Agentic Access Management
VisionEvery identity.Every action.One authority model.
Agentic Access Management is where the platform is heading: one control plane that decides what humans, machines, agents and tools may do to which resources — continuously, with evidence. Its agent half is built today: time-bounded access grants, runtime credentials and a gate for agent actions. One model across humans, machines and tools is a future capability.
Control plane
Human · Machine · Agent · Tool · Resource · Action
Six kinds of entity, one question asked of every request, three possible answers — and evidence attached to each.
- Human
- owner
- approver
- operator
- Machine
- service account
- workload
- key, cert
- Agent
- copilot
- orchestrator
- coding agent
- Tool
- MCP server
- API
- function
- Resource
- bucket, table
- repository
- tenant
- Action
- read, write
- deploy, rotate
- delete, pay
- principal
- credential
- tool entitlement
- effect
- resource impact
- autonomy
- standing grant
- source address
- hour
- ALLOW
- CHALLENGE
- DENY
Problem
Authority is governed by who holds it, not by what it can do
Humans get IAM, machines get secret stores, agents get guardrails, tools get allow-lists. Four systems, four vocabularies, no shared answer.
Humans
Directories and SSO govern people who log in, then stop at the service accounts those people create
Machines
Secret managers hold the credential but do not know the identity, the owner or the reach behind it
Agents
Guardrails shape what a model says; they cannot decide whether what it asks for should happen
Tools
Allow-lists name the tools an agent may call and say nothing about the resource or action behind each call
Model
One question. Asked of everyone.
The same evaluation for a person, a service account, an agent and a tool — and the same honesty about which parts exist today.
Different actors. One authority model.Future capability
A human, a service account, an agent and a tool are different entities with one thing in common: authority to act on a resource. Trustivan's direction is to model that authority once — identity, ownership, credential, effective access, context, risk, approval — and to evaluate every request against it. A stated purpose stays recorded for the investigator; no rule decides on it.
Should this identity be allowed to perform this action against this resource, right now, with this authority?
- Humanon-call engineer
restartprod-api-gatewayincident INC-311 open · within runbookALLOW - Machineci-deployer
deployprod-clustersigned artifact · change window openALLOW - Agentcleanup-bot
deletes3://prod-backupstool not entitled to this agent · entitlements declaredDENY - Toolmcp://tickets
writeJira project SEChigh-impact resource · no grant standing behind itCHALLENGE
What is true today. What is direction.
The control plane is assembled in order: govern identities, secure credentials and access, govern agents and tools, then authorize actions at runtime. Each phase ships on the graph the previous one built.
- Available now: discovery, ownership, the identity graph, credential findings, effective access, the runtime gate and access grants.
- Not built, by design: agent discovery — no connector discovers an agent, and no screen registers one.
- Future capability: credential brokering, remediation that executes at a provider, and the unified model.
- Identity discovery from AWS IAM, GitHub, Kubernetes, HashiCorp Vault and MCP
- Ownership, lifecycle, the identity graph, search and filtering
- Credential ↔ identity mapping; age, rotation, expiry and exposure findings
- Effective access (an upper bound), access paths and blast radius
- Agent profiles, autonomy, MCP tools and declared tool entitlements
- Runtime action authorization: 13 deny-by-default rules returning ALLOW · CHALLENGE · DENY
- Access grants: approved by someone other than the requester, bounded to seven days
- Quarantining an identity inside the platform, denied every action at the gate
- Credential brokering per action
- Remediation that executes at a provider
- Overprivilege from observed permission use
- The unified authority model across all six entity types
- Agent discovery — no connector discovers an agent, and no screen registers one
- Agent-to-agent lineage and chain evaluation
- Behavioural anomaly detection in posture
Labels follow the published platform trajectory. Nothing in the right column is sold as shipped.
Trajectory
How four phases lead here
Agentic Access Management is the destination of a sequence, not a separate product. Each phase is labelled with what it is.
- Phase 1Available
Discover · Classify · Own identities
- Phase 2Available
Secure credentials · Explain risk · Record exposure
- Phase 3Available
Govern agents · Govern tools · Declare entitlements
- Phase 4Available
Runtime action authorization · Agentic Access Management
Every phase is built and tested, not yet proven on a customer estate. What is not built is named as such — and never marketed as shipped.See the full platform trajectory
Principles
What will not change on the way
The constraints we hold ourselves to now are the ones the control plane will be judged by later.
Evidence before claims
Every finding carries its source, the identity, the credential, the owner, the permission, the resource and the access path. When evidence is missing we show unknown — never a fabricated score.
Identity ≠ Credential
A secret is not an identity. Trustivan models who owns an identity, what credentials it holds, what it authenticates to, what it can reach and what it actually does.
The model requests. Authorization decides.
An LLM is never the security boundary. Actions are authorized outside the model from the credential, tool entitlement, effect, resource impact, autonomy and grants. Purpose is recorded; no rule decides on it.
Risk must be explainable
Identity criticality × privilege × exposure × reachability × credential and lifecycle risk — a conceptual framework a human can audit, not a black box.
One authority model for every actor is a future capability
Its agent half is available: access grants bounded at seven days (M9), runtime credentials a person issues, and the runtime gate (M8). Applying the same verdicts to humans, machines and tools is not built; use the trajectory, not this page, to plan a purchase.
See the full platform trajectoryPlan against the trajectory, not the pitch.
Talk to the engineers building it: what is available on your identities today, and how the direction affects your agent programme.