ControlAgent Identity & Access

Agents act for your people. They never hold your keys.

Every agent has its own identity and acts for a named person. When it needs a connected system, Record issues access for that one task, uses it on the agent’s behalf, and lets it expire. The agent never sees the secret, and every use leaves an access receipt.

invoice-agentacting for Priya Shah · FinanceNetSuite
Needs access toCreate vendor bill #4471No key stored in the agent
Access issued for this taskHeld by Record · expires in 4 minutes
Access receiptar-19c2
Agentinvoice-agent
Acting forPriya Shah
AccessScoped to one actionCreate one bill
Credential held byRecord, not the agent
Expired14:06
Access receipt sealedEvery use attributed to an agent and a person
What you get
An identity for every agent

Each agent is registered with an owner and acts for a named person, never as an anonymous key.

Access only for the task

For connected systems, access is issued when it is needed and expires right after.

A receipt for every use

Every use of access is tied to the agent and the person behind it, ready for audit.

Agent identity

Every agent has a name, an owner, and a person it acts for.

Connected and managed agents share one directory. Each action is attributed to the agent and the person behind it, not to a shared service account.

Agents148 across 11 teams
invoice-agentFinance · acts for the person who askedPriya Shah
support-botSupport · acts for the person who askedMaya Chen
ClaudeConnected · 42 developersVivek Rao
0 agents without an ownerEvery action attributed to a person
Agent directory

Every agent, its owner, and its status.

See which agents are running, who owns them, and which people they act for, across every team.

Find every agent

You have more agents than you think.

A scan of your employees’ machines finds the AI agents already in use, the MCP servers they connect to, and the secrets sitting in their config files.

Ungoverned · found in a scan1,240 machines
AI agents already in use3129 governed today
Coding agentsClaude, Codex, Cursor268
MCP serversLocal and remote143
Secrets in config files87
87 secrets in plain-text configRoute each agent through the gateway
Discovery

See shadow AI before it becomes an incident.

See Claude, Cursor, Codex, and other agents by machine, then route each one through the gateway with a single command.

If compromisedMost each agent could reach
joiner-mover-leaverStanding access to Okta, Workday, Google14 systems
phishing-triageAccess only while running6 systems
invoice-agentAccess only while running3 systems
Fix standing access firstjoiner-mover-leaver holds it while idle
Blast radius

Know what each agent could reach if compromised.

See which agents hold standing access and the most systems each one could reach, so you fix the riskiest first.

Just-in-time access

Access issued for one task, never kept by the agent.

When an agent needs a connected system, Record issues access at that moment, uses it on the agent’s behalf, and lets it expire. There’s no standing key to leak.

Access · NetSuiteinvoice-agent for Priya Shah
RequestedCreate one vendor bill14:02:11
Issued to RecordAfter policy allowed it14:02:11
UsedBill #4471 created14:02:13
Expired14:06:11
Never held by the agentExpired four minutes after it was issued
Credential lifecycle

Requested, issued, used, and expired in minutes.

Each credential is tied to one action and one person, and the agent never sees the secret.

Access receipts

Answer who acted, for whom, and with which access.

Every use of access leaves a receipt linking the agent, the person behind it, the policy, any approval, and the outcome.

Audit questionSOX review
QuestionWho used NetSuite access on September 12, and for whom?
Agentclose-agent
Acting forPriya Shah · Finance
AccessOne task · expired after 4 minutes
Approved byDana Reyes · 10:41
Answered from access receiptsNo log archaeology
Access on record

One receipt answers the auditor’s questions.

No searching logs across five systems to piece together what happened.

Agent Identity & Access

Take the keys out of your agents.

Connect one of your agents to a real system, and we’ll show access issued for a single task, then its access receipt.