Platform trajectory

Platform trajectory.Labelled honestly.

Ten milestones, M0 to M9: what is available today, what is a future capability, and what is not built by design. Nothing here is marketed as shipped unless it is — or as coming when it is not.

10 available

Legend

Five labels. Five different promises.

Every capability on this site carries one of these labels. This is what each one commits us to.

  • Available

    Built, tested and running in the platform today.

    Safe to evaluate and plan against now.

  • In development

    Actively being engineered; scope and timing can still change.

    Ask us for the current state before relying on it.

  • Strategic direction

    A committed design direction with architecture and prototypes, but no ship date.

    Treat as intent, not as a feature.

  • Future capability

    Long-term vision that shapes architecture decisions today.

    Not on a dated roadmap; never a purchase criterion.

  • Not built

    Deliberately not built. The reason is stated wherever the capability comes up.

    Not on the roadmap at all; do not plan around it.

Phases

From governed identities to Agentic Access Management

Four commercial phases, each built on the graph the previous one populated.

  1. Phase 1Available

    Discover · Classify · Own identities

  2. Phase 2Available

    Secure credentials · Explain risk · Record exposure

  3. Phase 3Available

    Govern agents · Govern tools · Declare entitlements

  4. Phase 4Available

    Runtime action authorization · Agentic Access Management

Every phase is built and tested, not yet proven on a customer estate. What is not built is named as such — and never marketed as shipped.See the full platform trajectory

Milestones

M0 to M9

The full sequence, grouped by phase, with the capabilities each milestone contains and its current label.

Phase 1Available

Discover · Classify · Own identities

  1. M0Available

    Engineering Foundation

    Multi-tenant runtime with row-level tenant isolation, the evidence model, and build, test and security gates.

    • Tenant isolation
    • Evidence model
    • Design system
    • Build, test and security gates
  2. M1Available

    Identity & Access Foundation

    Email and password sign-in with sessions, organizations, users, teams, invitations, RBAC and a hash-chained audit trail.

    • Authentication & sessions
    • Organizations, users, teams
    • RBAC & invitations
    • Tamper-evident audit trail
  3. M2Available

    Identity Governance

    Five connectors — AWS IAM, GitHub, Kubernetes, HashiCorp Vault and Model Context Protocol — with identity discovery, normalisation, ownership, lifecycle and the identity graph.

    • Connector contract & sync lifecycle
    • Identity discovery
    • NHI classification
    • Ownership & lifecycle
    • Identity graph, search, filtering
    • Relationships attributed to a connector
Phase 2Available

Secure credentials · Explain risk · Record exposure

  1. M3Available

    Credential Security

    A credential inventory mapped to identities, with age, rotation and expiry findings. Credential metadata only: secret values are never read.

    • Credential inventory
    • Credential ↔ identity mapping
    • Age & rotation-overdue findings
    • Expiry findings
  2. M4Available

    Understand Risk

    Posture policy evaluation over collected evidence, findings that carry that evidence, and explainable risk by identity. Missing evidence is reported as unknown.

    • Posture policy evaluation
    • Findings with evidence
    • Risk by identity, derived from findings
    • Unknown when evidence is missing
  3. M5Available

    Detection, Activity & Exposure

    What was actually done and what leaked. Activity and credential exposures arrive through an ingestion API and feed findings; no connector collects activity.

    • Activity ingestion
    • Credential exposure ingestion
    • Exposed & expired-credential-used findings
    • Privileged activity findings
Phase 3Available

Govern agents · Govern tools · Declare entitlements

  1. M6Available

    Agent Authorization

    AI agents as identities, MCP servers and tools, agent credentials and permissions, with autonomy and tool-effect controls. The MCP connector discovers tools; no connector discovers an agent, and no screen registers one.

    • Agents on the identity model
    • MCP server & tool discovery
    • Tool effect & agent autonomy declarations
    • Agent posture policies
  2. M7Available

    Govern AI Agents

    Agent ownership and policy, policy exceptions that are scoped, approved by a second person and expire, the permission inventory, and effective access as an upper bound.

    • Unowned & unprofiled agent findings
    • Policy exceptions with second-person approval
    • Permission inventory
    • Effective access, transitive reach, blast radius
Phase 4Available

Runtime action authorization · Agentic Access Management

  1. M8Available

    Secure Every Action

    The runtime gate is built: an agent runtime presents its credential, thirteen deny-by-default rules decide, and the decision is recorded. Purpose is recorded for the investigator; no rule decides on it.

    • Runtime authorization gate (ALLOW · CHALLENGE · DENY)
    • Thirteen runtime rules, strictest verdict wins
    • Deny by default — an empty rule set denies
    • Declared tool entitlements
    • Immutable decision records
    • Outcome reporting after the action
  2. M9Available

    Agentic Access Management

    Just-in-time access grants approved by someone other than the requester, agent runtime credentials minted by a person, certification, delegation and drift, identity resolution and risk history.

    • Time-bounded access grants (up to 7 days)
    • Agent runtime credentials (1–90 days, shown once)
    • Certification, delegation & drift (API)
    • Identity resolution without merge (API)
    • Risk history

Principle

Why we publish this

A trajectory is only useful if the labels on it are trustworthy. These are the rules that keep them so.

We publish the trajectory so you can plan against it — and so nobody mistakes a strategic direction for a shipped feature.

  • Every capability is labelled. Available, future capability or not built — on every page that mentions it.

  • Direction is never sold as shipped. Credential brokering and one authority model across humans, machines and tools are direction until they are not.

  • Sample data says so. Every screenshot, graph and finding on this site is marked illustrative. None of it is customer telemetry.

  • Evidence before claims. No invented customers, quotes, logos, benchmarks or certifications. When evidence is missing, the product shows unknown — and so does this site.

Evaluate what exists. Plan for what is coming.

A demo shows the available platform on your own identities and walks through the direction without dressing it up.

Evaluate what exists today.

See how TRUSTIVAN connects identity, credential, access, agent and action context into one control plane.