
Every agent action carries a verified name.
Your agents work on behalf of people. TraceMem confirms who, against the directory you already run, before the action happens. When someone asks who did this, the answer is a person, not a service account.
An illustration with made-up names. Three agent actions are checked in turn. A claim payment proceeds for Maya Okafor, verified by Microsoft Entra ID. A credit limit rise for Lena Lindqvist is held until Tomás Ruiz in Credit Risk approves it in Teams. An export of discharge summaries is stopped, because Sam Whitfield in Marketing is not allowed to use the records agent.
Illustrative examples. Names and records are made up.
An auditor asks who. You answer with a name.
Without TraceMem, everything your agents do is filed under one shared account. With it, every action points to the person the agent was working for, confirmed by your own identity provider.
- 09:41:07claims-agentPaid claim CLM-20931svc-ai-agents
- 09:41:19underwriting-agentQuoted home policy HM-44810svc-ai-agents
- 09:42:03claims-agentAsked for photos on CLM-20940svc-ai-agents
- 09:42:40finance-agentReleased supplier payment #7713svc-ai-agents
- 09:43:12support-agentUpdated the address on HM-30127svc-ai-agents
- 09:43:58fraud-agentFlagged CLM-20877 for reviewsvc-ai-agents
- 09:44:31claims-agentPaid claim CLM-20955svc-ai-agents
Illustrative log. Before TraceMem, every row read svc-ai-agents.
Your directory does the vouching. Nothing new to run.
TraceMem creates no accounts and keeps no passwords. It checks every agent against the identity provider you already trust, on every call, model calls included.
When someone leaves, their access to your agents leaves with them.
Works with Microsoft Entra ID, Okta, Ping Identity, OneLogin, Google Workspace, Keycloak, Oracle IDCS, IBM Security Verify, or any other OIDC provider.
Choose who may put each agent to work.
Pick the teams from your directory that may use an agent. Anyone else is stopped, or sent to a person who can vouch for them. Try it.
claims-agent may be used by
- Claims
- Claims leadership
Groups from Microsoft Entra ID
Illustrative. Names are made up.
Sam Whitfield is outside the allowed groups, so the payment is stopped.
One verified name makes every control sharper.
- Policies that know who is askingWrite rules around the person: their team, their role, or whether anyone was verified at all.Policy and Exceptions
- Sensitive data for the right people onlyProtected values are revealed only to people whose role allows it, and to nobody when no one was verified.PII Protection
- Model calls under the same nameThe person is checked at the model gateway too, so a prompt is tied to someone as surely as an action is.Model Gateway
- Approvals with a name on themEvery yes is kept next to the action it released, with the person who gave it.Decision Trace