idGenius platform

Three classes. Five traits. One schema.

Each source keeps its native shape. New entity types resolve at query time — no ETL program, no migration, no integration spend.

WORKFORCEPeopleEmployees, contractors and consultants. Contingent workers, vendors, suppliers and partners.
MACHINEMachinesService accounts, machinery and OT, devices — every workload with a verifiable identity.
CONTEXTOrganizations & digital entitiesOrganizations, projects, platforms, applications, data and documents.

AI agents connect across all three — people, machines, and organizations and digital entities.

Five traits, every object
A named accountable owner
A lifecycle
Policy
Relationships
One audit trail
Integration surface

Integrates with more than 2,000 systems

idGenius integrates with identity security platforms, applications, documents and data providers for discovery — each read in place and resolved into the same schema.

Years of ETL and millions of dollars — or read it where it already lives.

Native integrations · discovery

idGenius integrates with more than 2,000 systems.

idGenius integrates with the categories and vendors below for discovery — read in place, no migration, resolved into one schema.

HR / HCM
IAM
IGA
PAM
Secrets and machine credentials
AI platforms and LLM gateways
Cloud platforms
Containers and workload identity
CI/CD and source control
ITSM and CMDB
Endpoints and EDR
SIEM and SOAR
Third-party risk and GRC
Nonemployee and vendor management
Contract lifecycle
ERP and procurement
CRM
Documents and collaboration
Data warehouses
FinOps and cloud cost
Project management
INTEGRATES WITHHR / HCM
WorkdaySAP SuccessFactorsADPUKGBambooHRRippling
Read-only discovery. Native nodes where they exist, API and webhook connections everywhere else.

Native nodes where they exist, API and webhook connections everywhere else. Discovery first, read-only.

The shared identity layer

One graph. Eleven entity classes. Live risk on every edge.

Entity classes come into focus as you read down the page. Triple store plus streaming ingest — the graph is the state, not a nightly snapshot.

The runtime request

One request. Deeply answered.

AuthZEN asks the question. idGenius fills the context that makes the answer meaningful.

WITHOUT CONTEXT
subject = Agent123action = readresource = Document456
Three strings. Nothing about ownership, purpose, policy or risk.
WITH THE RELATIONSHIP GRAPH

Agent 123 — owned by Vendor A, acting for Project B, under Contract C, authorized by Employee D, accessing sensitive customer information, for a stated business purpose, under applicable policy — with current risk = X.

The authorization contract

Authorization as a standard contract.

AuthZEN defines the question. idGenius defines the answer it returns.

AUTHZEN EVALUATES · EVALUATION_REQUEST
subject: actor identifieraction: verb requestedresource: object identifiercontext: time, IP, device, …
The standard — the only standard the enforcement point knows.
IDGENIUS DELIVERS · EVALUATION_RESPONSE
decision: allow / denycontext: who owns it, who reached, current risk = Xreasons: policy citationsobligations: enforcement requirements
Same request shape. An answer that carries its reasoning.

One contract. Every enforcement point. Same request shape — an answer that carries its reasoning.

Capability cycle & APIs

One cycle. Six capabilities. One intelligence layer.

01
Discover
02
Understand
03
Govern
04
Enforce
05
Observe
06
Audit
01DiscoverFind every entity. Connectors and inventory, read in place.
  • Identity security platforms
  • Applications and data
  • Endpoints and platforms
  • Third parties and contracts
02UnderstandCritical relationship mappings — what it is, what it reaches, what it risks, so AI agents connect securely.
  • People and organizations
  • Endpoints and platforms
  • Applications and documents
  • The mapping consultants bill for
03GovernOwner, policy and lifecycle bound to every object.
  • Named accountable owner
  • Policy from source documents
  • Lifecycle state
  • Conflicts surfaced as they arise
04EnforceDecisions at your existing enforcement points.
  • AuthZEN contract
  • OAuth and SCIM
  • SPIFFE and SPIRE
  • No proprietary SDK
05ObserveCentral intelligence. Maintains the graph, computes live risk, drives reaction.
  • Streaming ingest
  • Edges re-weighted on every signal
  • Live risk = X
  • No nightly snapshot
06AuditSponsored, approved, reached, expired — one trail per action.
  • Identity ledger
  • Policy citations
  • SIEM streamed
  • Cost provenance

Every decision traces to its evidence, with a cost-provenance record on every action.

Discover · Understand · Govern · Enforce · Observe · Audit — one cycle, one runtime

Actor lifecycle

Engage to ReEngage. Governed by one ledger.

