Exactly the right access.
Nothing more.
Hierarchical RBAC, entitlements, and audit on top of your IdP — precisely the access every user, service, and AI agent should have.Add hierarchical RBAC, entitlements, and audit to the IdP you already run — so users, services, and AI agents get precisely what they should, and not a permission more. Keep Okta, Entra, or Auth0.
Built for regulated B2B — healthcare, fintech & SaaS teams
Okta · Entra · Auth0 · Google · Cognito
Enriched JWT: roles · permissions · entitlements · org
One platform for the three jobs every B2B app needs
Govern access, ship and experiment, and prove compliance — without stitching together an IdP, a feature-flag tool, and a SIEM pipeline.
Hierarchical access that matches your org chart
Roles, permissions, and attribute policies that inherit across a 5-level org tree — applied the same way to users, services, and AI agents, enforced at the edge from an enriched JWT.
- RBAC + ABAC + fine-grained (ReBAC) authorization
- 5-level org hierarchies with inherited permissions
- Break-glass, just-in-time & approval workflows
- Service accounts & M2M client credentials for agents
Feature flags + A/B testing, identity-native
Entitlements, feature flags, and experimentation in one system that already knows the tenant, org, role, and plan. Release safely, experiment on users, orgs and AI agents, and gate by plan — without a second SDK.
- Feature flags + entitlements: % rollouts, org overrides, plan & quota gating
- A/B testing with sequential (always-valid) statistics + guardrails
- Experiment on AI agents and login journeys — not just anonymous keys
- Target by tenant, org hierarchy, role, plan or geo — server-side
The only platform in the overlap of identity & authorization and feature management & experimentation. Auth0/Okta have no flags; LaunchDarkly/Optimizely have no identity, authz, or audit.
Explore experimentationAudit-ready for regulated B2B
Immutable audit, real-time streaming, and enterprise isolation built in — so security reviews move faster and compliance is evidence, not promises.
- Immutable audit + streaming to S3 / webhook / SIEM
- HIPAA (BAA), SOC 2 (in progress), GDPR, data residency
- BYOC + dedicated infra + per-tenant KMS encryption
- 7-year retention · 99.99% uptime SLA
Roles, permissions, and attribute policies that inherit across a 5-level org tree — applied the same way to users, services, and AI agents, enforced at the edge from an enriched JWT.
- RBAC + ABAC + fine-grained (ReBAC) authorization
- 5-level org hierarchies with inherited permissions
- Break-glass, just-in-time & approval workflows
- Service accounts & M2M client credentials for agents
Entitlements, feature flags, and experimentation in one system that already knows the tenant, org, role, and plan. Release safely, experiment on users, orgs and AI agents, and gate by plan — without a second SDK.
- Feature flags + entitlements: % rollouts, org overrides, plan & quota gating
- A/B testing with sequential (always-valid) statistics + guardrails
- Experiment on AI agents and login journeys — not just anonymous keys
- Target by tenant, org hierarchy, role, plan or geo — server-side
The only platform in the overlap of identity & authorization and feature management & experimentation. Auth0/Okta have no flags; LaunchDarkly/Optimizely have no identity, authz, or audit.
Explore experimentationImmutable audit, real-time streaming, and enterprise isolation built in — so security reviews move faster and compliance is evidence, not promises.
- Immutable audit + streaming to S3 / webhook / SIEM
- HIPAA (BAA), SOC 2 (in progress), GDPR, data residency
- BYOC + dedicated infra + per-tenant KMS encryption
- 7-year retention · 99.99% uptime SLA
Govern every AI agent like an employee.
AI agents are the fastest-growing non-human identity in your stack. AccessIQ gives each one a verifiable identity, least-privilege authorization on every action, and a tamper-evident audit trail — with native MCP support.
A first-class identity for every agent — not a shared API key.
A policy decision on every tool call and MCP request.
A hash-chained record of exactly what each agent did.
The only agent control plane that’s also your CIAM
Agent Guard ships inside every AccessIQ plan from Starter up — no separate product, no separate bill. Here’s how it compares to the point tools.
| Capability | Agent Guard | Permit.io | Cerbos | Lakera |
|---|---|---|---|---|
| First-class agent registry + lifecycle | ||||
| Signed agent cards (JWS) + software attestation | ||||
| DPoP token binding + private_key_jwt (RFC 9449 / 7523) | ||||
| Drop-in MCP gateway with tool-scope consent | ||||
| Built-in prompt-injection + PII/secret scanning | ||||
| PDP federation — OPA / Cedar / AuthZEN | ||||
| Hash-chained ledger + EU AI Act / ISO 42001 reports | ||||
| Generic RBAC / ReBAC for human users |
Reflects generally available Agent Guard capabilities and publicly documented functionality of each vendor at time of writing. Permit.io, Cerbos, and Lakera are trademarks of their respective owners; AccessIQ is not affiliated with or endorsed by them.
