Exactly the right access.
Nothing more.

Hierarchical RBAC, entitlements, and audit on top of your IdP — precisely the access every user, service, and AI agent should have.

Hierarchical RBAC + ABAC across a 5-level org tree
Entitlements & feature flags, gated by plan & org

Built for regulated B2B — healthcare, fintech & SaaS teams

SOC 2 in progressHIPAA-readyGDPR

One platform for the three jobs every B2B app needs

Govern access, ship and experiment, and prove compliance — without stitching together an IdP, a feature-flag tool, and a SIEM pipeline.

Roles, permissions, and attribute policies that inherit across a 5-level org tree — applied the same way to users, services, and AI agents, enforced at the edge from an enriched JWT.

  • RBAC + ABAC + fine-grained (ReBAC) authorization
  • 5-level org hierarchies with inherited permissions
  • Break-glass, just-in-time & approval workflows
  • Service accounts & M2M client credentials for agents
See how it compares

Entitlements, feature flags, and experimentation in one system that already knows the tenant, org, role, and plan. Release safely, experiment on users, orgs and AI agents, and gate by plan — without a second SDK.

  • Feature flags + entitlements: % rollouts, org overrides, plan & quota gating
  • A/B testing with sequential (always-valid) statistics + guardrails
  • Experiment on AI agents and login journeys — not just anonymous keys
  • Target by tenant, org hierarchy, role, plan or geo — server-side

The only platform in the overlap of identity & authorization and feature management & experimentation. Auth0/Okta have no flags; LaunchDarkly/Optimizely have no identity, authz, or audit.

Explore experimentation

Immutable audit, real-time streaming, and enterprise isolation built in — so security reviews move faster and compliance is evidence, not promises.

  • Immutable audit + streaming to S3 / webhook / SIEM
  • HIPAA (BAA), SOC 2 (in progress), GDPR, data residency
  • BYOC + dedicated infra + per-tenant KMS encryption
  • 7-year retention · 99.99% uptime SLA
Talk to sales
New · Agentic

Govern every AI agent like an employee.

AI agents are the fastest-growing non-human identity in your stack. AccessIQ gives each one a verifiable identity, least-privilege authorization on every action, and a tamper-evident audit trail — with native MCP support.

Verifiable identity

A first-class identity for every agent — not a shared API key.

Per-action authorization

A policy decision on every tool call and MCP request.

Tamper-evident audit

A hash-chained record of exactly what each agent did.

Agent Guard vs. the field

The only agent control plane that’s also your CIAM

Agent Guard ships inside every AccessIQ plan from Starter up — no separate product, no separate bill. Here’s how it compares to the point tools.

Full support Partial Not offered
CapabilityAgent GuardPermit.ioCerbosLakera
First-class agent registry + lifecycle
Signed agent cards (JWS) + software attestation
DPoP token binding + private_key_jwt (RFC 9449 / 7523)
Drop-in MCP gateway with tool-scope consent
Built-in prompt-injection + PII/secret scanning
PDP federation — OPA / Cedar / AuthZEN
Hash-chained ledger + EU AI Act / ISO 42001 reports
Generic RBAC / ReBAC for human users

Reflects generally available Agent Guard capabilities and publicly documented functionality of each vendor at time of writing. Permit.io, Cerbos, and Lakera are trademarks of their respective owners; AccessIQ is not affiliated with or endorsed by them.

Purpose-built for agentic, hierarchical access

The agentic, hierarchical, and compliance capabilities you usually have to build or buy separately — built into AccessIQ, on top of the IdP you already run.

Agentic & non-human identity

AI agent / service-account identity

AccessIQ
Native, first-class
Auth0
M2M apps
Okta
Service apps
Cognito
App clients

Agents inherit the human access model (roles, entitlements, audit)

AccessIQ
One model for all
Auth0
Not available
Okta
Not available
Cognito
Not available

Scoped, revocable, rotating agent credentials

AccessIQ
Per-scope · instant revoke
Auth0
Limited
Okta
Limited
Cognito
Limited

Delegated / on-behalf-of tokens (Token Exchange, RFC 8693)

AccessIQ
Built-in
Auth0
Add-on
Okta
Limited
Cognito
Not available

Tool-scoped agent tokens (MCP / A2A)

AccessIQ
Emerging
Auth0
Not available
Okta
Not available
Cognito
Not available

Per-agent usage tracking & rate limits

AccessIQ
Built-in
Auth0
Limited
Okta
Limited
Cognito
Limited
Hierarchical authorization & entitlements

Hierarchical RBAC across org tree (HRBAC)

AccessIQ
5+ levels, inherited
Auth0
2 levels
Okta
2 levels
Cognito
Limited

ABAC + fine-grained authorization (ReBAC)

