regulAIt-Authorized · Access & identity
Know who — and what — can reach your data.
Access reviews were built for people. Agents now hold credentials, act on their own schedule and drift between reviews. Authorized treats every identity — human or machine — as something that has to be justified, evidenced and revoked.
What it does
Inside regulAIt-Authorized
Review access, including agents
Campaigns that cover service accounts and agent credentials, not just people. Reviewers see what the identity actually did, not only what it may do.
Catch entitlement drift
Continuous comparison against the approved baseline. When scope widens between reviews, a finding opens the same hour.
Evidence the decision
Every approval, denial and revocation is recorded with its justification and carried into the audit export automatically.
Controls this module evidences
Audit-ready without an audit sprint
Each control carries its own evidence trail — who approved the grant, on what basis, when it was last reviewed, and what happened to it since.
| Control | Requirement | Framework |
|---|---|---|
| AC-2 | Account management and periodic review | NIST 800-53 |
| AC-2.3 | Disable inactive accounts and sessions | SOC 2 |
| IA-5.1 | Credential rotation and lifetime limits | ISO 27001 |
| A.5.18 | Access rights review and adjustment | ISO 27001 |
| Art. 14 | Human oversight of high-risk systems | EU AI Act |
How it fits
One module, the same three moves
Every module in the suite speaks one compliance vocabulary and exports one evidence format. Authorized runs as its own system — what it shares with the rest of the suite is the contract, not the runtime.
Connect
Read-only connectors into the systems that already hold the truth. No agents to deploy, no data to move.
- identity providers
- cloud & data platforms
- model gateways
- agent runtimes
Map
One inventory, mapped to the controls of every framework you answer to — once, not per audit.
- control library
- framework mappings
- policy engine
- ownership graph
Evidence
Each control collects its own proof continuously, timestamped and immutable, ready to export.
- evidence store
- attestation packs
- finding workflow
- audit exports
The rest of the suite
Six modules, one control plane
regulAIt-LLM
Build, evaluate and guardrail your own models and agents on your own data, with the evaluation record kept as evidence.
Build your ownregulAIt-Governed
Policies mapped to controls, controls mapped to evidence, monitored continuously rather than at audit time.
Policy & controlsregulAIt-Migrate
Move between frameworks and versions with mappings and evidence carried forward instead of rebuilt.
Join the waitlistregulAIt-Attested
Continuous audit evidence and attestation packs an auditor can accept without a working session.
Join the waitlistregulAIt-Observed
Runtime oversight for live models and agents — drift, abuse, cost and behaviour, watched continuously.
Join the waitlistSee it against your own frameworks
Thirty minutes, your control set, and an honest answer on what regulAIt does today.