Purpose-built for agentic, hierarchical access
The agentic, hierarchical, and compliance capabilities you usually have to build or buy separately — built into AccessIQ, on top of the IdP you already run.
| Capability | AccessIQ | Auth0 | Okta | Cognito |
|---|---|---|---|---|
| Agentic & non-human identity | ||||
| AI agent / service-account identity | Native, first-class | M2M apps | Service apps | App clients |
| Agents inherit the human access model (roles, entitlements, audit) | One model for all | Not available | Not available | Not available |
| Scoped, revocable, rotating agent credentials | Per-scope · instant revoke | Limited | Limited | Limited |
| Delegated / on-behalf-of tokens (Token Exchange, RFC 8693) | Built-in | Add-on | Limited | Not available |
| Tool-scoped agent tokens (MCP / A2A) | Emerging | Not available | Not available | Not available |
| Per-agent usage tracking & rate limits | Built-in | Limited | Limited | Limited |
| Hierarchical authorization & entitlements | ||||
| Hierarchical RBAC across org tree (HRBAC) | 5+ levels, inherited | 2 levels | 2 levels | Limited |
| ABAC + fine-grained authorization (ReBAC) | Built-in | FGA (separate product) | Not available | Not available |
| Entitlements as a service (plan & quota gating in JWT) | Built-in | Not available | Not available | Not available |
| Feature flags + A/B testing, identity-native | Built-in | Not available | Not available | Not available |
| Experiment on AI agents & login journeys (by identity) | Built-in | Not available | Not available | Not available |
| Always-valid experiment statistics + guardrails | Built-in | Not available | Not available | Not available |
| Policy-as-code (Git-backed, versioned) | Built-in | Not available | Not available | Not available |
| Delegated administration (scoped to org subtree) | Built-in | Limited | Available | Not available |
| Break-glass · just-in-time · approval workflows | Built-in | Not available | Limited | Not available |
| Compliance & enterprise | ||||
| Audit log streaming (S3 · webhook · SIEM) | Built-in | Add-on | System Log API | CloudTrail only |
| Immutable audit retention | Up to 7 years | Limited | Limited | CloudTrail |
| HIPAA BAA | Available | Enterprise tier | Enterprise tier | AWS BAA |
| Dedicated infrastructure + per-tenant KMS encryption | Built-in | Enterprise tier | Limited | Not available |
| Bring Your Own Cloud (BYOC) | AWS · GCP · Azure | Not available | Not available | AWS only |
| Data residency (US · EU · APAC) | Built-in | Available | Available | Region-bound |
| Identity verification (KYC / KYB / AML) | Integrated | Third-party | Third-party | Not available |
AI agent / service-account identity
Agents inherit the human access model (roles, entitlements, audit)
Scoped, revocable, rotating agent credentials
Delegated / on-behalf-of tokens (Token Exchange, RFC 8693)
Tool-scoped agent tokens (MCP / A2A)
Per-agent usage tracking & rate limits
Hierarchical RBAC across org tree (HRBAC)
ABAC + fine-grained authorization (ReBAC)
Entitlements as a service (plan & quota gating in JWT)
Feature flags + A/B testing, identity-native
Experiment on AI agents & login journeys (by identity)
Always-valid experiment statistics + guardrails
Policy-as-code (Git-backed, versioned)
Delegated administration (scoped to org subtree)
Break-glass · just-in-time · approval workflows
Audit log streaming (S3 · webhook · SIEM)
Immutable audit retention
HIPAA BAA
Dedicated infrastructure + per-tenant KMS encryption
Bring Your Own Cloud (BYOC)
Data residency (US · EU · APAC)
Identity verification (KYC / KYB / AML)
Comparison based on publicly documented capabilities; competitor features may require add-ons or higher tiers. “Emerging” = on the AccessIQ roadmap.
Connect to Any Identity Provider
Bring your own IdP. AccessIQ integrates with enterprise, open source, and social identity providers via SAML 2.0, OIDC, and SCIM 2.0.
