and it's not trying to. Those platforms govern human identities and privileged accounts, and they're good at it. Mandate ID governs the agent layer — a workforce your IAM was never designed to see. They run side by side.
Every agent declares a mandate in plain English at provisioning. The engine classifies each action the agent takes — resource, operation, volume, timing — against that mandate, weighted by resource sensitivity. Consistent behaviour keeps the score high; drift pulls it down and raises an alert long before a hard policy breach.
In order: the out-of-scope action is blocked at the policy layer, the alignment score drops, an alert lands with your security team, and if velocity guardrails trip, the agent is auto-suspended and its credential frozen. The owner gets told why, in plain English — the click becomes the lesson.
Claude, Microsoft Copilot Studio, OpenAI Assistants, LangChain, Zapier Agents and custom in-house runtimes via SDK. If your agents can make an API call, we can give them a mandate.
Mandate ID is a separate product with its own plans, but Qyli Cyber customers get combined reporting and a bundle discount — talk to us and we'll sort it.
A working platform, a live demo, and a founder who'll walk you through it personally.
Request a pilot walkthrough