Automate access decisions, detect identity risk, and continuously govern entitlements across enterprise applications, cloud infrastructure, service accounts and AI agents.
KeyForge AI unifies IGA, non-human identity governance and AI agent security through explainable, policy-driven identity reasoning. Run it standalone, or extend the IGA you already own.
What we do
One engine, one rule set and one evidence model across all three — so a policy written once applies to an employee, a service account and an agent alike.
See it work
Create Payments lives in the ERP. Finance File-Share Admin lives in the directory. Each is a reasonable grant, approved by a different team, and neither system can see the combination. One rule spans both.


Why KeyForge AI
Continuous Identity Reasoning is the architecture underneath all three solutions: deterministic policy first, every outcome traceable to a named rule, and no generative AI in the decision path unless you switch it on.
How it works
Detection feeds the platform; the platform owns everything after it. A signal becomes a governed event with an owner, an SLA, a decision, a remediation and an audit trail behind every state change.
Entitlement, HR, usage and runtime events arrive from the systems you already run.
Risk, peer comparison, blast radius and policy evaluated together against a versioned rule.
Revoke, approve with mitigation, accept risk or dismiss — signed, with evidence required.
Executed against the target system automatically or by a reviewer, with a rollback path.
Every state transition written to an immutable audit record you can reproduce months later.
Events move OPEN → IN_REVIEW → DECIDED → MITIGATING → REMEDIATING → CLOSED. Transitions are enforced server-side — reviewers cannot skip states, and every transition writes an audit record.
Enterprise use cases
AI agent security
An MCP server is an entitlement bundle. Every server is registered with its lifecycle, publisher and drift status; every tool carries a risk rating, a side effect, and whether it requires a human in the loop.

Integration ecosystem
Pre-built connectors across ERP, HR, directory and cloud — plus AI self-discovery connectors that map REST and database targets themselves, turning connector onboarding from days into minutes. We resolve inheritance down to the atomic permission in each system, then normalise it, which is what makes a cross-application rule possible at all.
Book a technical demo mapped to the applications you run, or score your governance programme in five minutes first.