AccessIQ
Built-in
Auth0
FGA (separate product)
Okta
Not available
Cognito
Not available

Entitlements as a service (plan & quota gating in JWT)

AccessIQ
Built-in
Auth0
Not available
Okta
Not available
Cognito
Not available

Feature flags + A/B testing, identity-native

AccessIQ
Built-in
Auth0
Not available
Okta
Not available
Cognito
Not available

Experiment on AI agents & login journeys (by identity)

AccessIQ
Built-in
Auth0
Not available
Okta
Not available
Cognito
Not available

Always-valid experiment statistics + guardrails

AccessIQ
Built-in
Auth0
Not available
Okta
Not available
Cognito
Not available

Policy-as-code (Git-backed, versioned)

AccessIQ
Built-in
Auth0
Not available
Okta
Not available
Cognito
Not available

Delegated administration (scoped to org subtree)

AccessIQ
Built-in
Auth0
Limited
Okta
Available
Cognito
Not available

Break-glass · just-in-time · approval workflows

AccessIQ
Built-in
Auth0
Not available
Okta
Limited
Cognito
Not available
Compliance & enterprise

Audit log streaming (S3 · webhook · SIEM)

AccessIQ
Built-in
Auth0
Add-on
Okta
System Log API
Cognito
CloudTrail only

Immutable audit retention

AccessIQ
Up to 7 years
Auth0
Limited
Okta
Limited
Cognito
CloudTrail

HIPAA BAA

AccessIQ
Available
Auth0
Enterprise tier
Okta
Enterprise tier
Cognito
AWS BAA

Dedicated infrastructure + per-tenant KMS encryption

AccessIQ
Built-in
Auth0
Enterprise tier
Okta
Limited
Cognito
Not available

Bring Your Own Cloud (BYOC)

AccessIQ
AWS · GCP · Azure
Auth0
Not available
Okta
Not available
Cognito
AWS only

Data residency (US · EU · APAC)

AccessIQ
Built-in
Auth0
Available
Okta
Available
Cognito
Region-bound

Identity verification (KYC / KYB / AML)

AccessIQ
Integrated
Auth0
Third-party
Okta
Third-party
Cognito
Not available

Comparison based on publicly documented capabilities; competitor features may require add-ons or higher tiers. “Emerging” = on the AccessIQ roadmap.

Connect to Any Identity Provider

Bring your own IdP. AccessIQ integrates with enterprise, open source, and social identity providers via SAML 2.0, OIDC, and SCIM 2.0.

Microsoft Entra ID logo

Microsoft Entra ID

Azure AD / Entra

Full SCIM 2.0 provisioning

AWS Cognito logo

AWS Cognito

AWS IAM

Federated identity

Google Cloud Identity logo

Google Cloud Identity

Google Workspace

SAML & OIDC

Okta logo

Okta

Workforce Identity

Universal Directory

Auth0 logo

Auth0

Developer Identity

OIDC & Social Login

OneLogin logo

OneLogin

IAM Platform

SSO & MFA

Ping Identity logo

Ping Identity

Enterprise SSO

Intelligent identity

ForgeRock logo

ForgeRock

Identity Platform

OIDC, SAML, SCIM

IBM Security Verify logo

IBM Security Verify

IBM IAM

Enterprise security

SailPoint logo

SailPoint

Identity Governance

Identity management

Keycloak logo

Keycloak

Red Hat SSO

Open source IAM

Authentik logo

Authentik

Self-hosted IdP

Modern open source

Gluu Server logo

Gluu Server

Open IAM

Enterprise open source

Google Workspace logo

Google Workspace

G Suite

Business identity

Microsoft 365 logo

Microsoft 365

M365 Business

Office 365 identity

SAML 2.0 logo

SAML 2.0

Enterprise Standard

XML-based federation

OpenID Connect logo

OpenID Connect

Modern Auth

OAuth 2.0 identity layer

LDAP logo

LDAP

Directory Services

Active Directory

Google logo

Google

2B+ users

Consumer login

GitHub logo

GitHub

100M+ devs

Developer auth

LinkedIn logo

LinkedIn

930M users

Professional identity

Apple logo

Apple

2B devices

Sign in with Apple

Facebook logo

Facebook

3B+ users

Social login

Twitter / X logo

Twitter / X

500M+ users

X OAuth

Salesforce logo

Salesforce

150K+ orgs

CRM identity

Built for developers

Drop in beside your app

Authorization, entitlements, and feature flags from one SDK — typed clients, framework-agnostic components, and edge JWT validation. No rewrite, no proxy.

