Runtime authorization for agentic transactions

Decide whether an agent's action should execute, before it runs.

Agents now act across your systems on their own. FederatedIQ decides each cross-system action against live state at the moment it happens, and returns allow, deny, or escalate with a signed decision record anyone can verify. One decision per action. An approval a minute ago does not carry forward to the next one.

Stripe moves money. FederatedIQ decides whether the transaction should exist.
The authorization gap

Agents were given credentials, not judgment.

An agent with permission to act can string permitted steps into an outcome no one authorized. The controls most companies have run after the fact: a log, an audit, an alert once the action already happened. The decision has to move to before the action, and it has to reason across every system at once.

Federation, not mastery

Thirty years of governance asked one system to be the master of record. FederatedIQ holds no master copy. It resolves identity and context in flight, across the authorities you already run, at decision time.

A decision, not a copy

Source systems stay authoritative. What crosses the boundary is a decision about a single action, never a duplicate of your records. Nothing is centralized to be governed.

Admission decisions · computed at decision time
The control plane

Two engines. One question: should this action proceed?

Is this the right entity?

Engine 1 · Entity Resolution

Resolves the entity an action names across the authorities you already run, with a confidence score. When the authorities disagree, or confidence falls below threshold, it escalates to a person rather than guessing. Authorities are peers. Disagreement is a signal, not noise to average away.

Zero-copyAlways-liveConfidence scoring
Should this action execute now?

Engine 2 · Action Governance

Recomputes an action's approval against live policy, the actor's current standing, and present state at the moment of the decision. A stale approval is denied by naming the dependency that moved, so the record says exactly why. Valid a minute ago is not valid now.

Recompute-at-decisionLive-stateNames what moved
The shape

Enforce at the edge. Keep authority at the hub.

Spoke
Enforces next to the action. Holds no signing key. A compromised spoke can deny, never forge.
decision →
← verdict
Hub
Holds identity, entitlements, and the signed decision log. Receives a decision, never a copy of your data.

Every decision, allow and deny alike, is a signed, hash-chained record produced at decision time and verifiable by anyone holding the public key. You trust neither the actor nor the enforcement point. You check the signature.

Use cases

One control plane. A growing set of authorizations, each with a live demo.

The same decision engine governs any cross-system agent action. Every use case below is a live demo you can drive in your browser. Same six gates, same signed record, a different decision each time.

Live demo

Agentic card-fraud authorization

Decide whether a card transaction should complete, before it clears. Approve, decline, or step up to a person when the cardholder identity is in doubt, with a signed record the merchant and the bank both hold. One decision, one audit trail, front office and back office.

Try the live demo →
Live demo

Refunds and payouts

Decide whether a refund or a vendor payout should execute against live approvals and limits. A payout approved against yesterday's state is denied when the state has moved.

Try the live demo →
Live demo

Entity and vendor onboarding

Resolve a customer or vendor across the directories you already run. A clean match proceeds. Directories that disagree go to a person instead of a guess.

Try the live demo →
Live demo

Data-export authorization

Decide whether an agent may send data to a destination before it leaves. An export to an unapproved destination is denied at the gate, not flagged afterward.

Try the live demo →
What it is not

A control plane, not another copy of your data.

Knowing what we are not is how the category stays clear.

Not an MDM tool. No master record. Not ETL or iPaaS. No pipelines, no data movement. Not a data warehouse. No copy of source records. Not a system of record. Source systems stay authoritative. Not a vendor MCP connector. FederatedIQ governs across vendors.