KeyForge AI
Identity Security Platform

Continuous identity governance for humans, machines & AI agents.

Automate access decisions, detect identity risk, and continuously govern entitlements across enterprise applications, cloud infrastructure, service accounts and AI agents.

KeyForge AI unifies IGA, non-human identity governance and AI agent security through explainable, policy-driven identity reasoning. Run it standalone, or extend the IGA you already own.

What we do

Three problems enterprises are solving right now.

One engine, one rule set and one evidence model across all three — so a policy written once applies to an employee, a service account and an agent alike.

See it work

A conflict that exists in neither application.

Create Payments lives in the ERP. Finance File-Share Admin lives in the directory. Each is a reasonable grant, approved by a different team, and neither system can see the combination. One rule spans both.

Rule builder defining a cross-application segregation of duties rule spanning an ERP and a directory
Rule definition — stated in plain language, scored and scoped
Cross-application segregation of duties ruleset listing seven rules spanning ERP, directory and API systems
Cross-application ruleset — ERP × directory × API
Rules evaluate the effective permission — after inheritance and nesting are resolved — then normalise it across platforms. Once an EBS function, a Fusion privilege, a SAP authorization value and a directory group are the same kind of object, one rule can span all of them.

Why KeyForge AI

Observe. Reason. Govern. Assure.

Continuous Identity Reasoning is the architecture underneath all three solutions: deterministic policy first, every outcome traceable to a named rule, and no generative AI in the decision path unless you switch it on.

01 · Execution chain

Observe

Every identity, entitlement, tool call and the principal it acted as — captured as a connected chain rather than scattered logs.
02 · Every decision

Reason

Identity, intent, context, risk and policy evaluated together, continuously, at each decision point.
03 · Identity lifecycle

Govern

Ownership, scope, rotation, expiry and certification applied uniformly to people, service accounts and agents.
04 · Every transaction

Assure

A durable record of who authorised what, under which policy, with which approval — generated at decision time.

How it works

Signals in. Evidence out.

Detection feeds the platform; the platform owns everything after it. A signal becomes a governed event with an owner, an SLA, a decision, a remediation and an audit trail behind every state change.

  1. 1

    Signals

    Detection

    Entitlement, HR, usage and runtime events arrive from the systems you already run.

  2. 2

    Reasoning

    Policy

    Risk, peer comparison, blast radius and policy evaluated together against a versioned rule.

  3. 3

    Decision

    Judgement

    Revoke, approve with mitigation, accept risk or dismiss — signed, with evidence required.

  4. 4

    Remediation

    Action

    Executed against the target system automatically or by a reviewer, with a rollback path.

  5. 5

    Evidence

    Assurance

    Every state transition written to an immutable audit record you can reproduce months later.

Events move OPEN → IN_REVIEW → DECIDED → MITIGATING → REMEDIATING → CLOSED. Transitions are enforced server-side — reviewers cannot skip states, and every transition writes an audit record.

Enterprise use cases

The decisions your team still makes by hand.

Access reviews

Reviews triggered by change, not by calendar

A transfer, a contract extension or a new entitlement opens a targeted micro-certification with risk, usage and peer context attached — instead of waiting for the next campaign.
Cross-application SoD

Conflicts that span two systems

Create Payments in one application and Finance File-Share Admin in the directory are each reasonable alone. Together they are a toxic combination no single system can see.
Orphaned accounts

Service accounts nobody owns

Integration users outlive the projects that created them. We discover them, resolve a likely owner with evidence, and put them under the same lifecycle as people.
Excessive access

Standing privilege that was never used

Peer comparison and usage history surface the entitlements a user holds but has never exercised — the safest revocations in the backlog.
Agent delegation

Authority an agent was never meant to hold

An agent granted one tool that creates a supplier and another that releases a payment has assembled a conflict that exists in neither application.
Audit evidence

An answer before the auditor asks

Every decision carries the rule that produced it, the signals evaluated, the approver and the remediation — generated at decision time, not reconstructed later.

AI agent security

Govern the tools an agent can actually call.

An MCP server is an entitlement bundle. Every server is registered with its lifecycle, publisher and drift status; every tool carries a risk rating, a side effect, and whether it requires a human in the loop.

MCP registry showing six registered servers and the tool catalog for an SAP procure-to-pay server with per-tool risk, side effect and human-in-the-loop flags
MCP registry — server lifecycle, tool catalog, drift detection and ownership

Integration ecosystem

Built for how each platform actually grants access.

Pre-built connectors across ERP, HR, directory and cloud — plus AI self-discovery connectors that map REST and database targets themselves, turning connector onboarding from days into minutes. We resolve inheritance down to the atomic permission in each system, then normalise it, which is what makes a cross-application rule possible at all.

Start with your own estate, not a slide deck.

Book a technical demo mapped to the applications you run, or score your governance programme in five minutes first.