KeyForgeAI
A NEW LAYER OF THE IDENTITY STACK.

Your IGA moves access.
Something else should reason about it.

Continuous Identity Reasoning — the missing layer between your IGA platform and the audit-ready decisions your team still makes by hand. A reasoning layer that sits above your IGA, governs across human, machine, and AI identity, and automates the judgment calls your team handles one ticket at a time.

§ 01 — The Premise

For fifteen years, the identity industry has confused provisioning with governance. The leading IGA platforms built remarkable engines for moving access through an enterprise. But the judgment behind every access decision — who should get it, under what conditions, with what guardrails, for how long — remains stubbornly, expensively manual.

We believe the next decade of identity governance belongs to a new discipline: Continuous Identity Reasoning. A reasoning layer that sits above your IGA platform, governs across human, machine, and AI identity, and automates the judgment calls your team still makes by hand.

§ 02 — The Argument

Identity has had two eras.
The third one has begun.

I
2005 — 2015

The Provisioning Era

We learned how to move access through enterprises. Workflows, connectors, joiner-mover-leaver. The plumbing got built. The compliance checkbox got checked.

II
2015 — 2023

The Platform Era

IGA platforms consolidated into a mature category. Yet governance maturity flatlined — most programs deliver a fraction of what was promised, years late, with armies of consultants still on retainer.

III
2024 — now

The Reasoning Era

Non-human identities now vastly outnumber humans. AI agents request access autonomously. The bottleneck is no longer provisioning — it's the continuous reasoning required to govern it all.

§ 03 — The Pillars

A new layer. Not another IGA.

01 · Where we sit

Above your IGA

The leading IGA platforms continue running. We sit above them as a reasoning layer — adding the judgment they were never designed to deliver.

02 · What we do

Reason continuously

Every governance signal that matters, evaluated at every access event, across every identity. Not periodic. Not event-driven. Continuous.

03 · Who we govern

Human · Machine · AI

One unified reasoning engine across employees, contractors, service accounts, secrets, bots, and AI agents — not a separate tool for each.

§ 04 — The Architecture

The identity stack, re-drawn.

For years, vendors have argued horizontally — IGA platforms vs. enterprise SSO tools vs. privileged access vaults — as if identity were a single market with one winner. It isn't. Identity is a stack, and the stack has layers that do fundamentally different work.

The layer the market has been missing — the layer that determines whether your IGA investment delivers a fraction of its promise or all of it — is the Reasoning Layer. It is not another IGA platform. It is the brain that makes IGA platforms intelligent.

04Surface

The Experience Layer

How humans and machines request, review, and consume access.

Inhabited byServiceNow · Slack · Custom portals
03Reasoning

The Reasoning Layer ← new

Continuously evaluates every governance signal that matters across every identity, every request, every change in context. Explainable. Auditable. Policy-driven.

Inhabited byKeyForgeAI
02Platform

The Governance Platform Layer

Workflow engines, connectors, role models, certification campaigns, lifecycle automation.

Inhabited bySailPoint · Saviynt · SAP IAG · Microsoft Entra
01Source

The Identity & Access Layer

Directories, vaults, applications, the underlying entitlement model itself.

Inhabited byOkta · Entra ID · CyberArk · AD · Applications

§ 05 — The Scope

Five governance surfaces.
One reasoning engine.

Continuous Identity Reasoning is not “smarter access requests.” It is a unified reasoning engine applied uniformly across the five governance surfaces that define a modern identity program — human and non-human, employee and agent, request-time and lifetime.

01 / 05

Access Governance

Requests, approvals, reviews, certifications — reasoned against every contextual signal that matters at decision time.

02 / 05

Lifecycle Management

Joiner, mover, leaver, contractor expiry, sponsored identity — governed continuously, not at events.

03 / 05

Non-Human Identity

Service accounts, API keys, secrets, machine identities — inventoried, owned, lifecycle-managed.

04 / 05

Risk & SoD

Fine-grained Segregation of Duties across applications, evaluated at request, approval, and review.

05 / 05

Agentic Identity

AI agents, MCP servers, bot lineage — inventoried, governed, scope-validated continuously.

§ 06 — The Engine

Reasoning, in three tiers.
You choose where to stop.

