Skip to content
QDataCloud

Product

QData Identity Security

Identity Security for AI Agents and Non-Human Identities — inventory, governance, authorization, and enforcement where a PEP exists.

You buy a control loop, not a dashboard that implies a block. Agents and other NHI get owners, policy, a decision on the action, and a trail. Protection is a path you attach, not a toggle in a screenshot.

The control loop

Discover identities. Govern owners and lifecycle. Authorize the action. Protect only where a policy enforcement point sits on the path. Audit the decision. Shadow first.

  1. Discover

    Find agents and other non-human identities before they sprawl across tenants.

    1 / 5

  2. Govern

    Give each identity an owner, a lifecycle, and a least-privilege baseline.

    2 / 5

  3. Authorize

    Decide allow, deny, or require approval for a subject, action, and resource.

    3 / 5

  4. Protect

    Block only where a policy enforcement point sits on the path.

    Requires a PEP

  5. Audit

    Keep an immutable trail of decisions. Evidence is a log, not a badge wall.

    5 / 5

What the product covers

Category pages for AI Agent Security and Non-Human Identities go deeper on those topics. Authorization and MCP Security are capabilities and surfaces — not a rename of this product.

  • Inventory and governance

    Register agents and other non-human identities, discover what already exists, and assign an owner. Create, review, expire, and revoke. Without a connector, inventory is what you register yourself or report through an SDK — not a promise that every secret in the estate appears automatically.

  • Authorization and policy

    Each check asks the same question: this subject, this action, this resource, this context. The answer is allow, deny, or require approval. Policy is something you can read, version, and simulate. Risk can raise or lower confidence; it is not the policy decision point.

  • Runtime and audit

    A recorded decision is not a block. Protection exists only on a path that includes a policy enforcement point: SDK, security gateway, MCP gateway, sidecar, or connector. MCP tools are resources. Secrets belong in the same identity model. The trail is evidence of decisions — not a badge row.

  • AI Agent Identity Security

    Treat agents as first-class identities: owners, tools, and a decision on every action.

    Open AI Agent Identity Security
  • NHI Management

    Cover service accounts, workloads, machines, bots, and APIs — not only agents.

    Open NHI Management
  • Inventory

    If it can act, it must be findable. Flag orphans before they become standing access.

    Open Inventory
  • Identity Governance

    Lifecycle and ownership for non-human identities, without a spreadsheet sidecar.

    Open Identity Governance
  • Authorization

    Allow, deny, or require approval for a subject, action, resource, and context.

    Open Authorization
  • Runtime Authorization

    Decide at the time of the action. A dashboard toggle is not a block.

    Open Runtime Authorization
  • Policy

    Policy-based access you can review, version, and simulate before protect.

    Open Policy
  • Risk-Based Access

    Risk informs the decision. It does not replace the decision engine.

    Open Risk-Based Access
  • MCP Security

    Authorize tool calls as actions on resources, typically at an MCP gateway PEP.

    Open MCP Security
  • Credential Governance

    Govern secrets and keys as part of identity — not a disconnected vault UI.

    Open Credential Governance
  • Audit

    Immutable decision evidence. Not a substitute for a certification mark.

    Open Audit

One decision, three outcomes

The check is always the same shape: subject, action, resource, context. Risk can inform it. A language model does not make it.

  1. Agent
  2. Identity
  3. Authorization
  4. Policy
  5. Risk
  6. Decision
  7. Resource
Agent to identity to authorization to policy to risk to decision to resource.
  • ALLOW

    The subject may perform the action on the resource in this context.

  • DENY

    The subject may not. In shadow, this is recorded as a would-be deny. In protect, a PEP can block.

  • REQUIRE_APPROVAL

    The action waits on a human. That is a decision outcome, not a notification after the fact.

Organization and Tenant

One Organization owns the people who sign in. Isolated Tenants own agents, NHI, policies, and resources. Policy and inventory do not leak across tenants.

A software house typically maps each customer environment to a tenant. An AI product team often starts with a single tenant and adds more when a second environment must not share agents or secrets.

Organization

Owns users who sign in

Tenant A

Agents · NHI · policies · resources

Isolated. No leak to Tenant B.

Tenant B

Separate inventory and policy

Typical software-house customer environment.

Conceptual tenancy. Not a live console screenshot.

Software houses

Delivery organizations that ship agents and automations into many customer environments. This is a job on this product page — not a separate marketing URL, and not a promise of white-label or custom domains.

  • One organization, many customer environments

    The software house’s people live on the organization. Each customer environment is typically a tenant, so agents, NHI, policies, and resources do not mix.

  • Agents shipped into someone else’s estate

    The identity that acts at the customer is still yours to inventory and authorize. Standing access that outlives the engagement is an orphan with a contract date.

  • Shadow before you protect a client path

    Simulate would-be denies in the tenant before a PEP blocks a production tool call. That order is the same as everywhere else — the blast radius is just a customer’s.

Shadow, then protect

Simulate produces the same decision as protect, including would-be denies, without blocking the caller. Enable enforcement after a PEP is on the path and the trail has been reviewed. That order is the product, not an optional extra.

How protection actually attaches is on the security model.

What this is not

The first offer is identity security for agents and other NHI — not a ten-year IGA program and not a magic block.

  • Not a full IGA suite

    Human identity governance at enterprise connector scale is not the first offer. This product starts with agents and other NHI.

  • Not prompt DLP as the core

    Inspecting prompts is not the control loop. The loop is identity, policy, a decision, and enforcement where a PEP exists.

  • Not a chatbot wrapper

    An agent is an identity that calls tools. Wrapping a model UI is not the same as authorizing an action on a resource.

  • Not a block without a PEP

    Seeing an event, scoring risk, or opening a dashboard does not stop the caller. Attach a PEP before you claim protect.

SHADOWALLOWDENY

Observation is not enforcement

QData Identity Security can inventory identities, evaluate policy, and record a decision. It blocks an action only when a policy enforcement point is actually in the request path. Shadow mode shows what would have been denied before you enable protect.

Developer path

Register an agent, check authorization, see the decision. The snippet is conceptual until the public API host is live. Full DX copy lives on the developers hub.

authorization.check({
  subject:  "agent:invoice-agent",
  action:   "payment.execute",
  resource: "payment:9281",
  context:  { amount: 240, env: "prod" }
})
Conceptual example — not a live API contract.
  • Authorization

    The check: subject, action, resource, context — including runtime.

    Open authorization
  • MCP Security

    When the action is a tool call. Surface, not a second product.

    Open MCP Security
  • AI Agent Security

    Agents as a type of NHI: tool calls, MCP, no human session.

    Open AI Agent Security
  • Non-Human Identities

    Service accounts, workloads, machines, bots, APIs — the rest of the set.

    Open NHI
  • Security model

    Observe is not enforce. Shadow before protect.

    See security
  • Pricing

    Conversation frames and a quote. No invented list prices.

    See pricing

Questions

QData Identity Security: inventory, ownership, authorization, policy, risk that informs a decision, enforcement where a PEP exists, and an audit trail. It is the first product on QData Cloud.

Explore the platform

Get started when the console is public, or talk through tenants, shadow, and rollout.