The AI OS your security team approves.
Agent identity. RBAC. SSO + SCIM. Approval policies. Reversible writes. An immutable audit trail on every action. The controls your procurement team asks about first — built into the platform, not sold as an add-on.
An AI employee should never have more access than the human it acts for.
Who's acting. Who authorized it.
Agent identity
Every AI employee has its own account, its own email, its own audit trail. Actions attributable back to Human → AI Employee → Skill → Tool → Action.
SSO / SAML
OIDC and SAML 2.0 out of the box. Okta, Entra, Google Workspace, OneLogin, and any SAML-compliant IdP. Group membership drives workspace permissions.
SCIM 2.0 provisioning
Automated user + group sync from your IdP. Deprovisioning propagates within the SLA — no orphaned agent access.
RBAC per surface
Role-based access on every surface: dashboards, portal, MCP, A2A, admin API. Never more access than the human it acts for.
What runs. What waits.
Approval policies
Three risk tiers. Reads auto-run. Reversible writes route to a manager. Destructive writes add step-up MFA on the reviewer before execution.
Tool + data permissions
Scoped per employee — Ivy can touch Okta but not Payroll. Data permissions enforced at row-, doc-, and field-level, not just at the surface.
Reversible writes
Every executed action ships with a rollback path. Destructive operations are gated, logged, and never silent.
Immutable audit log
Every action stored with the who, the why, the reviewer, and the outcome. Exportable to your SIEM. Never editable, never expiring.
Where it goes. Where it stays.
Zero training on your data
Your indexed content and conversations stay isolated to your workspace. Never used to train shared models. Ever.
Bring your own model
Anthropic, OpenAI, or self-hosted inference. Your API key sits in your workspace under AES-256-GCM at rest.
PII masking + zero retention
Configurable PII detection with per-knowledge-base rules. Zero-retention mode drops conversations after answering — nothing persists.
Data residency
EU, US, or private-cloud deployment. Data stays in your region; the control plane respects your regulator's rules.
Three postures. Same platform.
Pick the deployment your regulators approve. The control plane, the AI employees, and the governance guarantees stay identical.
Multi-tenant SaaS
The fastest path. Your workspace on our infrastructure, isolated with row-level tenancy. SOC 2, GDPR, HIPAA-ready by default.
Single-tenant VPC
Your data plane in a dedicated VPC we manage. Full isolation at the network layer, dedicated inference endpoints, region-locked storage.
Self-hosted
Your infrastructure, your operator team, our control-plane binary. For teams that must never send data across an admin boundary they don't own.
The controls your procurement team will ask about first
What ships alongside the platform.
45-day proof-of-concept
One team, one AI employee, a golden set of past requests scoped upfront. If the numbers don't hit the targets we agree, we say so first.
Dedicated CSM + solution architect
A named contact and a named engineer for the deployment. Weekly cadence during launch, quarterly business reviews after.
Custom SLA
99.9% or 99.99% uptime with remediation commitments and financial penalties. First-response times as tight as your incident policy demands.
Compliance & audit support
SOC 2 report, penetration test summary, DPA, sub-processor list, and questionnaire library. Written answers, not links to a status page.
What security review asks first.
Where does our data live?
Multi-tenant SaaS deployments run in your chosen region (EU or US). Single-tenant VPC and self-hosted deployments put your data plane where you choose. In all cases, your indexed content, conversations, and vectors stay isolated to your workspace and are never used to train shared models.
How does agent identity work in a security review?
Every AI employee has its own account with an email, group memberships, and an audit trail. When an action is executed, the log reads Human → AI Employee → Skill → Tool → Action — every hop attributable. Security teams can revoke an employee's access without touching any human's permissions.
What about destructive writes?
Every action carries a risk tier. Low-risk reads auto-run. Reversible writes route to a manager. Destructive writes require step-up MFA on the reviewer before the platform will execute. And every executed write ships with a rollback path — the log records both the entity written and how to undo it.
How do you handle a hallucination that acts on a system?
It shouldn't happen — agents ground answers in your corpus and refuse to act when the corpus doesn't cover the request. But when models drift, the approval matrix catches it: the reviewer sees the source paragraph the agent read, the tool call it proposed, and the entities it targeted. Nothing writes without a real human's signature on high-risk actions.
What integrations count as 'enterprise'?
SSO (OIDC, SAML 2.0), SCIM 2.0, IdP-driven RBAC, per-tenant encryption at rest, audit log export to SIEM (Datadog, Splunk, Sumo Logic), and outbound webhooks for every material state change. Custom SIEM integrations available on request.
How long does an Enterprise deployment take?
The 45-day proof-of-concept covers scoping, integration wiring, evaluation-set assembly, and one live team. Enterprise-wide rollout after the POC is typically another 60–90 days depending on the number of departments and integration complexity. First department live in an afternoon; the workforce live in a quarter.
Deployed with governance. By default.
Book a call and we'll walk through the security review your procurement team will run — before they run it.