The Platform
Proof at every hand-off
Traditional automation asks you to trust a script. Automentic gives every agent a cryptographic identity, checks it at every critical step, and signs the result — so what your workflows did is a matter of record, not a matter of faith.
spiffe://automentic.com/ns/finance/agent/invoice-processor
invoice.approve — INV-2026-04812
oidc | finance-controller · policy ap-approvals-v4
ES256 · verified against the issuing CA
Architecture
Four layers, one chain of proof
Identity layer
Every agent is issued an X.509 certificate or a SPIFFE ID at provisioning, and must present it before it touches a system. No shared service accounts, no anonymous automation.
Policy layer
Each request is authorised in real time against your rules — this action, on this system, right now. Nothing is implicitly trusted, including an agent that was trusted a second ago.
Evidence layer
Every action is signed with the agent’s private key and written to an immutable trail, naming the agent, the authoriser and the moment — non-repudiation you can hand to an auditor.
Control plane
Issue, rotate and revoke agent identities from one place, under the same lifecycle rules your people already follow. Revoking an agent stops it mid-workflow.
Integration
Federate, don't replace
Automentic does not ask you to run a second identity system. It federates with the identity provider you already operate, so agents inherit the same groups, policies and joiner-mover-leaver rules as your people — and your IAM team keeps one place to look.
- Single sign-on over OpenID Connect or SAML 2.0
- Agents inherit your groups, policies and lifecycle rules
- No parallel directory to provision or de-provision
- FIDO2 and WebAuthn for the humans who approve agent actions
- Mutual TLS on every agent-to-system channel
Runtime
What happens when a workflow runs
Trigger
An event, a schedule or an API call starts the workflow inside the systems you already run.
Authenticate
The agent presents its certificate or SPIFFE ID. If it cannot prove who it is, nothing proceeds.
Authorise
The request is checked against your policy in real time — this action, on this system, at this moment.
Act and sign
The agent performs the task and signs the result with its private key, so the outcome cannot later be disowned.
Record
A tamper-proof entry lands in the audit trail and streams on to your SIEM, ready for the next review.
Evidence
What your auditors actually get
Non-repudiation
Signed actions mean nobody can credibly deny which agent did what, or who authorised it.
Continuous evidence
Proof accrues as the work happens, instead of being assembled by hand in the weeks before a review.
Mapped controls
Access control, accountability and data handling line up with SOC 2, ISO 27001 and GDPR requirements.
Export to your SIEM
Immutable logs stream into the tooling your security team already watches, in the format they expect.
See it run against your stack
Bring your identity provider and one workflow you would rather not do by hand. We will show you the signed record it produces.