SCIM is the lingua franca. idGenius inherits it — and adds the owner, policy, relationships, and audit trail.

The lifecycle every actor moves through
01
Engage
02
Change
03
DisEngage
04
ReEngage
05
Identity Ledger
06
Audit
01EngageBirth of an actor. Owner assigned. Policy bound.
02ChangeRole and relationships change. Policy re-evaluated live.
03DisEngageDecommissioned. Revocation cascades, sessions terminate — the record persists.
04ReEngageRenewed two years later. History intact, re-attested against today's policy.
05Identity LedgerA constant state of governance. No access certification campaigns.
06AuditOne trail. For every event, in every state.
IDENTITY LEDGER · CONSTANT STATE OF GOVERNANCEGovernance as a state, not a campaign.

Every state change writes to the ledger — including the dormant years. Because it is always current, entitlements never need to be re-proven on a calendar: no quarterly access certifications, no manual re-attestation drives. Conflicts and violations surface as they arise, and Audit inherits a trail that was already complete.

Provisioning is the easy half. Governance is the half that persists.

Policy from documents

Source documents. Structured policy. Live decisions.

Source documents → structured policy → live decisions on every request.

SOURCEDocumentsMSA & DPA clauses · HR & infosec policy · regulatory text · industry frameworks.No data loss, no LLM hallucination.
PARSEDStructured policySubject & action & resource & condition. Citable & traceable.Original text — always retrievable.
LIVEDecisionsCited to source · current risk. Forces and obligations applied. Re-evaluated on every signal.Compiled enforcement.

Documented obligations become a runtime all identities inherit.

Every decision cites the clause it came from — so an auditor reads policy, not inference.

Open standards

Standard pipes. idGenius composes the context.

OAuthToken and delegation flowAgent to agent, service to service — delegation that carries its grant.
SPIFFEWorkload identityEvery workload gets a cryptographic, verifiable identifier — the SVID.
SPIRERuntime issuanceSPIRE mints those identities. idGenius is the trust root it draws from: identity sources, governance and attestations inherited through the graph.
SCIMProvisioning and lifecycleJoiner, mover, leaver — inherited, then extended with owner, policy, relationships and audit trail.
MCPThe AI handshakeModels call tools and idGenius sits in the middle, so identity context rides the call instead of a separate handshake. Models ask in context; tools receive rich, governed calls.
DID · VCExternal and federated actorsDecentralized identifiers and verifiable credentials for actors outside your directory.
AuthZENThe authorization contractThe enforcement point asks; idGenius returns decision, context, policy citations and obligations.

MCP is the wire. idGenius is the meaning on it.

No proprietary SDK at the enforcement point — the contract is the integration.

SPIFFE & SPIRE

Workload identity. Issued at runtime.

SPIFFE defines the SVID. SPIRE attests workloads and mints the certificate.

SPECSPIFFEA standard identity document. A cryptographic SVID with a verifiable provenance.What every workload needs.
RUNTIMESPIREAttests workloads, mints SVIDs. Attestation methods plug in.Typical SPIRE deployments start blind.
TRUST ROOTidGeniusThe trust root that SPIRE draws from. Workloads inherit identity, governance, and attestations through the relationship graph.No fork. One schema.

SVIDs issued from the same governance every actor inherits.

Stack

Boring on purpose.

Postgres + Kubernetes
Kafka streaming
Graph database · triple store
Open-source SDKs
Connectors

Plug into what you already run.

Okta · Azure AD · Workday · SCIM
AWS · Azure · GCP · cloud KMS
Splunk · Sentinel · SIEM streaming
Datadog · ServiceNow · ITSM
Security & audit

Every agent. Every action. One trail.

TrustBacked by a $15M cybersecurity insurance policy.
ComplianceSOC 2 Type II scheduled. Roadmap to ISO 27001, HIPAA and NIST.
EncryptionAt rest and in transit, with customer-managed KMS keys. Bring your own root of trust.
Audit trailOne record per action, SIEM-streamed. Replay, reconstruct, prove.

“AI abandonment is a chaos of vendor-managed, vendor-controlled AI agents securing themselves.”

— an enterprise CISO

The ask

Ask us how 30–45 minutes can reduce your risk and operating expenses for AI.

How it runsRead-only connections. Nothing replaced, nothing disrupted.
What you leave withA discrepancy ledger — where the gaps are, what they cost, what to prioritize.
Thank you.

Your request is recorded. We reply within one business day.

Something went wrong while submitting the form. Please try again.