Identity Access Plus Platform

Zero Trust for Agents

AI agents can now act on your identity systems: creating users, disabling accounts, granting access. Identity Access Plus keeps every one of those actions accountable, authorized just in time and verified by the human behind them, built on open standards like OAuth 2.1, OpenID AuthZEN and MCP.

Identity Access Plus Agent home screen

Why Identity Access Plus?

A Zero Trust for Agents platform, built on open standards so you can adopt the policy engines, gateways, and other components that best fit your architecture. Every privileged action is authorized just in time and verified by the human behind it.

IA+ Agent

Talk to your identity platform in plain language. The IA+ Agent understands requests like "disable this user" or "list active sessions" and carries them out through the Model Context Protocol (MCP), under the same security guarantees as any other action on the platform.

Access Management

Authentication built on open identity standards such as OpenID Connect, supporting both password based and passwordless sign in.

Authorization via AuthZEN Gateway

Authorization is delegated via OpenID AuthZEN to an external PDP, with the AuthZEN AI/API Gateway enforcing decisions on every MCP request.

Agent Native Authorization (ANA)

When an agent attempts something privileged, ANA steps in: the request becomes an explicit, auditable intent, then a Just In Time, passkey backed authorization confirms it, with no browser redirect and cryptographic proof bound to the exact operation.

Centralized Admin Console

One console, one 360° view of your entire IAM landscape across every IA+ module.

Open Source & Open Standards

Built on open source platforms and open identity standards, so you're free to adopt the components that fit your architecture.

See it in action

Ask, and the platform shows you

Natural language becomes a live view of your identities. Ask the IA+ Agent to list users, and it opens an interactive MCP App right inside the conversation, no separate console tab required.

Drill into any identity

Every identity's full record (credentials, roles, permissions, devices, organizations) is one question away, explored through the same interactive MCP App.

Intent Based Agent Native Authorization

For complex requests, the agent builds a plan you approve

When a request touches multiple users or actions, the IA+ Agent doesn't just execute. It drafts an explicit plan of the exact operations involved, for you to review and approve before anything runs.

Critical actions pause for just-in-time authorization

Disabling or deleting a user isn't a single silent step for an agent. Identity Access Plus pauses the task and requires Just In Time authorization, approved with a passkey, before anything critical executes.

Verified by you, in the conversation, not a redirect

The final step is cryptographic, not conversational: a passkey challenge (Touch ID, Face ID, or a security key) confirms a human authorized the exact operation, without ever leaving the agent experience.

See the full flow

Watch Identity Access Plus manage a live Keycloak tenant

In this demo, our AI stack manages our MCP IAM server for Keycloak. We start with a high level view of the connected platforms, then use MCP Apps to explore flows and manage users.
A critical user management operation triggers Just In Time authorization with passkeys. For a more complex, multi user operation, the agent builds a plan for review and approval, using Intent Based Authorization. Every action is enforced by the AI Gateway against a decision from an external Policy Decision Point over AuthZEN.

Agentic AI Identity Access Plus Release Status

The platform is currently in the early stages, progressing towards stabilization, and actively engaging in product discovery based on customer feedback gathered during the Proof of Concept (PoC) phase. Customer feedback is crucial for us as it helps prioritize the platform's roadmap and guides us in determining our next steps. Stay connected to receive the latest updates.