Products / AI agent control engine
Mandate
AI agents do the work. Companies set the rules. Mandate gives every agent an identity, a defined scope and a complete audit trail.
Request early accessThe problem
AI agents now reach live databases, APIs and internal tools the way an employee would. Increasingly they act: updating records, approving changes, moving money.
Most run on static keys with broad grants, because fine-grained scoping is hard to build in-house. Some route credentials through a gateway the enterprise does not control. When something goes wrong, nobody can say exactly what the agent did, or on whose authority.
How it works
Give each agent an identity
Each agent is declared as a spec and registered with an identity, a version, an owner and a named business capability.
Grant only what the role needs
Access is scoped to the tools and data that capability requires, with short-lived credentials issued per task instead of standing keys.
Check every action before it runs
Each call is allowed, denied with a stated reason, or held for a person to approve.
Record everything
Every access, finding, attempt and decision is logged, so when someone asks what an agent did, there is a precise answer.
Treat an agent like a new hire
A new employee gets a badge, a role and access to what the job needs, and their work can be reviewed. Mandate gives an agent the same.
| A new employee gets | An agent on Mandate gets |
|---|---|
| An ID badge | A verifiable identity, listed in your directory |
| A defined role | A named business capability |
| Access to the information the job needs | Least-privilege access to the tools and data that capability needs |
| Permission to take certain actions | Action boundaries, checked before every call |
| Work that can be reviewed | A complete audit trail |
Watch it work
A procurement agent is reviewing an invoice. It is allowed to read orders and supplier history. It is not allowed to change a supplier’s status.
Where it runs
- In your cloud. Mandate deploys inside your own environment. Credentials and audit records never leave it, and logs go to your own logging stack.
- In your directory. Each agent’s identity can appear in Active Directory or Microsoft Entra ID next to your people, so access reviews, groups and offboarding cover agents too.
- With the agents you build. Engineer-built agents on LangChain, CrewAI or custom code, calling your APIs, databases and internal tools.
Who it is for
- Platform and security teams running engineer-built agents on frameworks such as LangChain, CrewAI or custom code
- Identity and access teams who want agents in the same directory, reviews and offboarding as people
- Risk, compliance and audit teams who have to approve agents before they touch production
- CIOs and CISOs who need credentials and audit evidence to stay inside their own cloud