Agent Identity · Know Your Agent
Your agents need an identity. Your compliance team needs proof.
The KYA program gives every AI agent a stable, auditable identity: cloud-attested trust levels, operator accountability, and signed credentials your downstream systems can verify offline. Every operator is your IdP's user, federated via OIDC, SAML, and SCIM.
Unregistered
agents are already operating inside enterprise systems: no identity record, no declared scope, no accountable owner.
None
of the compliance frameworks you already report against were written for autonomous AI agents operating on third-party platforms.
Unknown
Who authorized the agent that just modified your production database, and can you prove it?
Trust tiers
KYA mirrors KYC. Three trust levels.
Just as human identity has basic, strong, and enhanced verification, KYA assigns agents a trust level based on what has been declared, attested, and linked.
Basic
Minimal declaration: model name only
Agent registered but not yet fully classified
Strong
Complete declaration or cloud attestation
Production agents with complete classification
Enhanced
Full declaration + cloud attestation + operator linked
KYA Ready: cryptographic proof of environment and human accountability
Cloud attestation (AWS, GCP, Azure) strengthens an agent's trust tier.
The KYA program
Everything a KYA audit requires.
Persistent agent identity
Every agent gets a stable ID that persists across re-verifications, model updates, and credential renewals: one identity for the full lifecycle.
Declaration-based trust scoring
Agents are scored on how completely they are declared and classified. More complete, higher trust.
Cloud environment attestation
Submit your cloud provider's signed instance evidence (AWS, GCP, or Azure). We cryptographically verify the execution environment; attested agents earn a higher trust floor.
Operator accountability chain
Each agent is anchored to a verified human operator. If the operator's credential is revoked, all linked agents are cascade-suspended automatically.
Signed agent credentials
ES256-signed W3C Verifiable Credentials carrying the agent's declared identity and attestation status. Offline-verifiable without calling our API.
Quantum-ready credentials
The credential format supports a hybrid signature: ES256 plus ML-DSA-65 (NIST FIPS 204). Classical verifiers work unchanged; PQC-aware verifiers gain protection against retroactive forgery.
Model version monitoring
Re-verification triggers automatically when an agent re-registers with a different model version, so credentials always reflect the current runtime.
KYA compliance dashboard
A real-time compliance score for your whole fleet. Know your KYA gap at a glance.
Tamper-evident audit trail
Every registration, attestation, operator link, model change, suspension, and retirement produces a signed, append-only audit entry. SOC 2 ready, 7-year retention.
Time-limited credentials
Set a validity window you control at enrollment. When it closes, the agent suspends and billing stops. Reissue any time; identity and history are preserved.
Consumer transparency seal
Mark any agent as consumer-facing to unlock a public verification page: a structured scope checklist, live credential status, and the Eniyan seal.
Structured scope checklist
Declare exactly what a consumer-facing agent can and cannot do from a standardised catalogue. No freeform text; platform-reviewed before going live.
Just-in-time activation
No standing privileges. JIT-enrolled credentials are suspended by default and wake only for named, scoped, time-bounded task windows.
Sub-agent delegation
Agents can spawn purpose-scoped child agents that inherit trust from the parent. Opt-in at registration; a child never exceeds its parent's trust or scopes, and suspension cascades.
KYA Ready
Tell your compliance team it's handled.
An agent earns KYA Ready status when it is active, cloud-attested, operator-linked, fully declared, and holds a Strong or Enhanced credential. That's the bar. We track it for every agent in your fleet.
- Lifecycle
- Active
- Trust level
- Enhanced
- Cloud attested
- AWSYes
- Operator linked
- Yes
- Full declaration
- Yes
Under the hood
Two properties worth a closer look.
Just-in-time activation
Suspended by default. Live only for the task.
The PAM principle applied to AI agents: zero standing privileges, enforced at the credential layer.
- The operator's application wakes the agent with a task label, narrowed scopes, and a bounded lifetime. It auto-suspends when the window closes.
- Every wake narrows the agent to the scopes the task actually requires: a strict subset of what it holds.
- Out-of-scope activity is flagged the moment it happens: an audit event and a webhook, before the action completes.
- Schedule wakes in advance for batch jobs and overnight runs; activation and auto-suspension happen on the clock.
Full JIT reference lives in the docs. Sign in to read it →
Quantum-ready credentials
Built for the post-quantum era.
The credential format supports a hybrid signature: ES256 for today's verifiers, ML-DSA-65 (NIST FIPS 204) against tomorrow's quantum threat.
- Harvest-now protection: credentials signed with ML-DSA-65 cannot be retroactively forged, even after Shor's algorithm is practical.
- Zero breakage: the ES256 signature is unchanged, so every existing verifier and offline JWKS check keeps working.
- Two signatures, cryptographically bound: tampering with either breaks the whole credential. Neither can be downgraded away.
- Credentials issued with the hybrid signature stay verifiable by post-quantum verifiers years from now, without re-issuance.
Implementation details and verifier reference are shared with customers under NDA. Sign in →
Same platform
Deploying consumer-facing agents?
Public verification seals, review-gated scope declarations, and the Eniyan seal are part of Verification & Transparency, the consumer-facing side of the platform.
Available add-on
KYA Compliance Pack
Audit-ready documentation for every AI agent you deploy. Live compliance PDFs, AI System Cards, scheduled exports, custom branding, and a 24-month archive, all generated from your real KYA registry data. For security audits, regulatory compliance, and board governance.
Give every agent an identity your auditors can verify.
Simple per-agent pricing: a flat platform fee from $199/month plus $4/agent, with every risk control included in every plan.