⚡ New from the Qyli Cyber team

Your employees are hiring AI agents.
Nobody's doing the background checks.

Anyone in your company can spin up an agent in minutes and hand it the keys to your most sensitive data. Mandate ID gives every agent a mandate — an identity, least-privilege access, and a live behavioural conscience — without blocking the work.

Runs alongside your existing IAM. Okta, Entra and CyberArk stay exactly where they are.
Our thesis

AI isn't creating a security problem.
It's exposing a decision problem.

Every autonomous action is a decision. Most software records what happened. Some software prevents what shouldn't happen. Mandate ID is built for the question that comes next: now that reality has happened, what should the organisation do?

Why now

Your IAM was built for humans. Your newest workforce isn't human.

Every identity tool you own assumes a person: one login, one manager, one job description. Agents break every one of those assumptions on day one — and every action they take is a decision nobody is accountable for.

🧑→🤖

Hired in minutes, not months

A human joins through HR, IT and a laptop build. An agent joins because someone in marketing had a spare lunch break. Onboarding process — there isn't one.

🔑

Handed real credentials

Agents run on borrowed API keys and OAuth grants scoped for their owner — which means an intern's side-project agent can read whatever the intern can. Or worse, whatever the shared service account can.

🚫

Blocking isn't an option

Agents are the biggest productivity gain your business has seen in years. Ban them and they go underground; shadow AI is still AI. The answer is governance, not prohibition.

The platform

Solve agent security the only way it can be solved: identity first.

Three things, in order. Give every agent a mandate. Decide what it may touch. Watch that what it does matches what it said it would do.

1

Give every agent a mandate

Each agent gets a first-class identity the moment it's provisioned: a named human owner, a department, a rotating credential, and — the part that matters — a declared purpose in plain English. That's its mandate.

  • Self-serve provisioning; under 60 seconds per agent
  • Auto-rotating scoped credentials — no shared API keys
  • Works with Claude, Copilot Studio, LangChain, OpenAI & custom runtimes
🪪 Identity — Invoice Reconciler
AGT-2041 · Copilot Studio
Human ownerDana Wells (Finance)
CredentialScoped key · rotates 24h
Declared mandateReconcile supplier invoices against POs
🛡️ Access — SharePoint Finance
Restricted tier · deny by default
Invoice Reconcilerread-only
Contract Clause Scannerread-only
Expense Audit Agentunder review
All other agentsdenied
2

Manage what it's allowed to touch

Least privilege, enforced. Scopes attach to identities, everything else is deny-by-default and logged. When an agent needs more, the request lands in an approval queue with our recommendation attached — a human decides in one click.

  • Sensitivity tiers per resource: Internal, Confidential, Restricted
  • Human approval gates on write actions where it matters
  • Time-boxed exceptions with auto-expiry — no forever-grants
3

See that it does what it said

This is the piece no traditional IAM has: every action is scored against the agent's declared mandate, live, and stored as a decision record — what acted, on what, why it was allowed or stopped, and what happened next. When behaviour drifts, you know before it's an incident. Over time, that record becomes the thing your IAM never had: the evidence base for what to do next.

  • Per-agent alignment score with a 14-day drift timeline
  • Velocity guardrails auto-suspend runaway agents
  • The click becomes the lesson: every block explains itself to the owner
📉 Drift — Expense Audit Agent
Alignment 94 → 62 over 14 days
◐ 3 alerts raised · owner notified · HR query blocked at policy layer
How it works

From shadow AI to governed fleet in an afternoon.

No agents ripped out. No workflows broken. No demos to book.

Step 1

Discover

Connect your SaaS estate and we surface every agent already operating in it — including the ones nobody admits to owning. Each gets claimed by a human owner or switched off.

~1 hour
Step 2

Provision

Owners re-register their agents through the self-serve flow: mandate, scopes, credential. Old shared keys are retired as each identity goes live.

