Agent Identity · Know Your Agent

Your agents need an identity. Your compliance team needs proof.

The KYA program gives every AI agent a stable, auditable identity: cloud-attested trust levels, operator accountability, and signed credentials your downstream systems can verify offline. Every operator is your IdP's user, federated via OIDC, SAML, and SCIM.

Looking for IdP federation, entitlement delegation, and agent OAuth? See the Agentic IdP platform →

Unregistered

agents are already operating inside enterprise systems: no identity record, no declared scope, no accountable owner.

None

of the compliance frameworks you already report against were written for autonomous AI agents operating on third-party platforms.

Unknown

Who authorized the agent that just modified your production database, and can you prove it?

Trust tiers

KYA mirrors KYC. Three trust levels.

Just as human identity has basic, strong, and enhanced verification, KYA assigns agents a trust level based on what has been declared, attested, and linked.

Basic

Minimal declaration: model name only

Agent registered but not yet fully classified

Strong

Complete declaration or cloud attestation

Production agents with complete classification

Enhanced

Full declaration + cloud attestation + operator linked

KYA Ready: cryptographic proof of environment and human accountability

Cloud attestation (AWS, GCP, Azure) strengthens an agent's trust tier.

The KYA program

Everything a KYA audit requires.

Persistent agent identity

Every agent gets a stable ID that persists across re-verifications, model updates, and credential renewals: one identity for the full lifecycle.

Declaration-based trust scoring

Agents are scored on how completely they are declared and classified. More complete, higher trust.

Cloud environment attestation

Submit your cloud provider's signed instance evidence (AWS, GCP, or Azure). We cryptographically verify the execution environment; attested agents earn a higher trust floor.

Operator accountability chain

Each agent is anchored to a verified human operator. If the operator's credential is revoked, all linked agents are cascade-suspended automatically.

Signed agent credentials

ES256-signed W3C Verifiable Credentials carrying the agent's declared identity and attestation status. Offline-verifiable without calling our API.

Quantum-ready credentials

The credential format supports a hybrid signature: ES256 plus ML-DSA-65 (NIST FIPS 204). Classical verifiers work unchanged; PQC-aware verifiers gain protection against retroactive forgery.

Model version monitoring

Re-verification triggers automatically when an agent re-registers with a different model version, so credentials always reflect the current runtime.

KYA compliance dashboard

A real-time compliance score for your whole fleet. Know your KYA gap at a glance.

Tamper-evident audit trail

Every registration, attestation, operator link, model change, suspension, and retirement produces a signed, append-only audit entry. SOC 2 ready, 7-year retention.

Time-limited credentials

Set a validity window you control at enrollment. When it closes, the agent suspends and billing stops. Reissue any time; identity and history are preserved.

Consumer transparency seal

Mark any agent as consumer-facing to unlock a public verification page: a structured scope checklist, live credential status, and the Eniyan seal.

Structured scope checklist

Declare exactly what a consumer-facing agent can and cannot do from a standardised catalogue. No freeform text; platform-reviewed before going live.

Just-in-time activation

No standing privileges. JIT-enrolled credentials are suspended by default and wake only for named, scoped, time-bounded task windows.

Sub-agent delegation

Agents can spawn purpose-scoped child agents that inherit trust from the parent. Opt-in at registration; a child never exceeds its parent's trust or scopes, and suspension cascades.

KYA Ready

Tell your compliance team it's handled.

An agent earns KYA Ready status when it is active, cloud-attested, operator-linked, fully declared, and holds a Strong or Enhanced credential. That's the bar. We track it for every agent in your fleet.

KYA statusKYA Ready
Lifecycle
Active
Trust level
Enhanced
Cloud attested
AWSYes
Operator linked
Yes
Full declaration
Yes

Under the hood

Two properties worth a closer look.

Just-in-time activation

Suspended by default. Live only for the task.

The PAM principle applied to AI agents: zero standing privileges, enforced at the credential layer.

  • The operator's application wakes the agent with a task label, narrowed scopes, and a bounded lifetime. It auto-suspends when the window closes.
  • Every wake narrows the agent to the scopes the task actually requires: a strict subset of what it holds.
  • Out-of-scope activity is flagged the moment it happens: an audit event and a webhook, before the action completes.
  • Schedule wakes in advance for batch jobs and overnight runs; activation and auto-suspension happen on the clock.

Full JIT reference lives in the docs. Sign in to read it

Quantum-ready credentials

Built for the post-quantum era.

The credential format supports a hybrid signature: ES256 for today's verifiers, ML-DSA-65 (NIST FIPS 204) against tomorrow's quantum threat.

  • Harvest-now protection: credentials signed with ML-DSA-65 cannot be retroactively forged, even after Shor's algorithm is practical.
  • Zero breakage: the ES256 signature is unchanged, so every existing verifier and offline JWKS check keeps working.
  • Two signatures, cryptographically bound: tampering with either breaks the whole credential. Neither can be downgraded away.
  • Credentials issued with the hybrid signature stay verifiable by post-quantum verifiers years from now, without re-issuance.

Implementation details and verifier reference are shared with customers under NDA. Sign in

Same platform

Deploying consumer-facing agents?

Public verification seals, review-gated scope declarations, and the Eniyan seal are part of Verification & Transparency, the consumer-facing side of the platform.

See Verification & Transparency

Available add-on

KYA Compliance Pack

Audit-ready documentation for every AI agent you deploy. Live compliance PDFs, AI System Cards, scheduled exports, custom branding, and a 24-month archive, all generated from your real KYA registry data. For security audits, regulatory compliance, and board governance.

from $49/mo

Tiered by your platform plan

Learn more

Give every agent an identity your auditors can verify.

Simple per-agent pricing: a flat platform fee from $199/month plus $4/agent, with every risk control included in every plan.