Skip to content

Site search

Type to search Pages

Security & control

Every action traces to a named human.

Mandavo issues each agent a short-lived, least-privilege identity bound to an accountable sponsor, enforces that authority at the moment of execution, and writes every decision to an immutable log. We run our own fabric on the same controls.

The mechanism

Issuance, execution and verification — kept distinct.

An internal permission and a credential a counterparty accepts are not the same claim. Mandavo holds both, and does not blur them.

Issuance

Each agent receives a distinct cryptographic identity in a canonical directory and short-lived credentials scoped to a named human sponsor. There is no shared service account and no standing, broadly-privileged key to leak.

Execution-time enforcement

Authorization is evaluated at the moment an agent acts, against its scope, value and transaction thresholds, and expiry. A stolen or over-reaching credential is bounded by what the policy allows, not by what the caller requests.

Immutable record

Every issuance and every authorization decision is written to an immutable log. This is the evidence a CISO needs to show which named human is accountable for a given autonomous action, and to support SOC 2 and ISO 27001 service-account and key-management review.

Revocation that propagates

Credentials are revocable by design. Revocations propagate across the network so no counterparty relies on stale authority, and short lifetimes mean credentials rotate rather than accumulate as long-lived secrets.

Open standards

Credentials are issued as W3C Verifiable Credentials over Decentralized Identifiers, not a proprietary token format. They remain interoperable and independently verifiable outside Mandavo.

Enforceable forum

The sponsor binding — the link between an agent's authority and the human fiduciary who holds it — is enforceable in the DIFC legal forum in which Mandavo operates.

Where humans stay in control.

AI colleagues operate the platform under human governance. They provision and rotate agent identities, monitor access patterns for anomalies, draft proposed permission changes, and prepare revocation actions. Routine, low-risk operations run autonomously, with full logging. The boundary is explicit and it does not move.

Retained human authority

High-risk grants, elevated scopes and production-affecting policy changes pass through explicit approval gates before they take effect.

Anything touching money, sensitive data, or the onboarding of a new counterparty system is escalated to the accountable human sponsor.

AI colleagues carry out the operational work but cannot self-approve elevated authority.

Each credential names a human sponsor who holds fiduciary accountability for the agent's authority and signs off on the controls.

What Mandavo does not do.

We state the boundary before you have to discover it.

Boundaries

The verification registry exposes only what a counterparty needs to make a trust decision — a credential's validity, its authority scope, and its revocation status. It does not expose your payloads, transaction contents, or internal policy.

Mandavo governs the identity and authority of an agent; it does not replace the runtime, model or business logic of the agent itself.

We make no certification claim we cannot evidence. The immutable log is built to support SOC 2 and ISO 27001 service-account and key-management evidence; where the record holds no certification, we do not assert one.

A credential is proof of granted authority checked at execution — it is not a guarantee about how an agent behaves once acting within that authority.

For the people who own this

Questions security and platform owners ask first.

When an agent takes a production action, can I trace it to a named human?

Yes. Each agent holds a distinct identity, and its credential binds it to a named human sponsor. Every issuance and authorization decision is written to an immutable log, so attribution runs to a named person rather than stopping at a shared service account or a borrowed login.

If a credential leaks, what is the blast radius?

Credentials are short-lived, least-privilege and revocable. Authorization is evaluated at the moment of execution against the credential's scope, value and transaction thresholds, and expiry — so a stolen credential is limited to what its scope permits, and revocations propagate across the network.

Do you hold SOC 2 or ISO 27001?

We do not assert a certification the record does not state. What we provide is the evidence those audits require: an immutable log of every issuance and authorization decision, built to support SOC 2 and ISO 27001 service-account and key-management review.

What does a counterparty actually see when they verify an agent?

Only what they need to make a trust decision — the credential's validity, its authority scope, and its revocation status — checked in real time before they transact. Payloads and internal policy are not exposed.

Can the AI colleagues that run the platform grant themselves elevated authority?

No. AI colleagues carry out operational work but cannot self-approve elevated authority. High-risk grants, elevated scopes and production-affecting policy changes pass through explicit human approval gates first.

Are the credentials locked to Mandavo?

No. They are issued as W3C Verifiable Credentials over Decentralized Identifiers, not a proprietary token format, so they remain interoperable and independently verifiable.

Review the controls with us.

Reach us at hello@mandavo.ai — a named human owns the response.