Skip to content

Site search

Type to search Pages

Product

Trace every agent action to a named human.

When an agent takes a production action, attribution should not stop at a shared service account or a borrowed login. Mandavo gives each agent a distinct identity and short-lived credentials scoped to a named human sponsor, evaluates authority at the moment of execution, and writes every decision to an immutable log.

The control gap

What security teams already see.

27%of leaders believe their identity systems can govern non-human identitiesSource: research cited in our record.
28%can trace an agent's actions to a human sponsorSource: research cited in our record.
70%of secrets leaked in 2022 remained valid in 2025Source: research cited in our record.

The product concept

One credential, three layers.

The layers are not three products. They are one credential that becomes worth more the further it travels — least privilege inside your company, verified delegation to your counterparties.

Control

Each agent gets a distinct cryptographic identity, short-lived credentials scoped to a named human sponsor, and policy evaluated at the moment of execution — with every decision written to an immutable log. This is the root of trust, and the layer a CISO can deploy inside their own tenant today.

Attestation

The same credential is issued as a W3C Verifiable Credential binding the agent to a legal entity, an authority scope, value and transaction thresholds, an expiry, and the accountable human fiduciary. This converts an internal fact into portable proof.

Verification

A real-time API lets a counterparty check a credential's validity, authority scope and revocation status before committing to an interaction. An internal permission is a control; a credential a counterparty accepts is a proof — Mandavo keeps both.

Four modules, one root of trust.

Issues each agent a distinct cryptographic identity in a canonical directory, with short-lived credentials scoped to a named human sponsor and policy evaluated at the moment of execution. Every decision is written to an immutable log, replacing borrowed logins and shared static keys.

How a customer moves through it

From provisioning to revocation.

The same path every agent follows, with a named human accountable at each escalation.

Provision a scoped identity

An administrator, or an AI colleague drafting the change, requests an identity for a new agent. Low-risk grants are issued automatically with full logging; elevated scopes route to a named human sponsor for approval. The agent receives a short-lived credential bound to that sponsor and to the systems it may reach.

Authorize an action at execution

When an agent attempts an action, Mandavo evaluates policy against the credential's scope, value and transaction thresholds and expiry in real time, then permits, escalates, or denies. The decision and its context are written to the immutable log.

Verify a counterparty's agent

Before committing to an interaction, a vendor, bank or another company's agent calls the verification API to confirm the presenting agent's credential is valid, in-scope and not revoked, and to see the accountable legal entity and human sponsor. If authority has been revoked, the check fails immediately.

Revoke authority

A sponsor or AI colleague revokes an agent's authority when it is compromised or its task is complete. The revocation propagates across the registry so counterparties cannot rely on stale credentials, and the action is recorded for audit.

How it runs, and where the boundaries sit.

AI colleagues operate; named humans govern

AI colleagues run the platform under human governance. They provision and rotate agent identities, continuously monitor access patterns for anomalies, draft proposed permission changes, and prepare revocation actions for review.

The credential is the coordination primitive: policy is expressed once, enforced at execution, issued as a verifiable attestation, and checked by counterparties through the same registry — so the internal control plane and the external verification surface share one source of truth.

Human accountability is not delegated

Human administrators retain final authority. High-risk grants, elevated scopes, and production-affecting policy changes pass through explicit approval gates before they take effect.

Each credential names a human sponsor who holds fiduciary accountability for the agent's authority and signs off on the controls. AI colleagues do the operational work but cannot self-approve elevated authority. Anything involving money, sensitive data, or onboarding a new counterparty system is escalated to the accountable sponsor.

Compliance and security posture

Credentials are short-lived, least-privilege and revocable by design, with every issuance and authorization decision written to an immutable log to support SOC 2 and ISO 27001 service-account and key-management evidence.

Mandavo builds on the W3C Verifiable Credentials and Decentralized Identifiers standards rather than a proprietary token format, so credentials remain interoperable and independently verifiable. The verification registry exposes only what a counterparty needs to make a trust decision — validity, scope, and revocation status. DIFC provides the legal forum in which the sponsor binding is enforceable.

What Mandavo does not do

Mandavo is an authority layer for AI agents, not a general-purpose identity system for your human workforce. It decides whether an agent may act within its scope, value threshold and expiry; it does not replace your application's business logic.

Cross-organisation verification is in development. At the outset, verification is a validity and revocation check between known parties, alongside issuance of the same credential as a W3C Verifiable Credential. Verified delegation across many organisations is a direction we are building toward, not a capability we claim today.

Direction, not commitments

Where the product is heading.

These are our current product intentions in sequence. They describe direction and may change; they are not promises of dates or outcomes.

Near term

The Control layer in production with a small number of design partners, starting with FTLAB portfolio ventures: per-agent identities, sponsor-scoped short-lived credentials, execution-time policy enforcement, and immutable logging, with early SOC 2 and ISO 27001 evidence mapping in place.

Following stage

The Attestation layer live: credentials issued as W3C Verifiable Credentials binding agent, legal entity, authority scope, thresholds, expiry and human sponsor. A first version of the verification API allows a counterparty to check validity, scope and revocation status between known parties, with anomaly monitoring and revocation workflows generally available.

Later stage

A verification registry operating across multiple organisations with revocation propagation, enabling verified delegation to external counterparties and early agent-to-agent authority checks, alongside integrations with Model Context Protocol tooling and common IAM directories.

Questions before you deploy

What security and platform teams ask.

How do I show an auditor which human is accountable for an agent's action?

Each agent holds a distinct identity, not a shared service account, and every credential names the human sponsor who is accountable for it. Every authorization decision is written to an immutable log, so an action traces to a named human sponsor through a distinct per-agent identity rather than a borrowed login.

What limits the blast radius if a credential leaks?

Credentials are short-lived and scoped to a named sponsor, and authorization is evaluated at the moment of execution against the credential's scope, value and transaction thresholds and expiry. A stolen or over-reaching credential is bounded by that scope, and revocation propagates across the registry.

Can an engineer obtain a credential without hardcoding a static key?

Yes. An agent can be provisioned a short-lived credential scoped to a named sponsor and to the systems it may reach, so there is no need to inject or commit a static key into agent or MCP configuration.

How are high-risk actions handled?

Low-risk grants are issued automatically with full logging. Elevated scopes, production-affecting policy changes, and anything touching money, sensitive data, or a new external system pass through explicit approval gates and are escalated to the accountable human sponsor. AI colleagues cannot self-approve elevated authority.

Are the credentials proprietary?

No. Mandavo builds on the W3C Verifiable Credentials and Decentralized Identifiers standards rather than a proprietary token format, so credentials remain interoperable and independently verifiable.

Does a counterparty need to trust Mandavo to accept a credential?

A counterparty checks a credential's validity, authority scope and revocation status through the verification API before transacting. At launch this is a check between known parties; verification across many organisations is in development, and the sponsor binding is enforceable in a DIFC forum.

Bring one agent and one system.

We will walk through provisioning a scoped identity, enforcing it at execution, and revoking it — on your terms.