Microsoft Entra ID
Azure AD / Entra
Full SCIM 2.0 provisioning
AWS Cognito
AWS IAM
Federated identity
Google Cloud Identity
Google Workspace
SAML & OIDC
Okta
Workforce Identity
Universal Directory
Auth0
Developer Identity
OIDC & Social Login
OneLogin
IAM Platform
SSO & MFA
Ping Identity
Enterprise SSO
Intelligent identity
ForgeRock
Identity Platform
OIDC, SAML, SCIM
IBM Security Verify
IBM IAM
Enterprise security
SailPoint
Identity Governance
Identity management
Keycloak
Red Hat SSO
Open source IAM
Authentik
Self-hosted IdP
Modern open source
Gluu Server
Open IAM
Enterprise open source
Google Workspace
G Suite
Business identity
Microsoft 365
M365 Business
Office 365 identity
SAML 2.0
Enterprise Standard
XML-based federation
OpenID Connect
Modern Auth
OAuth 2.0 identity layer
LDAP
Directory Services
Active Directory
2B+ users
Consumer login
GitHub
100M+ devs
Developer auth
930M users
Professional identity
Apple
2B devices
Sign in with Apple
3B+ users
Social login
Twitter / X
500M+ users
X OAuth
Salesforce
150K+ orgs
CRM identity
Drop in beside your app
Authorization, entitlements, and feature flags from one SDK — typed clients, framework-agnostic components, and edge JWT validation. No rewrite, no proxy.
import {
RequirePermission,
useHasPermission,
useFeatureFlag,
} from '@identia/react'
function Billing() {
// Authorization + entitlements, straight from the JWT
const canManage = useHasPermission('billing:write')
// Identity-native feature flag — no second SDK
const redesign = useFeatureFlag('billing-redesign')
return (
<RequirePermission permission="billing:read">
{redesign ? <BillingV2 /> : <BillingV1 />}
</RequirePermission>
)
}Wedges built for your industry
Capabilities most identity platforms don’t have — purpose-built for B2B commerce and regulated industries.
PunchOut & cXML identity bridge
AccessIQ brokers identity and session between procurement systems and your supplier catalog — a capability no other CIAM platform offers.
- cXML & OCI PunchOut (Ariba, Coupa, Jaggaer, Oracle, SAP)
- SSO-authenticated, org-scoped catalog sessions
- PunchOutSetupRequest/Response + OrderMessage, XXE-hardened
Identity verification, built in
KYC, KYB, and AML screening integrated into onboarding — verify people and businesses without bolting on a third-party vendor.
- KYC with AI liveness + document authenticity checks
- KYB beneficial-ownership verification
- Sanctions & PEP screening with risk scoring
Start free, scale without surprises
Starter
SSO, custom roles, and API access for growing teams
- Up to 1,000 monthly active users
- 10 organizations
- 3 identity providers
- SSO (OIDC) & social login
- MFA (TOTP, SMS, Email)
- Custom roles & permissions
- API access & data export
- 90-day audit log retention
- Email support (24h response)
- Agent GuardAdd-on includedAI-agent identity, registry, signed agent cards & kill switch — up to 50 agents
- Feature Flags & A/B TestingAdd-on includedidentity-native flags + experiments on users & orgs
Business
Advanced security with SAML, HRBAC, and compliance
- Up to 25,000 monthly active users
- Unlimited organizations
- 10 identity providers
- SAML 2.0 & SCIM provisioning
- Hierarchical RBAC (HRBAC)
- Webhooks & custom branding
- Custom domain & IP whitelisting
- SOC 2 (in progress) & GDPR-ready
- 1-year audit log retention
- Priority support (4h response)
- Agent Guard ProAdd-on includedMCP gateway, prompt-injection guardrails, DPoP & attestation — up to 500 agents
- Feature Flags & A/B Testing ProAdd-on includedagent-behavior experiments, sequential stats & guardrails
Enterprise
Unlimited scale with dedicated support
- Unlimited users & organizations
- Unlimited identity providers
- HIPAA BAA & SOC 2 report (on certification)
- Dedicated infrastructure included
- White-label (custom CSS)
- Session recording & real-time monitoring
- 7-year immutable audit logs
- Dedicated success manager
- 99.99% uptime SLA
- Agent Guard EnterpriseAdd-on includedPDP federation, delegation chains & AI-Act / ISO 42001 reports — unlimited agents
- Feature Flags & A/B Testing EnterpriseAdd-on includedauth-journey experiments, approvals & audit
Frequently asked questions
Everything you need to know about shipping enterprise identity with AccessIQ.
AccessIQ is authorization and entitlements as a service for B2B SaaS. It connects to any identity provider, models fine-grained permissions (RBAC + ABAC), and delivers entitlements at runtime via JWT, REST, or SDK — so you ship enterprise identity without building it yourself.
Let's discuss your entitlement needs
Get in touch
Fill out the form and our team will respond within 24 hours. We're excited to learn about your project.
Email us
info@accessiq.app
