Skip to content

For large environments

A map of the agents a large estate already has

The estate already has more agents than the IAM diagram admits. Olivares AI is the self-hosted kernel that discovers them, maps read/write access, and holds deny-closed gates you choose to wire — beside the gateway and the tower you already run.

Large environments already paid for routing, content safety and host telemetry. What those leave open is the agent over time: its identity, what it reached across stores and tools, who approved a risky call, and whether any of it can be proven. That is the kernel’s job.

What scales, and how far

  • A tenant-scoped store: persisted entities carry a tenant. That is data-model tenancy, not a completed multi-tenant isolation certification.
  • Identity federation: read-only snapshots and rules you declare. Roster connectors ingest Microsoft Entra Agent ID, AWS Bedrock AgentCore and Google agent registries as read-only snapshots. The workload-identity graph is rendered from the federation rules you declare — a view of what you stated and what those rosters report, not live-verified trust on the wire. Live-verified federation against those registries is still on the roadmap. Human SSO in the open build is single-IdP OIDC/SAML; multi-IdP and SSO enforcement belong to the Enterprise line and are not claimed as shipped here. The kernel can bind an agent to an existing non-human identity or mint a dedicated one; it does not become your IdP.
  • Fidelity is tiered. Coverage is clean, lossy or opaque; attribution is firm, approximate or unknown. Both are shown, never guessed. See fidelity.
  • A managed control plane is labelled future, post-v1. Collectors stay in your infrastructure in every topology.

Related: security leaders, compare, architecture.

Ask Claude

Questions

Does this replace our AI gateway or control tower?

No. See the comparison pages. A gateway sees the model request; a tower sees the host. The kernel sees the agent and the edges it touched, with a fidelity tier on each edge.

Is Olivares AI certified?

No. It is designed toward SOC 2, ISO/IEC 27001, ISO/IEC 42001 and the EU AI Act. It holds none of those certifications.

Try it on your own infrastructure

Olivares AI is open-core (AGPL-3.0) and self-hosted. Deploy it and see what your agents can reach.