<5 min to first auth (hosted) · <30 min custom
01
Hosted login pages
Zero-code, branded subdomain
02
Custom login UI
OAuth 2.0 + PKCE
03
TypeScript SDK
@identia/sdk
04
React hooks & guards
@identia/react
05
Token Exchange
RFC 8693 — keep your IdP
06
Backend JWT validation
JWKS, edge-enforced
TypeScriptReact.NETSpring BootWeb ComponentsNodePythonGo
Read the docs
Billing.tsx
import {
  RequirePermission,
  useHasPermission,
  useFeatureFlag,
} from '@identia/react'

function Billing() {
  // Authorization + entitlements, straight from the JWT
  const canManage = useHasPermission('billing:write')
  // Identity-native feature flag — no second SDK
  const redesign = useFeatureFlag('billing-redesign')

  return (
    <RequirePermission permission="billing:read">
      {redesign ? <BillingV2 /> : <BillingV1 />}
    </RequirePermission>
  )
}

Wedges built for your industry

Capabilities most identity platforms don’t have — purpose-built for B2B commerce and regulated industries.

B2B Commerce & Supply Chain

PunchOut & cXML identity bridge

AccessIQ brokers identity and session between procurement systems and your supplier catalog — a capability no other CIAM platform offers.

  • cXML & OCI PunchOut (Ariba, Coupa, Jaggaer, Oracle, SAP)
  • SSO-authenticated, org-scoped catalog sessions
  • PunchOutSetupRequest/Response + OrderMessage, XXE-hardened
Fintech & Regulated

Identity verification, built in

KYC, KYB, and AML screening integrated into onboarding — verify people and businesses without bolting on a third-party vendor.

  • KYC with AI liveness + document authenticity checks
  • KYB beneficial-ownership verification
  • Sanctions & PEP screening with risk scoring
AccessIQ Platform

Sign up today,
test in minutes

Get started with enterprise-grade identity and access management. No credit card required.

SAML 2.0
Enterprise SSO
OIDC
Modern Authentication
SCIM 2.0
User Provisioning
Custom
Any OIDC/SAML Provider
cXML
B2B Commerce
OAuth 2.0
Delegated Access

Start free, scale without surprises

Free

$0/month

Try AccessIQ with basic identity features

  • Up to 10 users / 10 MAU
  • 1 organization
  • Email/password authentication
  • 1 identity provider
  • System roles only
  • 7-day audit logs
  • Community support

Starter

$199/month

SSO, custom roles, and API access for growing teams

Everything in Free, plus:
  • Up to 1,000 monthly active users
  • 10 organizations
  • 3 identity providers
  • SSO (OIDC) & social login
  • MFA (TOTP, SMS, Email)
  • Custom roles & permissions
  • API access & data export
  • 90-day audit log retention
  • Email support (24h response)
  • Agent GuardAdd-on included
    AI-agent identity, registry, signed agent cards & kill switch — up to 50 agents
  • Feature Flags & A/B TestingAdd-on included
    identity-native flags + experiments on users & orgs
Most Popular

Business

$599/month

Advanced security with SAML, HRBAC, and compliance

Everything in Starter, plus:
  • Up to 25,000 monthly active users
  • Unlimited organizations
  • 10 identity providers
  • SAML 2.0 & SCIM provisioning
  • Hierarchical RBAC (HRBAC)
  • Webhooks & custom branding
  • Custom domain & IP whitelisting
  • SOC 2 (in progress) & GDPR-ready
  • 1-year audit log retention
  • Priority support (4h response)
  • Agent Guard ProAdd-on included
    MCP gateway, prompt-injection guardrails, DPoP & attestation — up to 500 agents
  • Feature Flags & A/B Testing ProAdd-on included
    agent-behavior experiments, sequential stats & guardrails

Enterprise

Custom

Unlimited scale with dedicated support

Everything in Business, plus:
  • Unlimited users & organizations
  • Unlimited identity providers
  • HIPAA BAA & SOC 2 report (on certification)
  • Dedicated infrastructure included
  • White-label (custom CSS)
  • Session recording & real-time monitoring
  • 7-year immutable audit logs
  • Dedicated success manager
  • 99.99% uptime SLA
  • Agent Guard EnterpriseAdd-on included
    PDP federation, delegation chains & AI-Act / ISO 42001 reports — unlimited agents
  • Feature Flags & A/B Testing EnterpriseAdd-on included
    auth-journey experiments, approvals & audit

Frequently asked questions

Everything you need to know about shipping enterprise identity with AccessIQ.

AccessIQ is authorization and entitlements as a service for B2B SaaS. It connects to any identity provider, models fine-grained permissions (RBAC + ABAC), and delivers entitlements at runtime via JWT, REST, or SDK — so you ship enterprise identity without building it yourself.

Let's discuss your entitlement needs

Get in touch

Fill out the form and our team will respond within 24 hours. We're excited to learn about your project.

Team discussing identity solutions

By submitting this form, you agree to our Privacy Policy