Skip to content

Site search

Type to search Pages

Company

An authority layer for agents, built to be verified — not asserted.

Mandavo is a venture of Future Thesis Lab, formed in the DIFC. It gives every AI agent a scoped, revocable identity bound to a named human sponsor, enforces that authority at the moment of execution, and lets any counterparty check it in real time before transacting.

The control gap security teams can already name.

Enterprises are deploying AI agents into production faster than their identity systems can govern them. Agents borrow human logins or share static, over-privileged keys, so when an agent takes an action there is often no per-agent attribution, no clean line back to an accountable human, and no clean path to revocation.

Industry research indicates that only 27% of leaders believe their identity systems can govern non-human identities, and only 28% can trace an agent's actions to a human sponsor. In the same research, 70% of secrets leaked in 2022 remained valid in 2025. This is the gap a CISO is budgeting for today: a distinct identity per agent, scoped to what it may do, bound to the person who is answerable for it.

Why now

Machine identities now outnumber humans by more than 80 to 1 (CyberArk), while governance was built for human and service-account workflows. Gartner projects task-specific AI agents in 40% of enterprise applications by end-2026, up from less than 5% in 2025.

Credential sprawl is accelerating alongside that shift: GitGuardian recorded around 28.65 million new hardcoded secrets in public GitHub in 2025, up 34% year on year. The identity layer is being demanded ahead of mass deployment, which is why we are building it now rather than after.

The insight we are built on

An internal control plane can secure an agent, but it can never make a counterparty accept that agent's authority, because it produces no portable proof. Control inside your tenant and proof a bank or another company's agent will accept are two different claims, and we keep them apart.

So Mandavo reissues the same credential as a portable W3C Verifiable Credential and exposes a real-time verification API. Holding both the root of trust and the neutral verification surface is a position incumbents structurally cannot occupy — a vendor whose customers are each other's counterparties cannot also be the neutral registry between them.

An AI-born company, operated the way it sells.

Mandavo is an FTLAB venture designed to be run by AI colleagues under accountable human governance — the same architecture the product provides.

  • A venture of Future Thesis Lab
  • DIFC, Dubai, UAE
  • Pre-Seed

AI colleagues do the operating work

AI colleagues provision and rotate agent identities, monitor access patterns for anomalies, draft proposed permission changes, and prepare revocation actions — all with full logging.

Named humans govern and approve

High-risk grants, elevated scopes and production-affecting policy changes pass through explicit approval gates before they take effect. Humans own the fiduciary duties and sign off on the controls.

Run on the controls it sells

Mandavo operates its own fabric on the same identity, enforcement and verification controls it offers customers, so the operating model and the product are the same architecture.

An enforceable DIFC forum

The DIFC provides an English-language common-law forum in which a credential's binding to a named human fiduciary is enforceable — which matters precisely when a counterparty relies on that authority to transact.

Where we begin, and what we are careful not to claim.

An early market, sized with our assumptions marked

Mandavo sits inside a global IAM market of roughly $26bn, within which non-human identity is the fastest-growing sub-segment. We scope a serviceable market of roughly $3.9bn — an assumption of about 15% of IAM for 2025, marked as an assumption because no credible standalone figure exists in the research we reviewed.

The direction of travel is real but early: Gartner expects 33% of enterprise software to include agentic AI by 2028. We report the estimate and the assumption side by side, and never round toward the flattering number.

The boundary of the product

Mandavo issues, enforces and verifies agent authority. It does not decide which grants an enterprise should allow — high-risk grants and elevated scopes remain with the accountable human sponsor. It secures how an agent acts; it does not replace the judgement about whether it should.

We also name the risks we could be wrong about: cross-counterparty verification may never become load-bearing, incumbents could ship a 'good enough' bundled feature, and Gartner expects over 40% of agentic AI projects to be cancelled by end-2027. We publish these so our roadmap stays honest and our customers stay ahead of our marketing.

Speak with the people accountable for Mandavo.

We are pre-launch and working with early design partners. If you own non-human identity, run an identity control plane, or ship agents into production, we would like to hear how you handle agent authority today.