We define reasoning the way computer science defines it: the systematic evaluation of multiple signals to reach a defensible conclusion. KeyForgeAI's reasoning engine operates in three tiers, each independently deployable, each fully transparent. Regulated buyers can stop at Tier 1. Innovation-led organizations can run all three. Every decision in every tier is explainable, auditable, and traceable to a named policy.

01
Deterministic Reasoning

The Policy Foundation

Rule-based evaluation of metadata at every decision point. If entitlement is privileged AND requester is contractor AND contract expires in <30 days, route to compliance approver and set expiry to contract end date. Every outcome is traceable to a named rule. Zero opacity. Fully audit-ready.

TechnologyRules · Policies · Metadata
Audit postureFully deterministic
Required forAll deployments
02
Statistical Reasoning

The Pattern Layer

Peer access analysis, role mining, outlier detection, usage-based right-sizing. Classical machine learning techniques — clustering, classification, regression — that have been industry-standard in IGA for over a decade. Surfaces patterns humans can't see manually. Fully explainable through feature importance.

TechnologyClassical ML · Statistics
Audit postureExplainable models
OptionalRecommended for most
03
Generative Reasoning

The Future Layer

LLM-assisted policy authoring, natural language access requests, AI agent intent analysis, conversational audit explanation. Opt-in, off by default. Available for organizations ready to use generative AI — never inserted into the decision path without explicit configuration.

TechnologyLLMs · Generative AI
Audit postureOpt-in, isolated
AvailableFor agentic-ready orgs
Run Tier 1 alone and you get a fully deterministic, policy-driven reasoning engine with no generative AI in the decision path. Add Tier 2 for pattern intelligence. Enable Tier 3 only when your organization is ready. The architecture meets you where you are, and grows with you.

§ 07 — The Evidence

The decisions your IGA
platform leaves to humans.

Every access event in your enterprise triggers a sequence of judgment calls. Your IGA workflow handles the mechanics — the routing, the approval click, the provisioning call. The judgment — the part that actually matters for risk, compliance, and audit — gets pushed to a manager who has thirty seconds and no context. Below: a sample of the questions our reasoning engine answers automatically. Your team is answering them today, by hand, one ticket at a time.

Is this entitlement actually privileged?

Manual todayReasoned

Has the requester completed required training?

Manual todayReasoned

Does this access violate SoD against existing roles?

Manual todayReasoned

Should this be JIT, not standing access?

Manual todayReasoned

Does the contractor's access expire with their contract?

Manual todayReasoned

Should this route to a risk-based approver?

Manual todayReasoned

Does this AI agent's request match its declared scope?

Manual todayReasoned

Which service account inherits this credential, and who owns it?

Manual todayReasoned

Should domain admin be removed after provisioning?

Manual todayReasoned

Are there provisioning dependencies that must fire first?

Manual todayReasoned

Does this MCP server expose sensitive scopes?

Manual todayReasoned

…and every other governance question that matters.

All Reasoned

Every signal that matters × every identity × every change in context= the reasoning your team is doing by hand, today.

§ 08 — The Path

The Reasoning Maturity Model.

Identity programs evolve along a predictable path. Most enterprises are stuck at Stage 2 — they bought the platform, but the platform alone cannot move them forward. The Reasoning Layer is what unlocks Stages 3, 4, and 5.

1
Stage One

Manual

Spreadsheets, tickets, tribal knowledge.

2
Stage Two

Platformed

IGA deployed. Workflows running. Judgment still manual.

3
Stage Three

Reasoned

Metadata-driven decisions. Risk-based routing live. Every signal evaluated automatically.

4
Stage Four

Continuous

NHIs, service accounts, secrets under the same reasoning as humans. Always-on.

5
Stage Five

Agentic-Ready

AI agents reasoned about continuously. Lineage tracked. SoD enforced on bots.

Most enterprises that bought IGA between 2018 and 2023 are still at Stage 2. They are not failing — the platform was never designed to take them further on its own. The Reasoning Layer is what's missing.
We are not replacing IGA.
We are giving it the reasoning
it was always supposed to have.
— The KeyForgeAI Thesis

Where does your program sit on the Reasoning Maturity curve?

Take the 5-minute self-assessment. Score your program against the governance decisions enterprise identity programs need to automate. Receive a gap report mapped to your existing IGA platform.