60 seconds per agent
Step 3

Govern

The alignment engine takes over: live scoring, drift alerts, approval queues. Your security team reviews exceptions, not spreadsheets.

Continuous
Built for security teams

Everything a CISO asks for. Nothing they have to babysit.

📋

Approval workflow queue

Activations, scope requests and policy exceptions queue for a named approver — with the engine's recommendation attached to every request.

📉

Drift timelines

A 14-day alignment history per agent. See the slide before it becomes the incident.

⏱️

Velocity guardrails

22 refunds in 4 minutes against a baseline of 3 an hour? Auto-suspended, funds held, owner paged.

🔄

Credential hygiene

Auto-rotating scoped tokens, mTLS and workload identity. Dormant credentials get flagged, not forgotten.

🧾

Audit-ready by default

Every action, verdict and approval is logged against an identity in a tamper-evident chain. Your next audit is an export, not an archaeology dig.

🔌

Sits beside your IAM

We govern the agent layer; Okta, Entra and CyberArk keep governing the humans. No rip-and-replace, no migration project.

The Qyli family

You've trained your people. Now govern their agents.

Qyli Cyber teaches your team to spot the phish. Mandate ID makes sure the agents they build don't become the next attack surface. One vendor, both halves of the human-and-machine risk picture.

Explore Qyli Cyber training →
🎓

Qyli Cyber — for your people

Escape-room-style security scenarios your team will actually finish. Deployed in 60 seconds.

🤖

Mandate ID — for their agents

Identity, least-privilege access and behavioural alignment for every AI agent in the business.

📊

One risk picture

Human click rates and agent alignment scores, side by side. Board reporting that finally covers both workforces.

Early access

Join the pilot programme.

The platform is built and running. We're taking a small number of founding partners through it before general launch — free, in exchange for honest feedback.

Limited places

Pilot partner

For teams who want to govern their agents now
Free during the pilot
  • The full platform — identity, policies, alignment engine, audit chain
  • Guided walkthrough & hands-on onboarding
  • Direct line to the founder — your feedback shapes the product
  • Launch pricing locked in when we go live
Request a walkthrough

At launch

Where pricing is headed — no surprises
~£12 /agent/month
  • Self-serve, per governed agent, billed monthly
  • Free tier for small teams dipping a toe in
  • Enterprise tier for SSO/SCIM, residency & retention
  • No demo call with someone called Brad — unless you want one
Get launch updates
Launch pricing is indicative and will be confirmed with pilot partners first. Every plan includes every agent runtime we support.
FAQ

Fair questions, straight answers.

Does this replace Okta / Entra / CyberArk?

No, and it's not trying to. Those platforms govern human identities and privileged accounts, and they're good at it. Mandate ID governs the agent layer — a workforce your IAM was never designed to see. They run side by side.

How does the alignment score actually work?

Every agent declares a mandate in plain English at provisioning. The engine classifies each action the agent takes — resource, operation, volume, timing — against that mandate, weighted by resource sensitivity. Consistent behaviour keeps the score high; drift pulls it down and raises an alert long before a hard policy breach.

What happens when an agent goes rogue?

In order: the out-of-scope action is blocked at the policy layer, the alignment score drops, an alert lands with your security team, and if velocity guardrails trip, the agent is auto-suspended and its credential frozen. The owner gets told why, in plain English — the click becomes the lesson.

Which agent platforms do you support?

Claude, Microsoft Copilot Studio, OpenAI Assistants, LangChain, Zapier Agents and custom in-house runtimes via SDK. If your agents can make an API call, we can give them a mandate.

We already use Qyli Cyber for awareness training. Is this included?

Mandate ID is a separate product with its own plans, but Qyli Cyber customers get combined reporting and a bundle discount — talk to us and we'll sort it.

Get started

Agent security you can actually measure.

A working platform, a live demo, and a founder who'll walk you through it personally.

Request a pilot walkthrough