Products

AnchorID delivers six governance products on one control plane — for humans, non-human identities, and AI agents, from access decisions to evidence and controlled remediation.

PRODUCT 01Access Governance

Govern Access Across Every Identity

Lifecycle, intelligent access requests, approvals, Access Certification Campaigns, and Separation of Duties across every identity type.

Access Governance

Govern every access binding across your enterprise — from intelligent access requests and certification campaigns to continuous separation-of-duties enforcement.

Pending access requests

38

Overdue certifications

7

Active SoD conflicts

12

Access drift findings

24

Remediation candidates

19

What's inside

  • Identity onboarding across HR, IdP, cloud, and SaaS
  • Joiner, mover, leaver lifecycle
  • Birthright and role-based access
  • Intelligent access recommendations
  • Natural-language access requests
  • Approval workflows and policy routing
  • Access Certification Campaigns
  • Separation of Duties
  • JIT and time-bound access
  • Access expiry and active access review
  • Full access history
  • Coverage: humans, NHIs, and AI agents
PRODUCT 02NHI Governance

Control Every Non-Human Identity

Discover and govern service accounts, workload identities, machine identities, API identities, credentials, bots, and M2M access.

Identities in scope

  • Service accounts across cloud and SaaS
  • Workload and machine identities
  • Kubernetes service accounts
  • API identities, keys, tokens, and certificates
  • Automation bots and M2M identities

Governance controls

  • Ownership assignment for every NHI
  • Credential age and expiry tracking
  • Dormancy and unused-privilege detection
  • Least-privilege scoping
  • Lifecycle events and certification

Continuous signals

  • Discovery on connection and refresh
  • Behavioral baselines per identity
  • Drift against approved scope
  • Related-identity exposure
  • Evidence-ready audit history
PRODUCT 03AI Agent Governance

Govern Every Autonomous Digital Actor

Govern agent ownership, delegated authority, tools, APIs, models, data access, credentials, activity, certification, and expiry.

Agent Control RoomSanitized demo tenant
86
Agents governed
7
Unowned
19
Privileged authority
12
Scope drift
14
Certification due
Agent roster

invoice-processing-agent

Reads supplier invoices and prepares them for AP approval.

71
Agent risk
High risk
Registration
FrameworkLangGraph
RuntimeVertex AI
ModelGemini Enterprise
Delegated identityinvoice-agent-prod
Accountability
Owning teamAccounts Payable Automation
Human sponsorPriya Shah
StatusUnder review
Last activity6 minutes ago

2 open findings — AnchorID keeps agent authority, tools, data scope, and expiry under continuous review, with evidence for every decision.

What's inside

  • AI-agent inventory across providers and frameworks
  • Named agent owner and human sponsor
  • Delegated authority scope and least-authority recommendations
  • Runtime identity, credentials, tools, APIs, and models
  • Data access boundaries and restricted-scope enforcement
  • Agent-to-agent and agent-to-system trust relationships
  • Scope drift detection and anomalous behavior signals
  • Activity and decision logging
  • Agent certification campaigns
  • Time-bound authority and expiry
  • Evidence for AI-governance controls
PRODUCT 04Identity Security Posture

Understand Identity Risk and Blast Radius

Prioritize explainable identity risk, access paths, privilege concentration, blast radius, threat relationships, and access drift. Identity Security Posture (ISPM).

Posture, not just policy

A continuous, measurable view of identity risk across the enterprise — updated as access and configuration change. Identity 360, Identity Knowledge Graph, Access Graph, and Identity Threat Graph work together as capabilities inside this product.

  • Explainable risk scoring per identity (0–100)
  • Risk breakdown: privilege, activity, exposure, drift, hygiene, AI-agent risk
  • Posture heat map by identity type and system
  • Privileged-access concentration
  • Direct and transitive access
  • Drift findings and anomaly signals
POSTURE · LIVE
TENANT SCORE 57

IDENTITIES · RANKED BY RISK

87/ 100

SELECTED IDENTITY

svc-github-deploy

Critical risk

Over-privileged service account · unused 62d · admin scopes on prod GitHub org

RISK FACTORS

Privilege92
Activity12
Exposure78
Drift84
Hygiene40
AI Agent0

Every score is explainable — click any factor bar in-app to open the underlying findings.

Identity Threat Graph

Visualize how threats propagate through identities, roles, and resources — a capability inside Identity Security Posture.

THREAT PATH · SIMULATION
IDENTITYROLERESOURCEagent-claude-opsAI AGENTsvc-github-deployNON-HUMANpriya.kHUMANrole/ci-deployerrole/prod-adminrole/data-readerprod-dbDATABASEk8s-prodCLUSTERsecrets-vaultSECRETScustomer-bucketSTORAGE

STEP

Propagating (0/13)

BLAST RADIUS

0 of 4 resources reachable

REACHED

Access Graph

Every identity mapped to its roles, resources, and downstream systems — filterable by identity type.

Blast Radius Simulation

Simulate the maximum damage if an identity were compromised, across direct and transitive access.

Threat Path Analysis

Step-by-step visualization of propagation — identity to role to resource to related identity.

PRODUCT 05Compliance & Evidence

Generate Identity Evidence Continuously

Continuously validate identity controls, generate evidence snapshots, monitor readiness, and maintain timestamped audit history.

ISO 27001SOC 2PCI DSSGDPRHIPAADORAFedRAMPNISTDPDP

Evidence readiness only. Not a certification, audit opinion, or legal compliance attestation.

Identity Compliance Posture

Framework mapping across ~200 identity controls with a control-readiness heat map — green, amber, red, gray.

Evidence Snapshots

One-click evidence for Identity 360, access reviews, NHI ownership, AI-agent governance, and remediation dry-runs.

Timestamped Audit Trail

Every identity event, access decision, and remediation action logged with tenant-scoped, timestamped history.

PRODUCT 06Autonomous Remediation

Move From Identity Drift to Controlled Action

Deterministic recommendations, dry-runs, approval routing, policy validation, write-back orchestration, and post-remediation verification.

Drift or risk detected
Drift detected
Deterministic recommendation
Dry-run plan generated
Human approval required
Executed + evidence captured
DETECTED

New hire j.chen@acme.com — Day 1 birthright bundle (Okta, GSuite, Slack, Jira) missing after 6h SLA.

RECOMMENDATION

Provision 'engineering-birthright' role set via Okta group assignment. Matches 98% peer baseline in same department.

Dry-run plan · no live changes
  • + Assign group: eng-birthright (Okta)
  • + Add to workspace: engineering@acme.com (GSuite)
  • + Invite to channels: #eng-general, #eng-onboarding (Slack)
  • + Grant project role: Developer (Jira / EngPlatform)
Awaiting approvalManager approval — Priya S. (Engineering Lead)
Executed · evidence captured

4 entitlements provisioned in 12s. Onboarding SLA restored. Evidence logged to SOX-AC-02.

Write-back remediation is disabled by default. All actions are dry-run or simulated unless explicitly enabled per tenant.

Deterministic Recommendations

Recommendations generated from real identity, access, and drift data — with current state, proposed state, and estimated risk reduction.

Approval-First Execution

No identity change executes without human approval. Dual-approval mode available for SOX and regulated tenants.

Full Audit Trail

Every recommendation, dry-run, approval, and execution logged with actor, timestamp, and outcome.

Ready to see it in action?

Join the design partner program to explore Access Governance, NHI Governance, AI Agent Governance, Identity Security Posture, Compliance & Evidence, and Autonomous Remediation.

Request early access