$ every product image on this site is an unretouched screenshot of the running platform — demo tenant, fictional people, captured live
🤖 Platform · AI agents

Every AI agent: registered,
owned, revocable.

AI agents become first-class identities on a register: a named owner, an autonomy tier you attest against, a credential inventory with expiry findings, and a kill-switch for the day one misbehaves. Plus an evidence pack that refuses to claim more than it measured.

01 · The agent register

An owner, a tier, and honest provenance.

Every agent on the register carries a named owner — a person or a group — an autonomy tier, a source and a credential position. Agents are re-confirmed through the same access-review spine as every other identity, and overdue attestation is broken out by tier — so the agents with the most latitude are the ones you see slipping first.

  • Three autonomy tiers — assisted, supervised, autonomous — recorded per agent and reported on. They are the first three rungs of the wider four-tier NHI ladder; the fourth, AI-to-AI federation, is a delegation concern rather than an autonomy setting
  • Provenance is two-tier and enforced: discovered means a Microsoft Entra Agent ID sync actually saw the object; registered means someone declared it. A declared agent cannot claim to be discovered
  • The register states what it does not know: agent sign-in activity is not reported without Microsoft Entra Workload ID on the connected tenant — that amber banner in the screenshot is the product saying so, and it adds that register, ownership and credential expiry work fully without it
  • Self-hosted agents show “n/a — self-hosted” for last-seen — never a fabricated number
…/nhi · agents
the agent register — three agents with autonomy tier, named owner and credential status, the provenance split reading 0 discovered · 3 registered, one credential expiring within 30 days, and the product's own amber notice that agent sign-in activity is not reported without Microsoft Entra Workload ID
the register admits its blind spot on screen — the amber banner is the product talking, not the marketing

Standing credentials, counted

Credential hygiene, and the hard stop.

🔑 A credential inventory per agent

Every agent carries its credential inventory, and expiry drives the findings: expiring-soon and expired credentials are flagged where you triage. The register column shows only the expiring and expired set — the full picture lives on the agent, and the product says so under the table.

🔐 Google Workspace app passwords, included

An application-specific password is a real standing credential: it bypasses two-step verification, never expires, and can only be revoked. The inventory treats it as exactly that — and its last-used timestamp is the first genuine last-used signal the inventory has had.

🛑 A kill-switch for incident response

When an agent misbehaves, one action cuts it off. Every kill-switch action — like everything else here — lands in the immutable audit trail, so the incident record and the response record are the same record.

🚫 What we deliberately do not cover

GCP service-account keys are out of scope today — deliberately, and we say so rather than half-support them. And Microsoft Entra's own credential last-used signal is licence-gated: where we cannot read it, it reads as unknown, not as a guess.

02 · The evidence pack

Aligned with the EU AI Act — applicability stated, not assumed.

One generated bundle answers the accountability questions: the agent register, who is accountable for each agent, whether credentials are current, the attestation history, and the audit trail including any kill-switch action.

  • Six sections, each with its citation: ISO/IEC 42001 Annex A resource documentation (A.4.2, A.3.2) and EU AI Act Art. 12, Art. 14 (human oversight) and Art. 26
  • The pack states its own applicability, on the card: those articles bind deployers of high-risk AI systems, most internal agents are not high-risk, and the pack does not determine which of yours are — that assessment is yours to make
  • It asserts only what it measured. It does not claim you are legally required to comply, nor that compliance has been achieved — read that in the screenshot, in the product's own words
  • Generated alongside the SOC 2 and NIS2 packs, from the same immutable trail
…/compliance · evidence packs
the AI-agent governance evidence pack card, tagged EU AI Act (deployer obligations) · ISO/IEC 42001, with its applicability caveat printed in full on the card, listed alongside the SOC 2 and NIS2 evidence packs
the caveat is on the card: the pack does not decide which of your agents are high-risk, and does not claim compliance

Honesty first

What this page will not claim

No compliance claims. On purpose.

The evidence pack refuses to over-claim in its own on-screen description, and this page holds itself to the same line:

Using RapidValue does not make you “EU AI Act compliant” — no tool purchase does We do not determine whether your agents are high-risk under the Act — that assessment is yours to make Agent sign-in activity is not reported without Microsoft Entra Workload ID — the product tells you so in an amber banner, on screen Entra's credential last-used signal is licence-gated — where we cannot read it, it shows unknown Deriving the review interval from the autonomy tier is not shipped — you set the review rule, the tier is what it reports againstGCP service-account keys are not covered today Self-hosted agents get “n/a — self-hosted” for last-seen, never an invented number

Put a name on every agent.

A 30-minute kickoff connects your HR feed and one system — working POC the same day.

Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.